MIP — Frequently asked questions
15 questions, grouped, with real answers.
Getting started
Do I need to be a current ACS managed services client?
No. MIP is a separate practice. We have MIP clients who use a different MSP (or no MSP) for their general IT. We will coordinate with your existing IT vendor when needed.
Can I buy just the Assessment?
Yes. About a third of Assessment clients do. The Assessment is sold as a standalone product. If you want the report and the roadmap and intend to implement with someone else (or yourself), that’s a fine outcome. Assessment details.
We’ve already started with AI — are we too late?
No. Most of our clients started with AI before MIP. The shape of the engagement is different — we don’t have to introduce the concept; we have to bring measurement, governance, and operating discipline to what’s already happening. Usually starts with an Assessment that catalogs the existing state.
What’s the minimum size?
Ten users for ongoing MIP service. No minimum for the Assessment. Under 10 users, the per-user math doesn’t work for either side; we’ll refer you to providers who serve smaller teams.
How it works
Where do the AI tools actually run?
Three options, picked per workflow: inside your Microsoft 365 tenant (Copilot, Copilot Studio, Azure OpenAI in your subscription); inside ACS Automate (our hosted environment, audited access to your systems); or hybrid. Strategic tier can also deploy on-prem (Ollama or equivalent) for ITAR/CMMC-controlled work.
Do you use my data to train anything?
No. We do not train models on your data. Microsoft does not train on your Copilot prompts or outputs under the standard Microsoft 365 data processing terms. Any third-party AI tool we evaluate goes through a documented vendor due diligence step that includes “training data policy”; tools that train on customer data without explicit opt-in do not get added to your Approved Tool Registry. The Governance Framework documents this explicitly.
Who owns the prompts and agents you build for us?
You own them. The prompts and the agent configurations are yours, documented in your environment, exportable. Our operating know-how — how we build, instrument, and maintain them — is ours. We do not lock your workflows behind a proprietary platform. If you cancel, you can take the prompts and agents with you and re-host them.
What happens if we cancel?
We help you offboard. You get every artifact: the AUP, the Tool Registry, the agent configurations, the ABR history, the Assessment data files. We disable our access to your tenant. We transition help desk access cleanly. Our standard contract has a 30-day notice; we don’t have lock-in clauses.
Do you work with our existing IT vendor?
Yes. We work with your MSP, your internal IT, or both. The hand-off points are clear: they run your IT, we run your AI. Some overlap on identity and DLP, which we coordinate with them on. Most existing IT relationships improve when MIP is added — your IT people stop being asked questions they aren’t trained to answer.
Risk and compliance
What if employees won’t follow the policy?
We expect non-compliance and design for it. The Governance Framework includes monitoring (Defender for Cloud Apps or equivalent), conditional access blocks on personal AI accounts for company devices, and an incident response playbook. The first time an associate pastes a privileged document into personal ChatGPT, our monitoring catches it. The Framework defines the response — coaching, retraining, documentation. Most violations are first-time and innocent; the second-time pattern is rare when the training is real and the enforcement is technical, not aspirational.
How do you handle HIPAA / ITAR / CMMC / state bar rules?
– HIPAA: Copilot in your tenant under a signed BAA; no PHI in tools outside the BAA; access and audit logging consistent with §164.308 and §164.312.
– ITAR: Microsoft 365 GCC High for tenant-resident AI; U.S. persons only on operations; no commercial-cloud LLMs on controlled technical data; on-prem deployment available in Strategic for fully controlled environments.
– CMMC Level 2: AI tooling mapped against the 110 controls; we produce the evidence artifacts your C3PAO will ask for; coordination with your assessor included.
– State bar AI rules: Current opinions in California, New York, Florida, and a growing list of states inform the AUP. We update the Framework within 30 days of new bar guidance.
The general principle: we don’t get cute with regulated data. If the rules require in-tenant or on-prem, we deploy in-tenant or on-prem. Cost difference is reflected in the tier and the project pricing.
What insurance do you carry?
General liability, professional liability (E&O), cyber liability — all current, all with limits appropriate to the practice. Certificate available on request to clients during contracting. We do not publish specific limits on the public site; ask during the proposal review.
What if an AI output causes a problem?
The Incident Response Playbook covers it. Categories: factually wrong output that affected a deliverable; data exposure through AI; vendor incident; regulatory inquiry. Each has a defined response sequence. The first step is always to preserve the evidence — the prompt, the output, the audit trail. We help you run the response. Liability allocation is in the Master Service Agreement, which we’ll send during the proposal phase.
Is anything you do covered by the existing MSP MSA, or is this all new contracts?
New contracts. MIP is a separate practice with a separate MSA. If you’re a current ACS managed services client, we’ll align signing dates so renewals don’t drift, but the agreements are separate. This is intentional — different scope, different liability shape, different deliverables.
Anything else?
If your question isn’t here, the discovery call is the right next step. 15 minutes, no pitch.
Book an AI Readiness Assessment
Ready when you are.
Three weeks. Fixed fee. A real report and a 90-day roadmap. You keep it whether you hire us or not.