Picking Up Where We Left Off
Last time, Chris Risher from Red Helm and I got into shadow AI, the paste problem, and why role-based access is the fastest way to get governance right. This episode picks up right where that left off, moving from “how do you control it” to “how do you prove it’s working.”
The Wrong Question Most Leaders Start With
Most conversations about AI in business start with the wrong question. Leaders want to talk about tools, use cases, maybe an agent they saw demoed somewhere. Christopher Risher, who runs GRC work at Red Helm, doesn’t start there. He starts with a much less exciting word: visibility.
What One Thing Should You Do Next Week
Here’s the thing that stood out. When I asked him what one thing a business should do next week to move forward with AI, he didn’t mention a platform or a pilot project. He said get visibility. Find out who in your organization is already using AI, on what devices, for what tasks. Because they are already using it. That ship has sailed. The only question is whether you know about it.
That’s the shift right there. AI adoption isn’t something you’re planning for the future. It’s something that already happened, quietly, on people’s workstations, and most leaders are managing a phenomenon they can’t see.
The Limits of Visibility
Chris was clear about the limits too. If you’ve got a BYOD policy on mobile devices, you’re not getting full visibility, full stop. But workstations are within reach. Start there.
Not All Prompting Is Equal
Here’s what matters next. Visibility isn’t just about knowing who’s using AI. It’s about understanding how they’re using it, because not all prompting is equal. Chris framed it as a maturity curve. Are people just typing raw questions into a chat box? Or are they using something like a prompt coach to sharpen their approach? Are they chaining prompts together, where the output of one becomes the input of the next?
When a Prompt Chain Becomes a Signal to Build an Agent
That last point is where it gets interesting for MSPs specifically. Chris’s read: a prompt chain that keeps repeating is a signal. If someone’s manually stitching together the same sequence of prompts over and over for a recurring task, that’s not a prompting problem anymore. That’s a leading indicator you should be building an agent, or a skill, to handle it outright.
Why AI Hallucinates (It’s Not a Mystery)
There’s a sharper test buried in there too: are people asking the AI to take notes? Chris compared it to a human conversation. If you and I talk and neither of us writes anything down, and we pick the conversation back up three weeks later, I might misremember what was said. I might fill in gaps with things that sound right but aren’t. That’s exactly what happens when AI hallucinates. It’s not a mysterious flaw. It’s the predictable result of no memory and no documentation, same as it would be for a person.
Bringing It Together: Visibility Before ROI
Let me bring this together. Before any of the ROI conversation, before the dashboard of savings and efficiency gains, there’s a foundational layer: do you actually know what’s happening inside your business right now? Chris’s answer to the CFO’s inevitable “what did I get for my money” question isn’t a clever metric. It’s that you can’t measure what you never made visible in the first place.
Visibility Plus Training, Not a One-Time Policy
The second piece he insisted on: pair visibility with a usage training program. Not a one-time policy memo. An ongoing loop where you see how people are actually using AI today, and use that as the basis for training them further, moving them up that maturity curve on purpose instead of hoping it happens.
What This Means for MSPs
For MSPs building out AI-powered services for clients, this reframes the starting conversation. It’s not “let’s pick a tool.” It’s “let’s see what’s already happening, and build a maturity path from there.” Governance, ROI, and agentic investment all sit downstream of that first, unglamorous step.
Visibility first. Everything else follows.


