47 / 63AI Readiness Assessment

AI readiness assessment in Canada, done by reading your tenant

A Canadian AI readiness assessment that examines your permissions and data, not a questionnaire.

  • CCIE and CCDE-led team
  • Building since 2021
  • Canadian data residency available
THE WORK

AI readiness assessment, three pillars, one operator.

One Canadian team examines what your AI would actually reach, so the AI capability assessment rests on what's configured in the tenant rather than on what a questionnaire remembers.

  1. 1

    Data and permission examination

    We scan what's overshared, stale, and unlabelled across the tenant and the data estate, because your AI inherits every one of those. Data readiness for AI is the dimension that decides whether a pilot is safe to start.

  2. 2

    Copilot readiness

    Licensing position, technical prerequisites, and the sharing and labelling cleanup that has to happen before a Microsoft 365 rollout. Copilot readiness is the most common reason Canadian firms call us, and it's a permissions job before it's a licensing one.

  3. 3

    Capability and gap scoring

    Infrastructure, skills, and governance scored against evidence, with each gap priced. The AI gap analysis says what to fix before a pilot, what can wait, and what's already fine as it stands.

THE PROOF

Built to last. Evidence over promises.

40% of organisations delayed a Copilot rollout by three months or more because of oversharing (industry surveys and Gartner, 2026). Finding it before the licences land is the cheap version of that discovery.

IN PRODUCTION

Readiness findings Canadian teams can act on.

We'd done the free vendor questionnaire and scored ourselves 'mostly ready'. SMEnode plugged into the tenant and found 40,000 files shared with everyone in the company, including payroll. Copilot would have surfaced all of it on day one. The score wasn't wrong about our strategy. It just couldn't see our permissions.

SMEnode · Engineering principle
  • CCIE Data Center
  • CCIE Security
  • CCDE Design
  • Canadian data residency
THE DEEP DIVE

AI readiness assessment in Canada, made real.

Free self-assessments score what you believe. This one reads what's configured, and it's written by the engineer who runs the scan.

Why a questionnaire can't score readiness.

Every AI capability assessment covers the same dimensions: data, infrastructure, skills, governance, strategy, culture. The dimensions aren't the hard part. The hard part is that a questionnaire asks your team whether data access is well controlled, and the answer is always a considered yes. Then you plug in an assistant and find the finance folder was shared with the whole company in 2021. AI doesn't grant new access, it just makes existing access findable. That's why an honest readiness score needs someone reading permissions, not collecting opinions.

Data readiness for AI is where most firms fail.

The risk sits in three places, and they're specific. Content shared with everyone in the organisation through a default nobody changed. Broken permission inheritance, where a locked site holds an unlocked folder. And stale documents that are wrong but confident, which an assistant will quote back as fact. Roughly 16% of business-critical data is overshared in an average Microsoft 365 tenant, and 40% of organisations delayed a Copilot rollout by three months or more because of it (source: industry surveys and Gartner, 2026).

Canadian conditions make this timely.

19.2% of Canadian businesses used AI in production in Q2 2026, up from 12.2% a year before, and 13.4% name cybersecurity or privacy as the barrier that limits them (source: Statistics Canada, 2026-05-27). Those firms are right to worry, and a readiness assessment is the cheap way to find out whether the worry is justified. PIPEDA applies to everything the model can reach, and Quebec's Law 25 applies if you hold data on customers there.

Inference graph
THE METHOD

How our AI gap analysis runs.

Four steps, and none of them is a survey. We ask for read-only access to the tenant and the data estate, then go and look. Clients sometimes push back on that, because a free tool takes twenty minutes and reading a real tenant takes proper time. The difference is that only one of them can tell you your payroll folder is world-readable. We score six dimensions, and the findings that change decisions are almost always in data and permissions, so that's where most of the effort goes.

  1. Step 01

    Connect and scan

    Read-only access to the tenant, the sharing reports, and the data stores in scope. Nothing changes, nothing moves, and you can watch every query we run.

  2. Step 02

    Find what's reachable

    Oversharing, broken permission inheritance, stale content, and unlabelled sensitive data. This is the list a questionnaire structurally could not produce, because it's read out of the configuration rather than out of memory.

  3. Step 03

    Score six dimensions

    Data, permissions, infrastructure, skills, governance, and use case fit, with evidence attached to each score. A score with no artefact behind it is an opinion, so every one of ours points at something we read.

  4. Step 04

    Sequence the fixes

    The fixes that have to land before any pilot, priced and ordered, plus what's fine exactly as it stands. That second list is usually longer than the client expects, and it's the part that makes the budget conversation easy.

QUESTIONS

AI readiness assessment questions, answered straight.

Answers first, including when the free tool is enough. An architect takes the call.

Because a questionnaire scores your beliefs and we read your configuration. The free wizards are genuinely useful for framing the conversation with your leadership, and we'll say so. What they can't do is scan your sharing links, find broken permission inheritance, or tell you which folders an assistant would surface on day one. Run the free one first. Call us when you need the version with evidence.

Six dimensions: data quality and permissions, infrastructure, skills, governance, use case fit, and licensing position. The permission work is the biggest piece, because it's where the surprises live. You get a scored report with evidence behind each finding and a priced fix list, and the report is yours either way.

No, though Copilot is the most common reason firms call. The permission and data problems are the same whichever assistant you deploy, since they all inherit your existing access model. If you're heading toward a custom build or another vendor, the assessment covers the same ground and we adjust the licensing section.

That's a useful answer and it happens often. It usually means a short list of specific fixes before a pilot makes sense, not that AI is off the table for a year. The report names them, prices them, and says which ones you can do yourselves. Deploying an assistant onto an unready estate is how firms end up with a privacy incident instead of a productivity gain.

Yes, and you're free to have someone else do it. We can remediate permissions, labelling, and data hygiene, or hand the report to your team with enough detail to act on. Some clients want the finding and the fix from one party. Others want the assessment kept independent from the remediation. Both are reasonable and we'll quote either.

Read-only, and scoped. We need a read-only view of the tenant's sharing and permission reports, plus the data stores you want in scope. Nothing is changed and nothing is moved while we're looking. If your team would rather run the exports themselves, we'll give you the queries and read what comes back.

LET'S CONNECT

A senior engineer replies within an hour, 24/7.