Skip to content
Resolved

AI & Automation | AI Security & Governance

Your team already uses AI. Make it safe.

The question isn’t whether your people are using AI. They are. The question is whether it’s happening on your terms, with your data protected and a policy everyone understands. We close the gap between how fast your team adopts AI and how well it’s governed.

Not sure where your senior time is going? Take the free senior time-back check

Already a Resolved client? This folds onto your managed services as an add-on.

Line-art illustration of an AI shield with guardrails, a lock, and a policy document

The Risk You Can’t See

The gap between adoption and oversight is where risk lives

Most firms have no formal AI governance. Teams use AI tools every day, and the space between what they’re doing and what’s actually governed is exactly where the exposure sits.

Shadow AI

Your team is using ChatGPT, Copilot, and other tools without IT visibility. Project data, drawings, and client information are leaving the building, and no one can see where.

Policy Gaps

Your IT and security policies weren’t written for AI. The gap between how your people actually work and what’s governed grows wider every month.

IP & Data Exposure

Designs, financials, and client data processed by consumer AI tools with unclear retention, no audit trail, and real regulatory exposure.

Why Now

A foundation now beats a cleanup later

AI adoption is moving faster than AI strategy. Most firms are improvising, with no policy and no oversight. The ones that put a governance foundation in place now will move faster and more safely as capabilities expand. The ones winging it will hit a wall.

You’re in the sweet spot: established enough to benefit from AI across the firm, nimble enough to actually deploy it. Get the guardrails right, and AI becomes a competitive advantage instead of a liability.

What You Get

From shadow AI to sanctioned strategy

Shadow AI Discovery & Inventory

A full picture of the AI tools in use across your firm, including the ones adopted without IT involvement.

AI Acceptable Use Policy

Approved tools, data-handling rules, and approval workflows, written in plain language for your team.

AI Risk Assessment

An exposure evaluation mapped to the NIST AI Risk Management Framework, so the gaps are named and prioritized.

DLP & Access Controls

Controls that stop sensitive data from reaching unauthorized AI platforms in the first place.

Executive AI Strategy Coaching

Guidance for leadership on adopting AI safely and strategically, not just defensively.

Ongoing Governance

Quarterly reviews, shadow-AI monitoring, vendor assessments, and regulatory briefings as the landscape shifts.

Levels of Control

Choose the right level for your firm

Whether you need a starting point or a fully managed program, there’s a tier that fits. Each one builds on the last.

AI Watch

Visibility and a baseline.

  • Shadow AI monitoring
  • Basic DLP rules
  • Quarterly policy review
  • New-tool detection alerts
Most Popular

Governance Program

A managed governance foundation.

  • Everything in AI Watch
  • NIST AI RMF risk assessment
  • Full DLP & access controls
  • Quarterly executive coaching

Governance Plus

Active, audit-ready oversight.

  • Everything in Program
  • Active vendor risk management
  • Regulatory update briefings
  • Quarterly leadership workshops

vCISO + Governance

An embedded security executive.

  • Everything in Plus
  • Embedded fractional AI/security executive
  • Audit handling (SOC 2, ISO, NIST)
  • Board reporting & exec dashboards

Monthly programs are scoped to your environment. We’ll walk through the right tier on a discovery call. A note on training: we focus on AI risk, security, and governance. Hands-on, tool-specific staff training is delivered through our trusted training partners.

In Their Words

What clients say

Reid was highly professional and provided highly specific advice to our business. His transparency and communication skills made the process so much easier than our previous provider. We fully understood what we were getting after one conversation, where other IT firm proposals left us confused. Reid also went above and beyond and outlined some security risks we were taking and sorted them out quickly.

Sarah | Office Manager

We have worked with Resolved for many years and have consistently been impressed with their professionalism and proactive approach. ... We would confidently recommend them to any firm looking for a reliable, forward-thinking IT provider.

Lee Campbell | President

Core One Consulting

Their response times to problems are always lightning quick. They are knowledgeable when it comes to troubleshooting and always suggest ways to improve security and management on the IT side. Always a pleasure to talk to.

Stiles | Operations

Trusted by firms like yours

Formosis Architecture logoKirsten Reite Architecture logoCore One Consulting logo

FAQ

AI security and governance questions

Do we need an AI acceptable-use policy for our firm? +

Most firms have no formal AI governance even though their teams use AI tools every day, and that gap is exactly where the exposure sits. We write an AI Acceptable Use Policy in plain language for your team, covering approved tools, data-handling rules, and approval workflows.

Is it safe to let our team use Copilot and other AI tools with client data? +

It can be, once it happens on your terms. The risk today is consumer AI tools processing designs, financials, and client data with unclear retention and no audit trail. We put data-loss prevention and access controls in place that stop sensitive data from reaching unauthorized AI platforms in the first place, so your data stays protected.

What is shadow AI and how do you find it? +

Shadow AI is your team using tools like ChatGPT and Copilot without IT visibility, so project data, drawings, and client information leave the building with no one able to see where. We run a shadow-AI discovery and inventory to give you a full picture of the AI tools in use across your firm, including the ones adopted without IT involvement.

What framework do you use to assess our AI risk? +

We run an AI risk assessment mapped to the NIST AI Risk Management Framework, so the gaps are named and prioritized rather than guessed at.

What does the Strategic AI Assessment include, and do we keep the deliverables? +

The first step is a shadow-AI discovery scan that baselines your usage, an AI usage policy, a risk and governance framework, and a prioritized 24-month roadmap. It starts with a free 30-minute call, the deliverables are yours to keep whether or not you continue with us, and if you proceed the cost is credited toward Managed AI.

Start Here

Strategic AI Assessment

The first step is a shadow-AI discovery scan that baselines your usage, an AI usage policy, a risk and governance framework, and a prioritized 24-month roadmap. You walk away knowing exactly where you stand, whether or not you continue with us.

Starts with
A free 30-minute call
Deliverables
Yours to keep
If you proceed
Credited toward Managed AI
Framework
NIST AI RMF