Perspectives · Microsoft stack · Agentic AI

Enterprise AI doesn't need a new app. It needs to show up in the ones already open.

Enterprise AI rollouts keep getting designed like product launches: a new portal, a new login, a training campaign, an adoption dashboard to prove people showed up. Meanwhile, every decision those rollouts are supposed to accelerate already happens somewhere specific — a Teams channel, an Excel tab, the Monday deck, an inbox. The organization already has a deployment surface. It already passed procurement, already has single sign-on, already gets opened four hundred times a day. It's the Microsoft stack, and most AI strategies treat it as scenery.

The industry is converging on a simple observation: software is shifting from recording decisions to participating in them. Take that seriously, and the deployment question inverts. The scarce resource isn't intelligence — models are abundant. It's attention placement. An insight that arrives inside the deck being assembled, or the channel where the review happens, gets acted on. The same insight in a separate portal gets a login nobody remembers.

Every new tool is an adoption bet stacked on top of the technology bet. The adoption bets are the ones that fail.

Distribution is solved. Governance is the question.

Deliver agent output through the applications people already live in, and the deployment problem you actually face changes shape. Not "how do we get people to use it" — they're already there. The question becomes "how do we govern what it does," and here the Microsoft stack earns its keep a second time. Entra ID already knows who everyone is. Conditional access already encodes what the security team will tolerate. The audit, retention, and compliance machinery already exists and has already survived an audit. An agent deployed inside that boundary extends a governed platform; an agent deployed beside it creates a new perimeter for the CISO to distrust. Having spent years on the identity and zero-trust side of this — Entra, conditional access, the whole apparatus — I can tell you the second conversation goes much worse than the first.

Rent the surface. Own the brain.

There's a trap at the other extreme, though: renting everything. The default AI experience shipping inside every productivity suite runs on generic models with generic context — the same for you and your competitor. Differentiation lives in the layer you connect to it: your data, your agents, your accumulated decision history. Build that layer on open agent frameworks and it stays yours — the code, the integrations, the semantic understanding of how your business actually works. Models get swapped as better ones ship. Nothing about your compounding advantage is on someone else's price sheet.

And it does compound. In the first quarter, a well-built system mostly learns your data landscape — where the clean sources are, what normal looks like. Six months in, it knows things your process never wrote down: which forecast assumptions habitually miss, which signals precede real movement versus noise. A year in, it holds a longitudinal view no analyst maintains, and the institutional knowledge that used to live in three senior people's heads is encoded, queryable, and available to everyone. The competitor who buys a SaaS equivalent next year gets the same technology and none of the learning.

AI as a new app

  • New portal, new login, adoption campaign
  • New security perimeter to review
  • Insights arrive where nobody is looking
  • Generic model, generic context
  • Vendor accumulates the learning

AI inside the stack

  • Shows up in Teams, Excel, the deck itself
  • Inherits Entra ID, conditional access, audit
  • Insights land where the decision happens
  • Your data, your agents, your context
  • The enterprise owns the compounding layer

The last mile is plumbing, and that's good news

Here's what the strategy decks omit: making this real is infrastructure work. Agents need workload identities in Entra with scopes someone actually reasoned about, not a service account with Graph permissions to everything. Data paths from the lake and the line-of-business systems into the agent layer need to be governed, enumerable, and auditable. Output needs provenance — when a number lands in a deck, the chain from source to slide has to be printable. Escalation needs design: who approves the recommendation that contradicts the regional forecast, and how is an agent's authority bounded and revoked. None of that is a prompt. All of it is identity, networking, and platform engineering — which is why the people who ship agentic systems into enterprise stacks look a lot more like platform engineers than AI researchers.

That's also why this is tractable in ninety days instead of eighteen months. Pick one decision that's bottlenecked by human assembly work. Find where it already lives in the stack — which channel, which spreadsheet, which recurring meeting. Build the bounded proof that delivers into that exact surface, on real data, with the identity and audit chain done properly from day one. The surface is already deployed. The trust layer is already accepted. The only new thing is the intelligence — and that part, you should own.

This is the work I do.

Bounded proofs on real data, agent platforms your organization owns, and the operating-model design that makes them stick — delivered end to end, corp-to-corp through Mazo Cloud Group LLC.

Start an engagement