Setup checklist
AI setup checklist for Tidewell Renovations & Custom Homes
These setup steps get the company ready to use AI safely. The account and access steps line up with the Canadian Centre for Cyber Security's baseline controls. The order is ours: accounts first, then sensitive data, then the AI tool. Whoever looks after IT approves the accounts and connections.
Email and files (their answer) Google Workspace
Two-step sign-in today (their answer) Not sure
Data sensitivity (from their answers) Some sensitive data
2 Know what's sensitive and where it lives
3 Then the AI toolA business AI plan or workspace the company owns, with people signed in on work accounts. Microsoft, Google, OpenAI and Anthropic each say business data isn't used to train their AI models by default. On any personal plan, turn training off. Admin approval before anyone connects an AI app to Gmail or Drive. In the Admin console, under Security > Access and data control > API controls > Manage App Access, review Accessed apps and block AI apps nobody approved. Mark the apps already in use Trusted first, then set Gmail and Drive to Restricted so only those apps reach that data. Send and edit permissions off to start, where the tool allows it. AI prepares drafts and a person sends. Check the connection's actual permissions, because instructions alone aren't a lock. Check where each AI tool stores and processes data, for the exact plan, in the vendor's own terms. Add AI accounts and connected apps to your offboarding steps, so access ends the day someone leaves.
Google settings checked against Google's admin documentation, October 2026.