Where Denver Equipment's information sits, what Claude can and cannot do with it, and how you check for yourself rather than taking my word.
Stay exactly where they are now, in your SharePoint and OneDrive. Nothing gets moved, nothing gets uploaded to a new system, and there is no second copy somewhere else.
Reads from the folders you point it at, and writes back into those same folders when you ask it to. A project summary, an updated record, a drafted document. It lands in SharePoint like any other file.
At the edge of those folders. It cannot send anything anywhere, and it cannot move your files out of SharePoint and OneDrive. There is no outbound door.
That is the whole shape of it. Denver Equipment's information lives in the Microsoft environment you just moved everything into, Evan controls who can open which folder exactly as he does today, and Claude works inside those walls rather than beside them.
Which is also why this is worth doing. Thirty five years of what you have quoted, built, gotten right and gotten burned on is already sitting in those folders. Nobody can search it. Pointing Claude at it means asking “what do we usually miss on a walk-in job for a school district” and getting an answer out of your own history instead of off the internet.
Worth saying out loud, because somebody will eventually ask you and I would rather you hear it from me.
Your files stay in SharePoint. When you ask a question, the part of a file needed to answer it gets processed and the answer comes back. That processing is the same shape as an email traveling through Microsoft or a document opening from SharePoint on your phone: the content is handled under terms, and it comes back. Every cloud tool you already use works this way, including the Microsoft 365 you just moved onto.
What matters is what happens to it during that. Three commitments, and you should hold me to all three.
Not promises about good behavior. Things that are not possible because the connection does not exist.
On writing to your files.
It can create and update documents in the folders you give it, because that is most of the usefulness. It only does that when you ask, in that request. It never reorganizes, overwrites or deletes on its own initiative, and because everything lands in SharePoint you have Microsoft's own version history on all of it. If it writes something you did not want, you roll the file back the same way you would after a person did it.
You choose the folders. That is the real access control, it is your decision rather than mine, and it can change any time. Here is where I would start.
That last line is the test I would use. It does not need access to everything to be useful, and the less it can reach that it does not need, the smaller this whole question gets.
Your tax return example is the right thing to worry about, and working from your own files makes it more relevant rather than less, because now it has your real numbers to be confidently wrong about. Told to minimize something with no boundary set, it will push further than a person with professional judgment would. It does not know it crossed a line, because nobody drew the line.
So we draw them up front, in the configuration, before anyone uses it on live work. You can read these, change them, and add your own.
The first two are what make this trustworthy. An answer that names the invoice it came from is an answer Tiffany can check in thirty seconds. That is the design goal: not an assistant you have to trust, an assistant you can audit.
If any of that changes later it is a separate conversation with its own written scope, not something that quietly expands.
Five things you can check directly. I will walk you through each one.
Everything on this page is built so that when it happens you catch it, because the answer names the file it came from and a person reviewed it before it went anywhere. If anyone tells you their setup cannot be wrong, that is the part not to believe.
Back to the plan →