Getting AI Right
from Day One

How Fund Evaluation Group, LLC (FEG), an independent investment management firm serving institutions, adopted Claude Enterprise safely—from the start.

FEG saw what AI could do for its business. And as a fiduciary investment advisory firm, it understood something many organizations learn the hard way: in a regulated environment, you don't adopt AI first and add controls later. Getting it right from the start is the responsible way in.

In about 2.5 weeks, FEG established a governed, validated Claude Enterprise platform with Aditi's support — giving its teams a foundation to put AI to work with the confidentiality, compliance, and control their business demands.

2.5 weeks
Handoff readiness
16 of 16
Validation Checks
2
Enterprise Connectors
THE CHALLENGE

Turning Claude Enterprise Access Into a Governed AI Platform

For a fiduciary firm, safe adoption isn't a constraint on AI — it's the way in.

FEG wasn't cautious about AI. It was deliberate about how to adopt it. In a fiduciary investment environment — where confidentiality, accuracy, approved-source use, and human review aren't optional — putting AI in front of the firm means getting the governance right before you scale, not after.

So FEG defined what "safe from day one" had to mean:

Access Control:Define who should use Claude Enterprise and which capabilities each group should have.

Department Boundaries:Separate business context across teams so users work with the right instructions and knowledge.

Connector Risk:Enable Microsoft 365 and GitHub access without bypassing existing source-system permissions.

AI Behavior:Define organization-wide and department-specific rules for how Claude should respond.

Security & Compliance:Preserve confidentiality and enforce a least-privilege access model.

Operational Ownership:Prepare FEG IT to maintain the platform after handoff.

THE SOLUTION

How FEG Built Its Access Model

FEG turned that standard into a structured Claude Enterprise configuration — with Aditi's support — bringing its security, access, and adoption requirements into the platform.

With Aditi's support, FEG put the following in place:

Access Foundation:

Configured members, seats, groups, custom roles, and role-based permissions. Least-privilege access ensures users receive only the capabilities required for their role; groups determine which custom role applies to each member; advanced capabilities are limited to Enterprise IT and Platform Owner roles.

Department Enablement:

Created department-level Projects with dedicated instructions and controlled access. Each business area has a dedicated Project for its workflows and context; sharing rules define access; knowledge files can provide approved department-specific context.

Behavior Governance:

Implemented organization-level and project-level instructions to guide Claude responses. FEG policies and organization-level instructions take priority over project instructions, with review and escalation boundaries defined through instructions.

Connector Control:

Configured Microsoft 365 and GitHub access with defined permission boundaries.

Security Alignment:

Applied privacy, security, least-privilege, and usage controls across the environment.

Operational Readiness:

Delivered validation evidence and a Platform Owner guide for FEG IT.

BEFORE AND AFTER
Before
1.

New Claude Enterprise environment.

2.

Undefined access structure.

3.

Enterprise connector access.

After
1.

Governed platform FEG IT can run and build on.

2.

Role-based access, Projects, and instructions aligned to FEG's governance model.

3.

Controlled Microsoft 365 and GitHub access with defined permission boundaries.

IMPLEMENTATION SCOPE
20 Claude Enterprise seats at implementation, with an expected future increase to approximately 30.
7 custom roles and 17 groups supporting the least-privilege access model.
17 Department Projects and 18 documented organization- and project-level instructions.
2 enterprise connectors configured: Microsoft 365 and GitHub.
THE CONTROLS THAT MAKE SAFE ADOPTION REAL

Microsoft 365

Approved user groups; read-only configuration; Claude inherits existing user permissions; users connect with their own approved corporate accounts.

Microsoft 365 Guardrails

Audit logging enabled; personal Claude accounts are not intended for FEG business use; connector changes require security/governance review.

GitHub

Restricted to Enterprise IT; per-user authorization; repository permissions remain governed by GitHub.

TECHNOLOGY

What Was Used and Configured

Platform: Claude Enterprise
Connectors: Microsoft 365 & GitHub
THE RESULTS

What FEG Can Do Now

1.
A Safe Foundation for Broader AI Adoption, From Day One.
2.
Least-Privilege Access, by Design.
7 custom roles and 17 groups provide a structured access model.
3.
Department-Specific Governance, Structured by Context.
17 Department Projects and 18 documented instructions establish defined boundaries for how each business area uses Claude.
4.
Controlled Enterprise Connectivity.
2 connectors — Microsoft 365 and GitHub — were configured with defined permission boundaries.
5.
A Foundation FEG IT Can Own.
The implementation reached handoff readiness in approximately 2.5 weeks, with a Platform Owner guide delivered.
DELIVERY PROOF

Evidence That the Adoption Is Safe

Role Permissions:Confirmed roles granted expected capabilities.

Group Assignments:Validated groups were created and mapped to the correct roles.

Project Configuration:Confirmed project instructions and group assignments were in place.

Budget Controls:Validated spend-limit behavior and restriction enforcement.

Microsoft 365 Read-Only:Confirmed users could retrieve permitted content; write actions were blocked as expected.

GitHub:Confirmed Enterprise IT access and permission inheritance.

Restriction Validation:Restricted actions failed as intended.

Validation:16 validation checks executed; all 16 passed.

Negative Tests:4 negative tests confirmed restricted behavior was blocked as intended.

Transparency:Chat export requires Primary Owner access; the implementation team had Owner-level access, so that item could not be tested.

OUTCOME HIGHLIGHT · PROVEN, NOT PROMISED
A Safe Foundation for Broader AI Adoption, From Day One.
FEG established a governed, validated Claude Enterprise platform with Aditi’s support — bringing together least-privilege access, controlled connectors, Department Projects and instructions, and validated controls so FEG’s people can put AI to work with the confidentiality, compliance, and control their business demands.