Offering

Governance, Security & Enablement

Align your policies and security posture with Power Platform, Copilot, and Microsoft 365 — so you can turn AI on with confidence instead of turning it off after an incident.

Governance is what makes the Microsoft app and AI platform safe to say yes to. Kumo works with your IT and enterprise architecture teams to establish the policies first — environment strategy, DLP, Copilot policy, and the tenant-level controls in Purview, Intune, and the Microsoft Admin Center — then builds the intake, review, and community structures that let people actually build inside those guardrails. The result is a Center of Excellence your team runs, measured against a Microsoft adoption-framework roadmap that shows whether it is working.

Governance starts before the platform does

The usual story is a retrofit: hundreds of apps and flows, no inventory, a security team asking questions nobody can answer. It is a good problem — it means people are building — and it is the moment governance either becomes a capability or a crackdown.

But the better engagement starts earlier. We work with IT and enterprise architecture to settle policy and security guidance while those decisions are still cheap, then move through the Microsoft adoption framework to build a roadmap the team can measure against. Whether you are ahead of the sprawl or cleaning up after it, the sequence is the same: policy, then guardrails, then community.

Shadow AI is bigger than any one tool

Your people are already building with AI — not just prompting it, but shipping working tools and, increasingly, agents. Hundreds of licensed ChatGPT and Claude users inside a single organization are generating code-based tooling and sharing it through OneDrive, built by people who are not developers, distributed with none of the architecture review a traditional development team would apply. That is shadow IT’s newest form: agents live in the tenant with no inventory, no owner, and no one in IT who can see what they can reach.

Most organizations have noticed this and have exactly two responses available: ban it, or ignore it. Neither works. The tools and agents are too useful to ban and too consequential to ignore.

The piece most organizations are missing is agent-level visibility, not another review process. Microsoft Agent 365 is what makes that possible — it gives every agent in the tenant, sanctioned or not, an identity and a manageable lifecycle, the same way Entra already governs people and Intune governs devices. That is the key to the shadow IT problem itself; governing the output people produce is a related but narrower job. On that narrower piece, we have built one part of the answer: a Copilot agent that vets submitted HTML tools, routes them through architecture review in Azure DevOps, and publishes approved ones to SharePoint, so makers keep their speed and the organization gets provenance on what gets published. It is a review pipeline for output — Agent 365 is what governs the agents themselves.

Enablement is the other half of the job

Governance that only restricts gets routed around. The engagements that hold up are the ones where we also build the community: a Community of Practice with a real monthly cadence, champions who are identified and equipped to help their own teams, and SOPs published in a Microsoft Teams space makers already live in.

The same applies to AI adoption. In one Copilot program we put the initial policies and DLP settings in place, enabled the surrounding tools that make Copilot worth having — Azure DevOps, Dynamics 365 Sales, Cowork — and ran light training workshops so people understood the difference between Copilot Chat and Copilot Cowork and how to prompt either one well. That program now supports roughly 100 to 200 active agent developers serving about 1,200 end users.

Beyond Power Platform: the tenant view

The app and AI platform is where we focus, but its policies cannot contradict the tenant they run in. Purview governs how data is classified and protected. Intune governs the devices reaching it. The Microsoft Admin Center holds the tenant configuration underneath both. We work alongside your IT and security teams so the platform guidance and the tenant controls tell the same story — which is usually the difference between a policy that survives review and one that gets rewritten in six months.

A roadmap you can measure

Governance fails quietly when nobody can say whether it is working. We use the Microsoft adoption framework to turn the current state into staged, measurable progress: maker activity, policy and environment compliance, community participation, and how many requests resolve through self-service instead of escalation.

One program built this way supports roughly 1,500 active makers — pro and low-code — across the US, Europe, and Asia. That scale is only survivable because the guardrails, the intake, and the community were designed together rather than bolted on in sequence.

Value

Why it matters

Policy before platform

We start with IT and enterprise architecture, not with a tool deployment. Environment strategy, DLP, and Copilot policy get settled while they are still cheap to change.

Your people are already building with AI

Hundreds of licensed ChatGPT and Claude users are shipping working tools through OneDrive with none of the review a development team would apply. Governance now means having an answer for that.

Guardrails, not roadblocks

Self-service intake for environments, security groups, and DLP exceptions means makers request what they need and get it, instead of routing around IT.

The tenant, not just the platform

Power Platform and Copilot policy sit inside a wider posture — Purview for data, Intune for devices, and the Microsoft Admin Center for tenant configuration.

A community, not just a policy document

A Community of Practice, named champions, monthly sessions, and SOPs published in Teams are what make governance stick after the engagement ends.

Proven at real maker scale

One program supports roughly 1,500 active pro and low-code makers across the US, Europe, and Asia — governance that holds up across regions, not just in one business unit.

Approach

How it works

1

Align with IT and enterprise architecture

Workshops to establish policy and security guidance before the platform question gets asked, so the rules come from the people accountable for them.

2

Design the guardrails and the intake

DLP, environment tiers, RBAC-aligned security groups, and the request mechanism that provisions them without a ticket queue.

3

Stand up the community

Champions identified, a Community of Practice with a real cadence, and SOPs published where people already work.

4

Roadmap and measure

The Microsoft adoption framework turned into a roadmap your team measures and improves against over time, rather than a one-time assessment.

FAQ

Questions we hear a lot

What is a Center of Excellence?

A CoE is the combination of tooling, policy, and operating rhythm that lets an organization run citizen development at scale safely — not just low-code apps, but the agents makers are increasingly building too. Inventory, data loss prevention policies, environment strategy, and a team that reviews and enables rather than blocks. The goal is not fewer makers, it is better ones — governed by policies that do not slow them down any more than they have to.

How do we govern employees using ChatGPT and Claude for work?

Start by accepting that they already are. There are really two things to govern here: the output people build, and the population of agents doing the building. Governing output is the more familiar problem — an intake path, a review before something reaches a wider audience, a sanctioned place to publish, so makers keep their speed and the organization gets provenance. Governing shadow IT itself is the harder, newer problem, and Microsoft Agent 365 is the piece most organizations are missing: it gives every agent an identity and visibility the same way Entra and Intune already do for people and devices, so IT can see what exists instead of finding out after the fact.

We have hundreds of ungoverned apps and flows. Where do we start?

With visibility. The CoE Starter Kit inventories the estate in days, and risk triage separates the three apps touching sensitive data from the three hundred that are harmless. Policy comes after visibility — writing rules before seeing the estate produces the wrong rules.

Does governance slow down the people building apps?

Done right, it speeds them up. Clear environment paths, pre-approved connectors, and self-service provisioning remove the ambiguity that makes makers hesitate — and remove the IT firefighting that makes leadership hesitate. The intake mechanism matters more than the policy document: makers who can request an environment and get one stop building workarounds.

What does a Copilot governance policy actually cover?

Which Copilot experiences are enabled and for whom, what data they are allowed to reach, how DLP applies to AI-generated content, and where the boundaries sit between Microsoft 365 Copilot, Copilot Chat, and agent-building tools. In practice it also covers the unglamorous parts — licensing, pilot groups, and which teams get access in which order.

How do you enable a community of makers rather than just policing them?

By giving it structure. We help establish a Community of Practice, identify and equip champions, set a monthly meeting cadence, and publish SOPs and guidance in a Microsoft Teams space makers already use. Enablement is what turns a policy into a practice — governance that only restricts gets routed around.

Does this cover tenant-level security, or only Power Platform?

Both. The app and AI platform is our focus, but the policies that govern it live inside a wider tenant posture — Purview for data classification and protection, Intune for device management, and the Microsoft Admin Center for tenant configuration. We work with your IT and security teams so the platform guidance and the tenant controls agree with each other.

How do we measure whether governance is working?

We use the Microsoft adoption framework to turn the current state into a roadmap with stages your team can measure against — maker activity, environment and policy compliance, community participation, and the volume of requests that resolve through self-service rather than escalation. The point is a trend your team owns, not a score from a one-time assessment.

Sound like your situation?

Start with a free Envisioning Session — one hour of strategic ideation tailored to your goals.

Book an Envisioning Session