Denver Equipment × ProBusinessOps
← Back to the plan
Phase 2  ·  Read this first

Your files, your data, and the guardrails around them

Where Denver Equipment's information sits, what Claude can and cannot do with it, and how you check for yourself rather than taking my word.

The short answers

You asked four questions. Here they are.

“I want to be sure we got guardrails. I don't want stuff to get out.”
Your files stay in your SharePoint and OneDrive. There is no new place for them to live and no copy anywhere else. Claude works inside the folders you point it at, and it has no way to send anything outside them.
“As long as we know it won't start thinking too much on its own.”
It does not run on its own. No schedule, no background activity, nothing happening while nobody is asking. It works when a person asks it to and stops when the answer comes back.
The tax return example. Telling it to lower a liability and getting deductions that are not real.
That one is real, and it is the sharpest version of the concern anyone has raised with me. It is not the model being dishonest. It is the model doing what it was told while nobody told it what it must not do. That is a configuration problem, and the fix is further down this page.
“If we connect it to Inform, it won't send out a PO, it's not going to send an invoice.”
Correct, and we are not connecting it to Inform at all in this engagement. Even later, reading and writing are separate permissions, and writing would stay off.
How it works

Three steps, and there is no fourth

i

Your files

Stay exactly where they are now, in your SharePoint and OneDrive. Nothing gets moved, nothing gets uploaded to a new system, and there is no second copy somewhere else.

ii

What Claude does

Reads from the folders you point it at, and writes back into those same folders when you ask it to. A project summary, an updated record, a drafted document. It lands in SharePoint like any other file.

iii

Where it stops

At the edge of those folders. It cannot send anything anywhere, and it cannot move your files out of SharePoint and OneDrive. There is no outbound door.

That is the whole shape of it. Denver Equipment's information lives in the Microsoft environment you just moved everything into, Evan controls who can open which folder exactly as he does today, and Claude works inside those walls rather than beside them.

Which is also why this is worth doing. Thirty five years of what you have quoted, built, gotten right and gotten burned on is already sitting in those folders. Nobody can search it. Pointing Claude at it means asking “what do we usually miss on a walk-in job for a school district” and getting an answer out of your own history instead of off the internet.

One piece of plumbing

What happens when you ask a question

Worth saying out loud, because somebody will eventually ask you and I would rather you hear it from me.

Your files stay in SharePoint. When you ask a question, the part of a file needed to answer it gets processed and the answer comes back. That processing is the same shape as an email traveling through Microsoft or a document opening from SharePoint on your phone: the content is handled under terms, and it comes back. Every cloud tool you already use works this way, including the Microsoft 365 you just moved onto.

What matters is what happens to it during that. Three commitments, and you should hold me to all three.

Hard limits

What it structurally cannot do

Not promises about good behavior. Things that are not possible because the connection does not exist.

×Send an email. It drafts into your drafts folder and a person presses send.
×Move, copy, or publish a file to anywhere outside your SharePoint and OneDrive
×Create, approve, or transmit a purchase order
×Reach a folder, system, or record you have not pointed it at
×Post an invoice or touch anything in Inform or AutoQuotes
×Run on a schedule, or do anything while nobody is asking it something

On writing to your files.

It can create and update documents in the folders you give it, because that is most of the usefulness. It only does that when you ask, in that request. It never reorganizes, overwrites or deletes on its own initiative, and because everything lands in SharePoint you have Microsoft's own version history on all of it. If it writes something you did not want, you roll the file back the same way you would after a person did it.

Access

Deciding what it can see

You choose the folders. That is the real access control, it is your decision rather than mine, and it can change any time. Here is where I would start.

✓Past invoices and the quotes they came from
×Payroll, employee records, anything with a Social Security number
✓Completed project records, including what went wrong
×Banking details and payment credentials
✓Supplier performance and lead time history
×Anything a customer gave you under a confidentiality agreement, unless you check that agreement first
✓Standard specs, drawings, and your own reference material
×Anything you would not want a new employee reading on day one

That last line is the test I would use. It does not need access to everything to be useful, and the less it can reach that it does not need, the smaller this whole question gets.

The real risk

Confidently wrong is the failure mode, not going rogue

Your tax return example is the right thing to worry about, and working from your own files makes it more relevant rather than less, because now it has your real numbers to be confidently wrong about. Told to minimize something with no boundary set, it will push further than a person with professional judgment would. It does not know it crossed a line, because nobody drew the line.

So we draw them up front, in the configuration, before anyone uses it on live work. You can read these, change them, and add your own.

Standing instructions, configured at setup
  • Never state a figure you cannot trace to one of our documents. Name the file.
  • If it is not in our files, say so. Do not fill the gap from general knowledge.
  • Do not estimate unless I ask for an estimate, and label it clearly as one.
  • Rate your confidence on every substantive claim: certain, likely, or uncertain.
  • Do not apply a rule, code, price, or standard you cannot cite the source for.
  • Never produce correspondence, an order, or a filing as a final action. Draft it for review.
  • When an instruction could be satisfied by bending a rule, stop and ask instead.
  • Never change or delete an existing file unless I tell you to in that request.

The first two are what make this trustworthy. An answer that names the invoice it came from is an answer Tiffany can check in thirty seconds. That is the design goal: not an assistant you have to trust, an assistant you can audit.

Boundaries

What we will not do in Phase 2

×Connect Claude to Inform or AutoQuotes, in either direction
×Put any Denver Equipment file anywhere outside your SharePoint and OneDrive
×Enable automatic sending of any email
×Give anyone a seat that has not been configured with the instructions above
×Point it at payroll, banking, or personal employee records
×Turn on any connection to an outside system

If any of that changes later it is a separate conversation with its own written scope, not something that quietly expands.

Verify it yourself

You should not have to take my word

Five things you can check directly. I will walk you through each one.

One thing I am not going to pretend

No configuration makes a wrong answer impossible. It will occasionally be confident and wrong, the same way a capable new employee is.

Everything on this page is built so that when it happens you catch it, because the answer names the file it came from and a person reviewed it before it went anywhere. If anyone tells you their setup cannot be wrong, that is the part not to believe.

Back to the plan →