It is deciding which data may touch which system, in what order, and who signs off on what comes out. Get that wrong and the tool does not matter. Get it right and most of the tooling questions answer themselves.
The first one is duller and it is the one that decides whether any of this survives contact with your business.
Your customer records, your contracts, your financials, and your HR files do not all carry the same exposure. Treating them as one pile โ "our data" โ is how a sensible pilot becomes a problem nobody planned for.
Sequence is a control. What gets retrieved before what, what is allowed to inform what, and where a step has to stop and wait โ these determine what the system can actually produce, and they are decisions, not settings.
A named person accountable for what goes out the door. Not a committee, not "the team", not the tool's own confidence score. If nobody owns the output, the organization has not deployed AI โ it has distributed a liability.
Most stalled AI efforts did not pick the wrong product. They picked a product first, then discovered that the data it needed could not be put where it needed to be, or that no one would put their name to what came out. The decisions above are portable โ they survive changing your mind about tooling. The tooling choice is not portable and should therefore come second.
The tiers describe where a workload sits and what protects it there. They are matched to data, not to how advanced a company is.
The ordinary consumer-grade services anyone can sign up for. Appropriate for public and low-sensitivity data only โ material you would be comfortable seeing outside the business, because you have no contractual control over what happens to it.
The same class of capability bought under a commercial agreement, where the protections are contractual: training exclusion, SSO, audit logging, and retention control. Suitable for internal business data.
Deployed inside your own cloud tenant. Your documents, your keys, and your logs stay inside your boundary. Appropriate for your most sensitive material and for anything with a regulatory obligation attached.
This is the distinction most often got wrong, and it is worth being blunt about. An enterprise tenant does not put a wall around your data โ the data still leaves your environment. What you are buying is a set of commitments about how it is handled once it does: that it will not be trained on, that access is tied to your identity system, that use is logged, that retention is bounded. Those are real and they are enforceable, and they are also a different kind of protection from Tier 3, where the data does not leave at all. Do not let a Tier 2 agreement stand in for a Tier 3 requirement.
Most companies need all three at once, for different data. The public tier for public material, the enterprise tier for ordinary internal work, the private tier for what genuinely requires it. There is no version of "maturity" in which a business graduates off Tier 1 โ it will always have public-facing work that belongs there, and paying to run that inside a private deployment is waste, not rigour. The exercise is matching each body of data to the tier that fits it, then holding that line.
Each option contains the one before it. Where you start depends on how much you intend to run yourselves.
The decisions above, made and written down for your business.
This is a complete deliverable that you own โ not a lead-in, not a discovery phase you have to buy something else to benefit from. You can take it and execute it with your own people, or with someone else entirely, and it still does its job.
Everything in Assessment & Plan, plus one process actually built.
A pilot that spans four departments cannot tell you what worked. One process in one department, measured against how it ran before, produces an answer your own people can check โ and a reason to continue or stop that is not a matter of opinion.
Everything above, plus Tier 3 built in your tenant and run for you.
The tenant is yours from the first day, not transferred at the end. The handoff path is documented as the work is done, so bringing this in-house is a decision you can make on your own timetable rather than a negotiation. Fractional operation is a staffing answer to a gap, not a dependency to be maintained.
The common approach is to buy a handful of individual licenses, give them to whoever asked first, and wait for it to spread. It does not spread. The people who volunteered were already going to find their way to it, and the work they do it on is their own โ so nothing in how the department operates changes.
Enablement here is department-level and team-based, built around a real working problem the team already has. Not a generic curriculum, not a sandbox exercise โ a piece of work that is genuinely on their plate, worked through together, using the tier that their data actually permits.
What a team keeps afterwards is the judgement, not the trick: which of their material belongs in which tier, where a human has to sign off, and how to tell a useful output from a confident one.
Adoption is measured in seats issued. The enthusiasts get better at their own tasks, everyone else carries on as before, and the department's actual process is untouched. Nobody learns which data belongs where, because nobody was asked to decide.
The whole team works one live problem end to end. The tier boundaries get exercised on real material, the sign-off step gets rehearsed by the person who will own it, and what changes is how the department does that work โ not how three individuals do theirs.
A first conversation is about which of your material is genuinely sensitive, what has to stay inside your own tenant, and who would sign off on the output. Those answers shape everything after them โ including whether we are the right people for it.