Picture a steering committee four months into a Copilot pilot. The results look promising: strong adoption, positive feedback, and an hours-saved estimate already validated by finance. Everyone is ready to discuss expanding the program.
Then the CISO asks a seemingly simple question: If we turn this on for everyone, what will it be able to read?
The room goes quiet. No one can say with evidence what thousands of employees and their AI agents could access once Copilot is deployed at scale. Not the security lead, the platform team, or the person who ran the pilot. Someone agrees to “pull together a fuller picture,” and the expansion slips to the next quarter. No one rejects the project. It simply stops moving, which in most enterprises leads to the same result.
The steering committee described above is a composite drawn from patterns we see repeatedly, no a single client engagement.
Get Unstuck with MosaicStack
Created by MajorKey, MosaicStack is a three-day workshop that delivers a prioritized, board-ready roadmap for scaling AI securely across the Microsoft ecosystem you already own.
Instead of a maturity score or a lengthy assessment that gets reviewed once and shelved, you leave with a practical, sequenced plan. Identity, data, and architecture priorities are mapped in the order they need to happen, giving executives a clear investment strategy and technical teams a roadmap they can immediately execute.
MosaicStack brings an identity to AI readiness. Because AI risk ultimately comes down to who or what can access sensitive data, MajorKey evaluates AI adoption through the interconnected foundations of identity, access, data governance, security, and architecture. This approach helps organizations identify gaps that broader technology assessments may overlook.
AI is not a standalone initiative. AI influences how people work, how data is accessed and governed, and how risk is managed across the organization. Every AI decision is also an identity, data governance, and licensing decision. When those workstreams are managed independently, gaps emerge that often surface later during audits, compliance reviews, or customer security assessments.
Day One: Count Everything, Especially What You Can't See
The first day is about inventorying: every relevant control across your Microsoft and third-party environments, from privileged identity management and threat protection to data classification and shadow AI. Third-party visibility matters because few organizations operate within a single vendor ecosystem. An inventory that only sees Microsoft isn't a complete inventory.
The most valuable findings often come from shadow AI. Long before an organization launches an official AI initiative, employees are already experimenting with tools that access company data. Those tools can create blind spots around governance, security, and compliance. Day one is about uncovering what's already happening so leadership can make informed decisions based on reality rather than assumptions.
The other half of day one focuses on capabilities you already own but aren't using. Features left disabled, overlapping tools, unfinished integrations, and outdated assumptions often surface before budget discussions begin. That's exactly when you want to find them.
Day Two: Decide What Is Off Limits
Day two turns the inventory into decisions. Together, we define policies, sensitivity labels, and guardrails that determine what an agent can access before wider Copilot deployments begin.
These discussions often reveal competing priorities between security teams and business leadership. Security teams want stronger controls, while business leaders want to enable productivity without creating unnecessary friction. The workshop process helps establish practical guardrails everyone can support.
By the end of the day, the organization will have documented answers to previously unresolved questions:
- Which data sources are in scope?
- How are prompts and outputs are handled?
- Who approves new AI agents?
- What protections does each sensitivity label provide?
With these questions addressed, the organization has a governance framework that supports broader AI adoption.
Day Three: Build Something a Board Will Support and Pay For
Day three turns the work of the first two days into a roadmap that leaders can act on. MajorKey consultants work with stakeholders to establish priorities, sequence investments, and present the outcomes in terms executives, finance teams, and boards can evaluate.
The roadmap is organized into clear phases, with each initiative assigned an owner, key dependencies, an estimated effort or cost range, and a defined risk if it is delayed. By linking investment decisions directly to business risk, the roadmap becomes a practical tool for planning, budgeting, and accountability.
The final deliverable includes a concise executive summary and a clearly articulated risk position designed for discussion with boards, auditors, customers, and other stakeholders.
Strong governance alone rarely secures funding. Decision-makers invest in outcomes they can understand, prioritize, and defend. A roadmap that connects business objectives, investment requirements, and risk exposure gives leaders the context they need to move forward with confidence.
MosaicStack Creates Tangible Output in Less Than a Week
At the end of the workshop, you’ll have:
- A comprehensive inventory of identified AI usage and relevant controls across your Microsoft and third-party environments, including shadow AI operating outside formal governance.
- A documented governance framework that defines labels, access boundaries, restricted repositories, and approval processes for new AI agents.
- A phased roadmap with clear owners, dependencies, cost ranges, and a transparent view of the risks associated with delaying each initiative.
- An executive-ready summary and risk position that can be shared with boards, auditors, customers, and other stakeholders.
- A licensing strategy that identifies underused capabilities, potential consolidation opportunities, and whether Microsoft 365 E7 supports your broader AI roadmap.
- Organizational alignment across security, IT, data, legal, and business stakeholders around a shared understanding of priorities, risks, and next steps.
The first five are tangible deliverables. Stakeholder alignment is what turns them into action instead of shelfware.
Before You Scale, Know What You're Scaling
Many organizations struggle to move beyond AI pilots because they lack clarity around risk, access, ownership, and investment priorities. MosaicStack brings those decisions together in three days, providing a clear picture of the current environment, practical governance guardrails, and a prioritized roadmap leadership can support.
The next time someone asks, "If we turn this on for everyone, what will it be able to read?" your team will have a documented answer backed by visibility, governance, and shared accountability.
Ready to move AI forward with greater confidence? Request a MosaicStack workshop to uncover hidden risks, align stakeholders, and build an actionable roadmap for secure AI adoption.