Contact Us

If you still have questions or prefer to get help directly from an agent, please submit a request.
We’ll get back to you as soon as possible.

Please fill out the contact form below and we will reply as soon as possible.

  • Contact Us
  • Verito
  • Home

  • Applications

    • Managed IT

      • Cloud Hosting KB

        • Home
        • Managed IT

        Using AI Tools in Your Firm: Setup and Safe Use Guide

        Discover essential steps for implementing AI tools in your firm safely and effectively to enhance productivity and minimize risks.

        Table of Contents

        1. Purpose and how to use this article 2. Sort your data before you touch any settings 3. Understand the rule that drives the whole setup 4. Redaction: useful, but not a way around the rule 5. Choose the right account 6. Turn off model training on every personal account ChatGPT, personal plans Claude, personal plans What these toggles do not do 7. Put the paperwork in place 8. Decide what connects to what 9. Agents and desktop apps 10. AI notetakers Fathom Dialpad 11. Microsoft Copilot: the tool already inside your Office apps Know which Copilot you are looking at The real risk is your permissions, not the AI 12. Retention, and what an administrator can actually see Retention Audit logs 13. Check what comes out, not just what goes in 14. Write the rule down You may already have this policy Note where that standard is stricter than this article What the policy does not cover What to add for your own firm 15. What to do this week 16. What to avoid 17. Where Verito fits

        Using AI Tools in Your Firm: Setup and Safe Use Guide

        Last Updated on 2nd September  |  Published by Parnav Dagar

        1. Purpose and how to use this article

        This article explains how to set up ChatGPT, Claude and Microsoft Copilot for use in a tax or accounting firm. It covers which account to buy, which settings to change, how to handle connectors, AI agents and notetakers, and what has to be in place before client information goes anywhere near any of them.

        It is written to answer three questions directly:

        • Which AI tools can our firm use, and on what kind of account?
        • What must be in place before client information is involved?
        • What is our firm responsible for, and what falls outside Verito's service?

        Work through Sections 2 to 10 in order, because each step assumes the one before it is done. Sections 11 to 14 cover the tools and rules that sit alongside the setup itself. If you would rather start with actions, Section 15 gives the whole thing as a short ordered checklist.

        2. Sort your data before you touch any settings

        The most common mistake is starting with the question "which app connects to AI." The question that actually matters is what information you are about to send, and where it goes. Sort the work you want AI to help with into three levels.

        Level What it covers What it means for setup
        Green No client information at all. Marketing drafts, staff training material, internal procedure notes, research on general topics. You can start today. No special account and no paperwork required.
        Yellow Your own business and staff information. Internal scheduling, staff notes, firm financials, vendor correspondence. No client tax detail. Use a business account with training turned off. No client consent needed, because no client information is involved.
        Red Client tax and financial information. Anything furnished to you in connection with preparing a return, including the fact that someone is a client. Business account, signed data agreement, and written client consent, all in place before anything goes in.

        One app can sit in more than one level depending on what you are doing with it. Your email is Green when you are drafting a newsletter and Red the moment it holds a client tax document. When you are unsure, treat it as Red.

        3. Understand the rule that drives the whole setup

        Internal Revenue Code Section 7216 governs how a tax return preparer may disclose or use client tax return information. The definition of disclosure in the regulations is deliberately broad. It covers making that information known to another party in any manner whatever, which includes pasting it into a prompt, uploading a file, or having a tool read it on your behalf.

        The IRS has not published guidance that addresses general purpose AI tools directly. The prevailing view among tax practitioners is that sending client tax return information to ChatGPT or Claude is a disclosure, and that the narrow exception for auxiliary service providers is unlikely to cover a general purpose AI tool. On that reading, you need the client's written consent before the disclosure happens, obtained under Treasury Regulation 301.7216-3.

        Three points matter most for setup:

        • The consent has to name the specific tool. Wording such as "various AI tools" or "third party technology providers" does not satisfy the requirement.
        • For Form 1040 clients, the consent must follow the mandatory format and language set out in Revenue Procedure 2013-14. Many templates circulating online omit the required wording and are not valid.
        • A vendor promising not to train on your data does not remove the need for consent. The disclosure has already happened at the moment the information leaves your systems. Training is a separate question.

        The most recent formal IRS guidance on Section 7216 dates from 2013, well before general purpose AI tools existed. The AICPA has asked the IRS to prioritize guidance on the use of AI in tax preparation. Until that arrives, firms are applying a 2013 framework to a 2026 problem, which is why the safe course is the documented one.

        This article is general information and is not legal advice. Confirm your consent wording with the provider of your engagement letters, or with your tax attorney.

        4. Redaction: useful, but not a way around the rule

        A common instinct is to strip out the client's name and identifying numbers, then treat what is left as safe to paste anywhere. It is worth being precise about what this achieves, because the answer is not what most people assume.

        What redaction does. It meaningfully reduces the harm if something goes wrong. A prompt with no name, no identifying number and no address is far less damaging in a breach, a subpoena or an accidental disclosure than one with all three. It is good practice and worth building into how your staff work.

        What redaction does not do. It does not reliably move a Red scenario into Green or Yellow. The regulation defines tax return information broadly. It covers information furnished to you in connection with preparing a return, and information you derive from it. Structural facts survive redaction: the specific deduction at issue, the dollar amounts, the entity type, the state, the unusual circumstance that made you ask the question in the first place. Those remain tax return information whether or not a name is attached. In a small firm serving a local client base, a described fact pattern can also be identifying on its own.

        There is a real distinction between redacting before the data leaves your possession and relying on a tool to strip identifiers after you have already sent it. The first is a genuine control. The second is not, because the disclosure has already happened.

        The practical position for staff:

        • Redact by habit. Names become "the client" or "Client A." Identifying numbers never go in at all. Round or generalize figures where the exact number is not what you are asking about.
        • A genuinely general question is genuinely general. "How does the passive activity loss limitation interact with a real estate professional election" is a research question with no client in it. That is Green, and you should feel free to ask it.
        • The moment a real client's actual figures, documents or specific circumstances shape the question, treat it as Red regardless of how much you have blanked out.
        • Do not treat redaction as a license to use a personal account for client work. The account and the paperwork are separate requirements from the redaction habit.

        5. Choose the right account

        This is the single decision that determines most of what follows. Personal plans and business plans sit under different contracts with different defaults. A paid personal plan is still a personal plan.

        Question Personal plans Business plans
        Which plans these are ChatGPT Free, Plus and Pro. Claude Free, Pro and Max. ChatGPT Business and Enterprise. Claude Team and Enterprise.
        Used to improve the model by default Yes on both, unless you turn the setting off yourself. No. Both providers exclude business plan data from model training by default.
        Which contract applies Consumer terms. You are the individual user. Business or commercial terms. Your firm is the data controller and the provider processes on your instruction.
        Data processing agreement available No. Yes on both.
        Central control over staff settings None. Each person controls their own account and can change it back at any time. Yes. An owner or admin manages members, permissions and which connectors are available.
        Suitable for client tax information No. Yes, once the data agreement and client consent are in place.

        If your firm will touch client information with AI at any point, buy the business plan and put staff on it. Keeping everyone on personal accounts and relying on each person to configure their own settings correctly is not a control you can evidence later.

        Keep personal accounts separate rather than trying to police them. Staff will use AI on their own devices regardless. The realistic position is a firm account for firm work and a clear rule that nothing client related goes anywhere else.

        6. Turn off model training on every personal account

        Do this even if you are moving to a business plan, because personal accounts usually stay in use for Green level work. It takes about a minute per account and per person.

        ChatGPT, personal plans

        1. Sign in and select your profile icon, then Settings.
        2. Open Data Controls.
        3. Find "Improve the model for everyone" and switch it off. This also switches off the audio recording option beneath it.
        4. Reopen Data Controls a moment later and confirm it is still off.

        The setting applies to the whole account and syncs across devices, so you only need to do it once per account rather than once per browser or phone. It is forward looking. Anything already used in a completed training run cannot be pulled back, which is why doing this early matters.

        Claude, personal plans

        1. Sign in and select your name from the settings menu.
        2. Select Settings, then Privacy.
        3. Find "Help Improve Claude" and toggle it off.

        The path on mobile is the same. As with ChatGPT, turning this off stops future use of your conversations for training but does not undo training that has already happened.

        What these toggles do not do

        One caveat before you rely on this. If Verito provides your written information security plan, it prohibits free tier and consumer AI tools for firm business as well as for client work, which is stricter than the general guidance in this section. Read section 14 before deciding what may be done on a personal account.

        Turning off training is not the same as deleting your history, and it is not the same as having a contract in place. Your conversations are still stored in your account, and both providers may retain and review conversations flagged by their safety systems. A personal account with training switched off is fine for Green level work. It is still not the right home for client information.

        7. Put the paperwork in place

        Two documents, both before any client information goes into the tool.

        The data processing agreement with the AI provider. OpenAI will execute a data processing addendum for ChatGPT Business, ChatGPT Enterprise and its API, through a form on its site. For Claude, the data processing addendum is incorporated into the commercial terms that apply to Team and Enterprise plans, so it comes with the plan rather than needing a separate signature for a standard deployment. Keep a copy of whichever applies in the same place you keep your other vendor agreements. If you maintain a written information security plan, your vendor list should reflect the AI provider once you are live.

        The client consent. This is the document that has to be right, and it is the one you should not build from a template you found online. Take the specific tool names to whoever supplies your engagement letters and have the consent drafted or reviewed there. Be ready to tell them exactly which tools you are naming, because a consent that does not identify the recipient is not valid. If you add a second tool later, the consent has to be updated to name it.

        A practical consequence worth planning for: this is easiest to handle at engagement letter time, alongside your other annual consents, rather than as a separate chase during filing season.

        8. Decide what connects to what

        Connectors let ChatGPT or Claude read one of your other applications directly. This is where firms most often widen their exposure without meaning to, because a connector inherits whatever you can see in the connected application. Connecting a document store gives the AI tool the same reach into that store that you have, not just the one folder you had in mind.

        Four rules keep this manageable:

        • Connect the narrowest thing that does the job. If the work only needs one folder, share one folder rather than the whole account.
        • Decide connectors at the firm level, not the individual level. On business plans, an owner or admin enables connectors for the organization and each person still authenticates individually. Use that. It gives you one list of what is connected, which is exactly what you want if you are ever asked.
        • Treat automation tools as an extra stop. A tool that passes information between your applications and the AI adds another vendor holding your data, with its own terms and its own retention. It needs the same review as the AI provider itself.
        • Never connect your password manager. A password vault has no business being readable by an AI tool under any configuration.

        On Claude Team and Enterprise, connectors are managed under Organization settings, then Connectors. On ChatGPT Business and Enterprise, application access is managed by owners and admins from Workspace settings. In both cases the practical control is the same: nothing is available to your staff until someone with admin rights turns it on.

        9. Agents and desktop apps

        This category deserves separate treatment. A chat window only sees what you choose to put in it. An agent, a browser extension or a desktop application that can read your files and act on your behalf sees whatever falls within its reach, and the decision about what it reads is being made by the tool rather than by you.

        That flips the default. With a chat window, client information gets in because someone pasted it. With an agent pointed at a working folder or a browser session, client information gets in unless something stops it.

        If you want to use these:

        • Run them on the firm business account, never a personal one.
        • Point them at a specific folder created for the purpose. Do not point them at a whole drive, a whole mailbox, or a folder tree that contains client files.
        • Keep approval steps on. Both providers offer modes that reduce how often the tool asks before acting. Convenient, and the wrong choice while client data is anywhere nearby.
        • Check the training setting separately. These features often have their own controls that sit apart from the main account toggle. In the ChatGPT browser product, for example, the setting covering browsed content is separate from the main training setting.
        • Start with Green level work. Building SOPs from your own recordings, drafting internal documentation, organising your own research. That is where agents earn their keep with the least exposure.

        If you are considering installing an AI agent or desktop application on a workstation that your IT provider manages, or on a hosted desktop, raise it with them before you install. There may be conditions attached to what can be installed in that environment.

        10. AI notetakers

        Judge a notetaker by whose call it is sitting in, not by what it costs. An internal team meeting is Yellow. A client tax call is Red, and everything in section 3 applies to the recording and the transcript exactly as it would to a pasted document.

        There is also a distinction worth understanding. Some vendors do not let their AI suppliers train on your data, but still use your data to improve their own models. Those are two different questions, and the answer to the first does not settle the second.

        Fathom

        Fathom states that its AI suppliers are not permitted to train on customer data. Fathom itself does use de-identified customer data to improve its own models, and that is on unless you turn it off. To opt out:

        1. For an individual account, open your user settings and turn off the option allowing your data to improve Fathom's models.
        2. On Team Edition, an administrator can opt out every user at once from Organization Settings. Do this rather than relying on each person.

        Dialpad

        Dialpad treats AI training as a preference controlled at company, office, line and individual level. Accounts in the United States and Canada default to opted out, so the position is likely already the one you want. Confirm it rather than assume it. A company administrator can check under Admin Settings, then My Company, then Ai Settings, then General Ai Settings. The relevant option is the one allowing Dialpad AI features to improve based on your conversations. If it is off at company level, no office, line or individual can turn it on.

        Whichever notetaker you use, decide in advance which meetings it is never allowed to join, and tell your staff. That instruction is worth more than any setting.

        11. Microsoft Copilot: the tool already inside your Office apps

        Most accounting firms run on Word, Excel and Outlook, and Microsoft has put Copilot inside them. That makes it the AI tool your staff are most likely to use without ever deciding to adopt an AI tool. It deserves its own thinking, because its risks are not the same as those of a chat window.

        Know which Copilot you are looking at

        There are two products with similar names, and the distinction is the whole ball game. The commercial versions used through your work account are covered by Microsoft's enterprise data protection commitments, which sit under the Microsoft Product Terms and the Microsoft data protection addendum, with Microsoft acting as your data processor. Under those terms your prompts and responses are not used to train Microsoft's foundation models. The consumer version, signed into with a personal Microsoft account, is a different product on different terms.

        Staff will not always notice which one they are in, particularly on a personal laptop or a shared browser. The same rule from section 5 applies here: firm work belongs on the firm account.

        Microsoft has also renamed these products. What was Microsoft 365 Copilot is now Microsoft Copilot, and Microsoft 365 Copilot Chat is now Microsoft Copilot Chat. You may still see the old names in menus and licensing during the transition. The security and privacy terms did not change with the rename.

        The real risk is your permissions, not the AI

        Copilot works within your existing permissions. It does not elevate anyone's access, and it cannot show a member of staff a file they could not already open themselves. That sounds reassuring, and in one sense it is. The problem is what it means in practice.

        Most firms have accumulated permissions they have forgotten about. A folder shared with everyone years ago. A link set to anyone in the organization. A site nobody ever locked down after a staffing change. Before Copilot, that content was technically reachable but practically invisible, because finding it meant knowing it was there. Copilot makes it findable by asking a plain question. A junior member of staff who asks about partner compensation, a disciplinary matter or another partner's client may get a genuine answer, drawn from a file they always had permission to open and never would have found.

        For a tax firm the exposure runs both ways. It reaches staff and payroll information, and it reaches client files that should be visible only to the people working on that engagement.

        The order of operations matters. Review your sharing and permissions before you switch Copilot on, not after. Once it is live, a permissions problem stops being theoretical.

        This is tenant level configuration work. It covers sharing policies, site permissions, sensitivity labeling and search restrictions, and some of the tooling that reports on oversharing depends on your licensing. Take it to whoever holds administrative ownership of your Microsoft tenant, and ask them specifically: which sites and folders are shared more broadly than we intend, and what will Copilot surface once it is enabled.

        12. Retention, and what an administrator can actually see

        Two questions get confused with each other and with the training question. How long is the data kept, and who inside your firm can see it. Neither is answered by turning off model training.

        Retention

        Not training on your data is not the same as not keeping it. Both providers store conversations so that your history is there when you come back, and both retain data in back end systems for a period beyond that, including for safety and abuse monitoring. That storage is normal and contractually governed. It is still storage, and if you have a document retention schedule your AI conversations should be considered against it.

        The important detail for a firm of your size is that the ability to set your own retention period is not available on the entry level business plans. On Claude, custom retention controls are an Enterprise feature, configured by an owner under Organization settings, then Data and Privacy, with a minimum of thirty days. A Claude Team workspace has no equivalent control. On the ChatGPT side, configurable retention likewise sits with Enterprise rather than Business. If a defined deletion schedule for AI conversations is something you need to be able to evidence, that is an Enterprise conversation, not a Business one.

        Audit logs

        Audit logging is worth understanding accurately, because it is commonly assumed to come with any paid business plan. It does not. On both providers, formal audit logs and the compliance interfaces that export them are Enterprise tier features. Claude Team does not have audit logs. ChatGPT Business does not have the compliance log export that ChatGPT Enterprise provides. What the entry level business plans give you is member management, control over what is enabled, and usage analytics. That is genuinely useful, and it is not an audit trail.

        It is equally worth knowing what an administrator cannot do, because staff will ask. On a Claude Team plan an administrator cannot read individual members' conversations from an admin panel. Enterprise plans add organization level export and compliance access, which is a different matter. If you tell your team their chats are monitored when they are not, you will lose the trust you need for people to actually report a mistake.

        For most small and mid sized firms, the honest conclusion is that the entry level business plan is the right purchase and the compliance evidence has to come from your own policy and records rather than from vendor logs. Know which one you are relying on before someone asks.

        13. Check what comes out, not just what goes in

        Everything above is about information going into the tool. The other half of the risk is what comes back. AI models produce confident, well written, plausible text, and that text is sometimes wrong in ways that are difficult to spot precisely because it reads so well.

        In a tax context the failure modes are specific. A model may cite a code section that does not say what it claims, refer to a revenue ruling or court case that does not exist, apply a threshold or phase out from a prior year, or state a rule correctly in general while missing the exception that governs your client's facts. None of this announces itself. It arrives in the same fluent register as the correct answer.

        The rule that follows is simple and should not be negotiable in your firm:

        No AI output is used, relied on or sent to a client until a qualified professional has checked it against primary authority.

        In practice that means:

        • Every citation gets opened and read. Not searched for, opened. A citation that cannot be located is a fabrication, and it is a signal to distrust the rest of that answer.
        • Figures, thresholds and dates get confirmed against the current year's authority. Models are often trained on material that predates the filing season you are working in.
        • Client correspondence is reviewed by the person whose name goes on it, in full, as though a junior had drafted it.
        • The person who reviews is qualified to reach the conclusion independently. Someone who cannot evaluate the answer is not reviewing it, they are agreeing with it.
        • If the checking takes longer than doing the work would have, that is a valid finding. It means the task was not a good fit for AI, and the answer is to stop using it there.

        This is not only a quality question. Circular 230 sets standards of competence and due diligence for practitioners, and requires written advice to rest on reasonable factual and legal assumptions. Advice you cannot trace back to verified authority does not meet that standard, and the fact that a tool produced it does not transfer the responsibility. The professional judgment remains yours in every case.

        14. Write the rule down

        Everything in this article eventually depends on staff behaviour, and a verbal instruction is neither enforceable nor defensible. It needs to be written, signed, and reviewed.

        You may already have this policy

        If Verito provides your written information security plan, look for the section headed Acceptable use of AI tools before you draft anything new. It is already there, it is already part of a document your staff acknowledge, and it sets a clear standard. In summary, it requires that:

        • Only paid, enterprise grade AI tools are used, and only once your Qualified Individual has approved them and added them to your software and applications inventory.
        • Free tier AI tools, consumer chatbots, and any AI service that trains on your input or shares it with third parties are prohibited for any task involving client information or firm business.
        • Client names, Social Security numbers, Employer Identification Numbers, financial account details and other personally identifiable information never go into an unapproved tool, including AI features built into personal accounts and consumer software.
        • Access to approved tools follows your role based access controls, with multifactor authentication enabled wherever the tool supports it.
        • Approved tools are reassessed periodically through your vendor review process.
        • Any suspected misuse involving client data is reported immediately to your Data Security Coordinator.
        • Violations may lead to disciplinary action, up to and including termination.
        • The policy is reviewed annually alongside the plan itself.

        Read the section in your own plan rather than relying on this summary. Where the two differ, your plan is the authority.

        Note where that standard is stricter than this article

        This is important enough to state plainly. Sections 2 and 6 of this article describe a general approach in which Green level work, with no client information in it, can be done on a personal account with model training turned off. If you hold the plan described above, that latitude does not apply to you. Its prohibition on free tier and consumer AI tools extends to firm business, not only to client information, which means drafting a marketing email or turning a recording into a procedure note also belongs on the approved firm account.

        That is a defensible position and an easy one to administer, because it removes the judgment call about whether a given task counts as client work. Where your own plan is stricter than general guidance, follow your plan.

        What the policy does not cover

        The acceptable use policy is written against your safeguards obligations. It governs which tools may be used and what may be entered into them. Two things in this article sit outside it, and you should address them separately rather than assume the policy has them covered.

        • Client consent under Section 7216. Approving a tool internally is not the same as obtaining your clients' consent to disclose their information to it. Section 3 covers this, and it is a separate requirement with a separate document.
        • Review of what the tool produces. The policy governs what goes in. Section 13 governs what comes out, and nothing in the policy requires anyone to verify an answer before it reaches a client.

        What to add for your own firm

        Rather than writing a second document that may drift out of step with the first, keep one policy and add the firm specific detail the baseline deliberately leaves to you:

        • The actual list of approved tools, named individually. The policy requires approval but the list is yours to hold and keep current.
        • The review requirement from section 13, written as a rule rather than a suggestion.
        • Your consent position, so staff know whether client work is permitted yet at all.
        • Which meetings AI notetakers may not join.
        • A blame free route for reporting a mistake. The policy already requires reporting to your Data Security Coordinator, and the practical addition is making clear that reporting promptly is not itself the offence. You want to hear about it on the day, not in a year.

        Walk your team through it rather than circulating it, have everyone sign, and re-sign annually alongside your other acknowledgements. Revisit it whenever you add a tool. A policy nobody has signed since the year it was written is worth very little if it is ever examined.

        If Verito does not provide your plan, everything above still describes a sound policy. Take it to whoever maintains your security documentation and have it written in.

        15. What to do this week

        You do not have to finish the whole setup before getting value. Work in this order.

        Order Action Who does it
        1 Turn off model training on every personal ChatGPT and Claude account in the firm. Each staff member
        2 Set the review rule. Nothing AI-generated goes to a client or into a file until a qualified person has checked it against primary authority. Firm owner
        3 Start Green level work now. Marketing drafts, staff training material, internal procedures, checklists, general research. Anyone
        4 Confirm your notetaker settings and decide which meetings AI never joins. Firm administrator
        5 Review sharing and permissions across your document storage. Do this before enabling Copilot, not after. Whoever administers your Microsoft tenant
        6 Buy the business plan for whichever tool you intend to standardize on, and move firm work onto it. Firm owner
        7 Put the data processing agreement in place and file it with your vendor records. Firm owner
        8 Read the acceptable use of AI tools policy in your security plan, add your approved tool list, walk your team through it, and have everyone sign. Firm owner
        9 Get the client consent drafted, naming the specific tools, and only then begin any work that touches client information. Your engagement letter provider or attorney

        Steps 1 to 4 can be done today and cover most of the immediate risk. Steps 5 to 9 are the ones that unlock client work, and they are worth doing properly rather than quickly.

        16. What to avoid

        • Pasting client tax detail into a free or personal AI account, however briefly.
        • Treating a vendor's no training statement as though it removed the consent requirement.
        • Connecting an entire document store or mailbox when a single folder would do.
        • Connecting a password manager to any AI tool.
        • Using a general consent that refers to AI tools without naming them.
        • Assuming a paid personal plan is a business plan. It is not, and it carries none of the contractual protection.
        • Letting an AI notetaker into a client call before your consent position is settled.
        • Treating redaction as though it converted client work into general research.
        • Sending AI-drafted advice or correspondence to a client without opening every citation and confirming every figure.
        • Enabling Copilot before reviewing who can currently see what in your document storage.
        • Assuming a business plan gives you audit logs or a retention schedule. On both providers those are Enterprise features.
        • Assuming the acceptable use policy in your security plan covers client consent or output review. It covers neither.

        17. Where Verito fits

        Where we provide your written information security plan, it includes a baseline acceptable use of AI tools policy, summarised in section 14. You can adopt it as written or build on it. That is the extent of what we supply on the policy side. We do not draft firm specific AI policy beyond that baseline, we do not approve tools on your behalf, and we do not advise on client consent wording. Tool approval sits with your Qualified Individual under your own plan, and consent wording is a matter for your engagement letter provider or attorney.

        We do not configure, manage or enforce AI tools. The accounts and settings described here are yours to hold. We share reference material such as this article so you have a clear starting point rather than an open search.

        Reviewing sharing and permissions across your Microsoft tenant, including what an AI assistant would surface once enabled, is tenant governance and sits outside our managed service. Our Microsoft 365 and Google Workspace support scope article sets out that boundary in full.

        If you are planning to install an AI agent or desktop application on a device or hosted environment we support, raise a ticket first so we can confirm there is nothing in that environment it would conflict with.

        Managed IT support: itsupport@verito.com or (844) 629-9899. Cloud hosting support: support@verito.com or (844) 917-9399.

        Settings paths in this article were verified against the vendors' published documentation in September 2026. AI providers change their interfaces frequently. If a menu does not match what is described here, check the vendor's own help center for the current path.

        This article is general information about tools and settings. It is not legal or tax advice, and it does not certify compliance with any regulation.

        ai integration tool utilization

        Was this article helpful?

        Yes
        No
        Give feedback about this article

        RELATED QUESTIONS

        • Protecting Your Computer with Endpoint Security
        • How to Use Task Manager to Manage and Monitor Your Computer
        • How to Uninstall Any Application from Your Computer
        • How to Check Your Internet Speed & Understand Why It’s Slow

        Table of Contents

        1. Purpose and how to use this article 2. Sort your data before you touch any settings 3. Understand the rule that drives the whole setup 4. Redaction: useful, but not a way around the rule 5. Choose the right account 6. Turn off model training on every personal account ChatGPT, personal plans Claude, personal plans What these toggles do not do 7. Put the paperwork in place 8. Decide what connects to what 9. Agents and desktop apps 10. AI notetakers Fathom Dialpad 11. Microsoft Copilot: the tool already inside your Office apps Know which Copilot you are looking at The real risk is your permissions, not the AI 12. Retention, and what an administrator can actually see Retention Audit logs 13. Check what comes out, not just what goes in 14. Write the rule down You may already have this policy Note where that standard is stricter than this article What the policy does not cover What to add for your own firm 15. What to do this week 16. What to avoid 17. Where Verito fits
        Verito Logo

        Secure Cloud Solutions for
        Tax & Accounting Professionals

        3524 Silverside rd. Suite 35B,
        Wilmington, Delaware 19810

        1-855-583-7486
        sales@verito.com

        Services

        • Dedicated Hosting
        • Managed IT Services
        • VeritComplete
        • IT for Law Firms
        • Tax Software Hosting
        • QuickBooks Hosting

        Company

        • About Us
        • Our Data Centers
        • Success Stories
        • Partners
        • Contact Us

        Pricing

        • VeritSpace Pricing
        • VeritGuard Pricing
        • VeritComplete Pricing
        • Free Hosting Trial
        • Hosting Demo

        Resources

        • Blogs
        • FAQs
        • Knowledge Base
        • Our Support Channels
        • Privacy Policy

        Compare

        • vs. Rightworks
        • vs. ACE Cloud
        • vs. Cetrom
        • vs. In-House
        • View All
        4.9 

        125+ Reviews on G2

        G2 High Performer
        AICPA SOC

        Proud Affinity
        Partner of:

        natp logo
        nea logo
        nstp logo
        4.9 

        125+ Reviews on G2

        G2 High Performer
        AICPA SOC

        Proud Affinity Partner of:

        natp logo
        nea logo
        nstp logo

        © 2026 Verito Technologies. All Rights Reserved  |  Privacy Policy  |  Terms & Conditions

        Knowledge Base Software powered by Helpjuice

        Expand