They had bought Claude for proposal work. Their files also held sensitive customer, finance and HR content. Before anything was connected, we scanned about 240,000 files, scored the tenant on eight competencies, and designed the boundary that keeps sensitive sites out of Claude's reach.
The company had bought a company-wide Claude plan for proposal and marketing work. Its Microsoft 365 connector reaches whatever the signed-in person can open, and nobody could say with certainty what that was. Until someone could, it stayed unconnected.
Assess the Microsoft 365 environment, show what a connected Claude would see, and set out what has to be true before it connects. Without anyone from Floor 16 opening a sensitive document.
A metadata-only scan of every SharePoint site, interviews across leadership, engineering, operations and project management, scores across eight competencies, a boundary design for Claude, a storage runway, and a fix list in five workstreams.
Eight competencies. The four Claude depends on scored lowest.
Which sites Claude may see, which it can't, and how to prove it.
A capacity deadline found, and about three years of runway designed.
Five workstreams, about 40 items, each one taken on its own.
We scored the tenant on the eight competencies of the Microsoft 365 maturity model, from Initial (100) to Optimizing (500). Adoption was strong. Content, search, governance and AI, the four a tenant-wide AI connector depends on, all sat at Initial.
Mock-up. Levels as reported; layout and labels simplified.
The question moved from when to turn Claude on to what has to be true first.
Claude's Microsoft 365 connector acts as the signed-in person. It searches the tenant within that person's permissions, and at the time of the assessment it could not be limited to one site from the Claude side. So the boundary has to be built in Microsoft 365, site by site.
Open to Claude, closed to Claude, or decide first. No mixed sites.
Restricted Content Discovery takes closed sites out of the search Claude depends on.
Encrypting sensitivity labels keep files closed to Claude, even for people who work on that site.
Every closed site is tested before Claude connects. The evidence is that nothing comes back.
"What would Claude see?" got a written answer: a site map, two controls, a test, and a working set of about 3,000 current documents.
| Site | Label | Hidden | Encrypted | Claude sees |
|---|---|---|---|---|
| Open to Claude · 4 sites | ||||
| Brand and Marketing | Public | |||
| Policies and Handbooks | Internal | |||
| Quality and Procedures | Internal | |||
| Proposal Library | Internal | |||
| Closed to Claude · 4 sites | ||||
| Project Delivery | Confidential | |||
| Finance and Legal | Restricted | |||
| People and HR | Restricted | |||
| Old Projects Archive | Archive | |||
| Decide first · 1 site | ||||
| Live Bids | Closed for now | |||
Mock-up with made-up site names. The real site map has the same structure.
The scan found SharePoint within about 70 GB of its licensed storage pool, with close to 300 GB added in the past eight months. On that path the tenant would reach its limit within a couple of months and go read-only soon after. Archiving inactive files, rather than buying space or deleting anything, would buy about three years.
Mock-up. Totals rounded from the report; the curve is illustrative.
The storage problem got a date, a cost for both paths, and a plan that deletes no business content.
Every finding became an item of work, about 40 in all, grouped by what each one depends on rather than by date. Each workstream can be taken on its own. The report carried no pricing: the client chose what to scope after the walkthrough.
A plan the client could take one piece at a time, with the reason for the order written next to each piece.
Mock-up. Workstreams as reported; wording shortened.
Claude was already paid for, so we laid out three ways to run it, from useful today to connected for everyone. We also asked security to rule on one question first: must the data never train a model, or never leave its home region? What Claude can see and where it runs are separate questions, and the design branches on the answer.
| Way to run Claude | Live Microsoft 365 connection | Useful on day one | Needs the boundary first |
|---|---|---|---|
| Curated Claude ProjectsOnly vetted content, added by hand | |||
| Scoped accountOne login with trimmed permissions | |||
| Governed rolloutEveryone, inside the tested boundary |
If full residency becomes the requirement, that is a separate build: Claude through a cloud provider's in-region endpoint, with the model confirmed in that region first.
At the walkthrough, leadership put licensing first, then classification, then Claude. The follow-on work is scoped as separate workstreams, each priced on its own, with the secure AI foundation first.
issues ranked by urgency, each with the workstream that fixes it and a reason for the order.
decides when Claude connects: a test account tries every closed site, and nothing comes back.
Claude stays useful through curated Projects for proposals and marketing, with no connector and no licensing change.
Thirty minutes on what's in your tenant, who can open it, and what Claude, or any connected assistant, would reach.