Garrett Smith

Assessment report · Prepared by Garrett Smith · Oct 2026

AI Integration EngineerClaude, MCP & Microsoft 365

I help companies put AI to work on their own data and workflows by building secure integrations, agents and internal tools, as someone who has run the IT side as well as the code.

Document control
Prepared byGarrett Smith
BackgroundIn-house IT and systems lead. I run the tenant, the devices and the code.
ScopeAI on company data · Microsoft 365 · internal tools · agents
Evidence6 case studies, 4 with a live demo
ClassificationTLP:CLEAR Public

1Findings

What I usually find when a company starts using AI. If you recognise one of these, the service that fixes it is listed next to it.

IDFindingRiskAddressed by
F-01
Staff paste company data into public AI chat tools.
They want the help, and there is no approved way to get it on your own data.
Risk: High
F-02
The AI cannot see SharePoint, Teams, the mailbox or the help desk.
So its answers are generic, and people copy and paste to fill the gap.
Risk: Medium
F-03
An AI agent can act, but nothing records what it did or who approved it.
Nobody can answer the auditor's question, or yours, after something goes wrong.
Risk: High
F-04
Routine Microsoft 365 work is still done by hand.
Requests, approvals, onboarding steps and weekly summaries eat hours every week.
Risk: Medium
F-05
An app built with Lovable, Bolt or Cursor is live, and nobody has checked it.
Auth, API keys and database rules are where AI-built apps usually fail.
Risk: High
F-06
The team wants Claude Code or Copilot, but there are no rules for it yet.
No agreed access, no shared instructions, no review before code ships.
Risk: Low

2Services

The controls I put in place. Each one names the engagements that show it working.

C-1Connect AI to your company data

Claude and other assistants get read access to the SharePoint sites, mailboxes, lists and systems you choose, through an MCP server or a Microsoft Graph integration.

  • Least-privilege app permissions, scoped to named sites and mailboxes
  • Every tool call logged: who asked, what was read, what came back
  • Works with Claude, Claude Code and other MCP clients

C-2AI internal tools with company sign-in

Small web apps your staff open with their Microsoft work account: request desks, document assistants, dashboards. The AI drafts; a person decides.

  • Entra ID sign-in and role checks, no new passwords
  • Approval step before anything is sent or changed
  • Audit trail your IT team can read

C-3AI workflow automation across Microsoft 365

Triage, routing, summaries and follow-ups across Outlook, Teams, SharePoint and your help desk, built so a person approves any step that changes something.

  • Automations that draft, then wait for approval
  • Runs on your tenant and your accounts
  • Plain runbook for whoever looks after it

Also available

C-5Production hardening for AI-built apps

Security review and fixes for apps built with Lovable, Bolt, v0 or Cursor: auth, secrets, database rules, deployment and tests.

3Engagements

Six case studies. Four are working demos built for a fictional manufacturer; two describe systems I run in-house, in general terms.

4How I work

The same rules on every job, whatever the size.

Security first
Before any code, we write down what the AI can reach and what it cannot. Permissions are the least that does the job, and secrets stay out of the code.
Approval steps
Anything that sends, changes or deletes waits for a person. Every AI action is logged with who approved it.
Handoff to IT
Your IT team gets the source, the architecture, the permission list and a runbook. Nothing depends on me staying around.
Tool-agnostic AI building
I build with Claude Code, Codex, Cursor or Copilot, whichever fits the job. I review and test what ships, and I am accountable for it, not the tool.

5Scope and limits

What this report does not claim. More about me.

  1. I have worked in IT for under three years. I am the in-house IT and systems lead at a manufacturer, so I run Intune, Entra ID, Microsoft 365 and the help desk myself.
  2. I hold no certifications. The evidence is the running systems in section 3.
  3. E-01 to E-04 are demos built for a fictional company, Tallgrass Precision Components. AI output in them comes from recorded runs of a real model, labelled with the date and model.
  4. E-05 and E-06 describe real in-house work in general terms. No employer data, names or systems are shown.

If one of these findings is yours, send me the details on Upwork.

Tell me what the AI should reach, who will use it and who has to approve it. I will reply with how I would build it, what it would touch, and a fixed scope.

Hire me on Upwork
Prepared by Garrett SmithAI Integration EngineerContracts and messages through Upwork
REVIEWED & TESTEDAPPROVED FOR HANDOFFG. SMITH · ACCOUNTABLE