How Fund Evaluation Group, LLC (FEG), an independent investment management firm serving institutions, adopted Claude Enterprise safely—from the start.
FEG saw what AI could do for its business. And as a fiduciary investment advisory firm, it understood something many organizations learn the hard way: in a regulated environment, you don't adopt AI first and add controls later. Getting it right from the start is the responsible way in.
In about 2.5 weeks, FEG established a governed, validated Claude Enterprise platform with Aditi's support — giving its teams a foundation to put AI to work with the confidentiality, compliance, and control their business demands.
For a fiduciary firm, safe adoption isn't a constraint on AI — it's the way in.
FEG wasn't cautious about AI. It was deliberate about how to adopt it. In a fiduciary investment environment — where confidentiality, accuracy, approved-source use, and human review aren't optional — putting AI in front of the firm means getting the governance right before you scale, not after.
So FEG defined what "safe from day one" had to mean:
Access Control:Define who should use Claude Enterprise and which capabilities each group should have.
Department Boundaries:Separate business context across teams so users work with the right instructions and knowledge.
Connector Risk:Enable Microsoft 365 and GitHub access without bypassing existing source-system permissions.
AI Behavior:Define organization-wide and department-specific rules for how Claude should respond.
Security & Compliance:Preserve confidentiality and enforce a least-privilege access model.
Operational Ownership:Prepare FEG IT to maintain the platform after handoff.
FEG turned that standard into a structured Claude Enterprise configuration — with Aditi's support — bringing its security, access, and adoption requirements into the platform.
With Aditi's support, FEG put the following in place:
Configured members, seats, groups, custom roles, and role-based permissions. Least-privilege access ensures users receive only the capabilities required for their role; groups determine which custom role applies to each member; advanced capabilities are limited to Enterprise IT and Platform Owner roles.
Created department-level Projects with dedicated instructions and controlled access. Each business area has a dedicated Project for its workflows and context; sharing rules define access; knowledge files can provide approved department-specific context.
Implemented organization-level and project-level instructions to guide Claude responses. FEG policies and organization-level instructions take priority over project instructions, with review and escalation boundaries defined through instructions.
Configured Microsoft 365 and GitHub access with defined permission boundaries.
Applied privacy, security, least-privilege, and usage controls across the environment.
Delivered validation evidence and a Platform Owner guide for FEG IT.
New Claude Enterprise environment.
Undefined access structure.
Enterprise connector access.
Governed platform FEG IT can run and build on.
Role-based access, Projects, and instructions aligned to FEG's governance model.
Controlled Microsoft 365 and GitHub access with defined permission boundaries.
Approved user groups; read-only configuration; Claude inherits existing user permissions; users connect with their own approved corporate accounts.
Audit logging enabled; personal Claude accounts are not intended for FEG business use; connector changes require security/governance review.
Restricted to Enterprise IT; per-user authorization; repository permissions remain governed by GitHub.
Role Permissions:Confirmed roles granted expected capabilities.
Group Assignments:Validated groups were created and mapped to the correct roles.
Project Configuration:Confirmed project instructions and group assignments were in place.
Budget Controls:Validated spend-limit behavior and restriction enforcement.
Microsoft 365 Read-Only:Confirmed users could retrieve permitted content; write actions were blocked as expected.
GitHub:Confirmed Enterprise IT access and permission inheritance.
Restriction Validation:Restricted actions failed as intended.
Validation:16 validation checks executed; all 16 passed.
Negative Tests:4 negative tests confirmed restricted behavior was blocked as intended.
Transparency:Chat export requires Primary Owner access; the implementation team had Owner-level access, so that item could not be tested.