Skip to content
Is there an AI for this?

Enterprise SaaS

Enterprise SaaS assistant with governance controls

A business or enterprise plan from an established vendor — ChatGPT Enterprise, Microsoft 365 Copilot, Glean or an equivalent — connected to your identity provider, scoped by existing permissions, covered by a DPA, and rolled out behind a written policy.

Source
Editorial recipe — no step evidence has been fetched yet
Verified
Evidence not verified
Confidence
Low

01Objective


02Recommended stack

4 components
RoleComponent
AuthenticationYour identity provider, with SSO and SCIM provisioning
IngestionoptionalVendor connectors to your existing systems
ObservabilityAdmin audit log export
UiVendor assistant (ChatGPT Enterprise, Microsoft 365 Copilot, Glean or equivalent)

Architecture and data flow

Architecture for Enterprise SaaS assistant with governance controls8 components in 5 layers. Trust boundaries: VENDOR CLOUD; COMPANY NETWORK. External data transfer: YES. Data leaves the boundary drawn here.Vendor assistant (web and desktop clients)Your identity provider (SSO + SCIM)Vendor retrieval over connected sourcesVendor-managed storage of chats and indexesConnected company systems (email, files, wiki)Vendor-hosted frontier modelEmployeesPEOPLEVendor assistant (web and desktop clients)Vendor assistant (web a…APPLICATIONYour identity provider (SSO + SCIM)Your identity provider …IDENTITYVendor retrieval over connected sourcesVendor retrieval over c…RETRIEVALVendor-managed storage of chats and indexesVendor-managed storage …DATABASEVendor model serviceINFERENCE SERVERConnected company systems (email, files, wiki)Connected company syste…EXTERNAL APIVendor-hosted frontier modelVendor-hosted frontier …MODELVENDOR CLOUDCOMPANY NETWORKHTTPSCONFIDENTIALOIDC sign-inPERSONALquestion + user groupsCONFIDENTIALdocuments + permissionsCONFIDENTIALchats, users, settingsPERSONALprompt + retrieved passagesCONFIDENTIALloaded weightsindexed content and permissionsCONFIDENTIALEXTERNAL DATA TRANSFER · YES

Components

  • Employees — people
  • Vendor assistant (web and desktop clients) — application
  • Your identity provider (SSO + SCIM) — identity
  • Vendor retrieval over connected sources — retrieval
  • Vendor-managed storage of chats and indexes — database
  • Vendor model service — inference server
  • Connected company systems (email, files, wiki) — external api
  • Vendor-hosted frontier model — model

Connections

  • Employees to Vendor assistant (web and desktop clients) — HTTPS (confidential data)
  • Vendor assistant (web and desktop clients) to Your identity provider (SSO + SCIM) — OIDC sign-in (personal data)
  • Vendor assistant (web and desktop clients) to Vendor retrieval over connected sources — question + user groups (confidential data)
  • Vendor retrieval over connected sources to Vendor-managed storage of chats and indexes — documents + permissions (confidential data)
  • Vendor assistant (web and desktop clients) to Vendor-managed storage of chats and indexes — chats, users, settings (personal data)
  • Vendor retrieval over connected sources to Vendor model service — prompt + retrieved passages (confidential data)
  • Vendor model service to Vendor-hosted frontier model — loaded weights
  • Vendor retrieval over connected sources to Connected company systems (email, files, wiki) — indexed content and permissions (confidential data)

External data transfer · YES

  • confidential content leaves your control on the Employees → Vendor assistant (web and desktop clients) link.
  • Content, prompts and answers are processed by the vendor under contract. What the vendor does with them is a matter for the DPA and the plan you buy, not for the architecture.
  • The identity provider stays yours: sign-in and de-provisioning remain under your control.

03Suitable for

Organisation size
50–20000 employees
Data classes
confidential, personal
Constraints
data may leave the company under contract; an identity provider already in place (Entra ID, Google Workspace, Okta); someone who can read a DPA and own the vendor relationship
Industries
Professional services, Technology, Financial services, Retail, Other
Jurisdictions
any

04Hardware

No hardware profile was sized for this answer.

Indicative costUSD · one-off plus monthly

Per-seat licences
Not estimated. We publish no price we have not read on the vendor's own pricing page, and enterprise pricing is negotiated. Get a quote for your seat count and term.
Not estimated
Model usage
Not estimated: whether model usage is bundled into the seat price or metered separately depends on the plan. Confirm it in the order form.
Not estimated
Implementation (4–12 FDE-days)
4–12 FDE-days at US$760–1940 per day, converted from the HK$6,000–15,000 band at the HKMA Linked Exchange Rate band of HK$7.75–7.85 to one US dollar. One-off; excludes internal staff time.
US$3,040 – US$23,280
  • Implementation covers vendor assessment, SSO and SCIM configuration, a permissions review, the policy, and a departmental pilot. It excludes licence fees entirely.
  • Assumes an identity provider is already in place.
  • The total is deliberately incomplete: the licence line is the largest cost and only the vendor can price it.

05Difficulty

2 / 5

A few days, mostly configuration


06Skills

API integrationapi-integration
development
Change managementchange-management
operations
Compliance and governancecompliance-governance
compliance
Identity and SSOidentity-sso
security
Security hardeningsecurity-hardening
security

07Deployment steps

7 steps

Commands are copied from each project’s own documentation, and the page they came from is linked under the step. 0 of 7 steps currently open an evidence record. The rest are linked to their source; §10 says which of those documents were fetched and which were fetched without their anchor being found — two different states, named differently there.

  1. 01

    Shortlist on terms and connectors, not on demos

    Assessment

    Write down the three or four things this has to do and the data it will touch, then ask each vendor the same questions in writing. Vendors publish enterprise privacy pages — OpenAI’s says its commitments give you "ownership and control over your business data" across its business products — but a published page is a starting point for the contract, not a substitute for it, and the wording on these pages changes.

    Source documentation

  2. 02

    Get the DPA, the subprocessor list and the retention terms in writing

    Assessment

    Ask for: the data processing agreement; the current subprocessor list and how you are notified of changes; where processing happens; the retention period and the deletion path; and a written no-training commitment covering uploads and connected sources. Note the boundaries the vendor documents: Microsoft states that for EU users "EU traffic stays within the EU Data Boundary while worldwide traffic can be sent to the EU and other countries or regions for LLM processing".

    Source documentation

  3. 03

    Connect SSO and automatic provisioning first

    Assessment

    Configure SSO before the pilot and SCIM provisioning before the rollout. Decide which groups get access, and make membership of those groups the only way in — a tool with its own user list becomes a shadow directory within a month.

  4. 04

    Fix the source permissions before connecting anything

    Assessment

    Connectors respect the permissions they find. Run an over-sharing review on the systems you intend to connect — the shared drive everyone can read, the site with inherited permissions — because retrieval will surface what browsing never did. Vendors sell controls for this (Glean markets "enforced data permissions"), but the underlying permissions are yours to correct.

    Source documentation

  5. 05

    Write the acceptable-use policy before the licences arrive

    Assessment

    One page: what may be put in, what may not, that output is a draft to be checked, that usage is logged, and who to ask. Publish it with the licences, not after the first incident. Name the sanctioned tool explicitly — most shadow AI use is people trying to do their job with the only tool they have.

  6. 06

    Pilot with one department and measure something

    Assessment

    Thirty people, six weeks, two or three named tasks, and a before-and-after measure you agreed in advance. Collect the answers that were wrong — they tell you which content is stale or over-shared, which is worth more than the satisfaction survey.

  7. 07

    Put the vendor on a review cycle

    Assessment

    Diary a quarterly check of the subprocessor list, the retention terms and the admin audit export, and re-read the terms at renewal. These pages change without notice; that is precisely why they are worth watching.

    Source documentation


08Compliance considerations

Structured issue-spotting to support your own review — not legal advice. Verify against the cited primary sources and your counsel.

Applies everywhere

  • Data processing agreement · Subprocessors · Vendor jurisdictionhigh

    A processor agreement is the foundation of this option. Get the DPA, the subprocessor list and the contracting entity, and check how you are told when a subprocessor changes.

  • Model training · Retentionhigh

    Ask for the no-training commitment and the retention period in the contract, covering uploads and connected sources as well as chats. Vendor pages describe defaults that can differ by plan — verify against the plan you are buying.

  • Data residency · Cross-border transfershigh

    Establish where prompts are processed, not only where data is stored. Microsoft documents an EU Data Boundary for EU users while noting worldwide traffic may be processed elsewhere; check the equivalent statement for your vendor and jurisdiction.

  • Confidentiality · Professional secrecyhigh

    Where professional secrecy or client confidentiality applies, a DPA may not be sufficient on its own — client consent or an engagement-letter provision may be required. This is a question for counsel, and it is the usual reason a firm chooses self-hosting instead.

  • Logging · Auditability · Transparencymedium

    Confirm the admin audit log exists, what it records, whether you can export it, and how long the vendor retains it. Tell employees what is logged.

  • Terms-of-service restrictions · Acceptable-use restrictionsmedium

    Vendor acceptable-use policies restrict certain uses regardless of your own policy. Read them against the workflows you actually intend to run.


09Alternatives


10Evidence

0 of 3 fetched

Not yet in the ledger

  1. not yet fetched

  2. not yet fetched

  3. not yet fetched


11Community

Deployed this stack, or hit something this page does not cover? Corrections, sources and implementation reports are what keep a recipe worth reading.

Improve this page

Sign in to contribute

From the field

0 deployments · 0 questions

Nobody has reported deploying this here yet, and no question has been opened against this page. Both appear once a reviewer accepts them.


12Hire an FDE

If you would rather not build it, we can introduce a forward-deployed engineer who has deployed this stack before. The enquiry form starts from this recipe.