Rosebud Cloud Solutions
Home
AI Governanceexpand_more
Case Studies
About
lockPortal login
Rosebud Cloud Solutions

Engineering the next generation of cloud experiences. We blend technical gravitas with aesthetic precision to build systems that scale.

Solutions

  • Azure Consulting
  • Cloud Architecture
  • Cloud Optimisation
  • Email Domain Security
  • Cloud Security & Compliance
  • Security Automation
  • Managed Cloud Support
  • AI Governance
  • Free Security Check
  • Free AI Scorecard
  • Partner Programme

Company

  • How We Work
  • About Us
  • Meet the Team
  • Insights
  • Reports
  • FAQ
  • Contact

Connect

  • LinkedIn
  • Instagram

© 2024–2026 Rosebud Cloud Solutions Ltd

Company No. 14500087  ·  VAT No. 439 921 563  ·  Registered in England & Wales

Privacy Policy
Governed AI · Step 1 · Assess

Most firms don't have an AI problem.They have an AI pilot problem.

Copilot trials. Chatbots. A spreadsheet quietly wired into something nobody formally approved. This assessment finds what is actually running in your environment, tells you where the risk sits, and gives you a plan, in two to three weeks, not a six-month consulting cycle.

The Problem

Nothing shows up until something goes wrong

Most organisations cannot answer three basic questions about the AI already in their business. What AI and agents are running right now, sanctioned and shadow? What data do they touch, and where does it go? And if a regulator or auditor asked us to prove any of this is governed, could we?

None of that surfaces until the failed audit, or the agent that had no logging. By then it is not a config tweak, it is an incident. The assessment names that risk before it becomes one.

psychology_alt

What AI and agents are running right now, sanctioned and shadow?

database

What data do they touch, and where does it go?

gavel

If an auditor asked us to prove this is governed, could we?

Deliverables

What's Included

travel_explore

Discovery

A full inventory of AI systems and agents across Microsoft 365 and Azure, including unsanctioned shadow AI: Copilot usage, third-party tools on company devices, and citizen-built agents in Copilot Studio.

rule

Risk Classification

Each system mapped against EU AI Act high-risk categories (recruitment, credit scoring, employment decisions and similar) and the obligations specific to your sector.

account_tree

Data-Flow Mapping

What data reaches which models, where it is stored, and where the gaps are, so the conversation about exposure is based on evidence rather than guesswork.

radar

Posture Snapshot

A current-state view of your governance controls across Microsoft Entra, Purview and Defender for Cloud, scored against a governed baseline.

checklist

90-Day Roadmap

A prioritised action plan with owners and effort estimates, not a wish list. Ranked so your team knows exactly what to fix first and why.

co_present

Readout

A written report plus a working session with your technical and compliance leads, so the findings land with the people who have to act on them.

Who It's For

Regulated firms where getting AI wrong has real consequences

Heads of Engineering, CTOs and Compliance or Risk leads at mid-market firms, roughly 50-300 users, in financial services, legal, recruitment or professional services.

Best fit: organisations already running AI pilots and starting to ask "why are we suddenly responsible for something we didn't design properly?"

Outcomes
inventory_2

A complete, written inventory of what AI is running

low_priority

A risk-classified backlog that removes the guesswork

verified

A defensible written compliance position for boards and examiners

route

A clear, costed next step

Fixed Price, Fixed Scope
£12,500standard scope, fixed
Narrow, single-entity scopefrom £9,500
Regulated depth (full EU AI Act mapping, multi-entity)from £15,000

Scoped to typical mid-market estates (50-300 users, up to 5 subscriptions). Reduced when bundled with the Governed AI Landing Zone.

What We Need From You

Light on your team, by design

check_circle

Read-only access (Reader, Security Reader and Purview), granted under NDA and time-boxed to the engagement

check_circle

A list of the AI tools, pilots and agents you already know about

check_circle

One engineering contact and one compliance or risk contact, roughly 2-3 hours each across the engagement

The timeline runs from access being granted. We share a full pre-kickoff checklist once an engagement is agreed, and we chase access hard in week zero because it is the only thing that ever slips a timeline.

After the Assessment · Step 2

Governed AI Landing Zone

The roadmap points at the build: a governed foundation that fixes what the assessment found. Discounted when it follows an assessment.

arrow_forward

KNOW WHAT'S RUNNING.
IN THREE WEEKS.

A 30-minute discovery call is enough to scope the assessment and confirm the fixed price.