Visibility Before Blocking: The Governance Shift MSPs Are Missing

I sat down with Chris Risher from Red Helm for this episode of AI By Design, and about fifteen minutes in he said a sentence that stopped me. 

“The fastest way to lose data may not be a hack. It may be a paste.” 

Sit with that for a second. Not a breach. Not a sophisticated attack. A copy and paste, done by someone on your own team, into a browser window. 

Chris has been at Red Helm for 22 years. Systems engineer to project management to technology leadership to advisory. Today he runs their advisory and digital innovation practice, which means he sits with clients on AI governance and agentic implementation. He also runs their webinars, most of them lately on AI and security. So when he talks about shadow AI, he’s not theorizing. He’s watching it happen inside real organizations. 

The mistake most leaders make 

Chris told me something about his own career that I think applies to every operator listening to this. He started as an engineer. Technology first. Over time, as he moved into leadership, he shifted. “Let’s focus on the whys and not the hows,” he said. That’s not how an engineer thinks. That’s how a leader thinks. 

His point was bigger than career advice. Digital transformation isn’t about installing technology. It’s about changing how a business produces an outcome. If you’re focused on the tool, you’ve already lost the plot. The outcome comes first. The tool is just how you get there. 

That’s why, when he hires today, he’s not screening for technical depth first. He’s screening for EQ. Can this person understand what shipping something into production actually does to a client, internally or externally? Can they think past the send button? That’s not a soft skill. That’s judgment. And judgment is what scales leadership. 

Where shadow AI actually lives 

Now back to the paste. 

Chris made a distinction I hadn’t heard framed this clearly before. Most security conversations focus on external attackers. He’s equally worried, maybe more worried, about internal users. Not bad actors. Uninformed ones. People who don’t think twice about dropping a social security number or a credit card number into a public AI tool because it’s sitting right there in their browser. 

The problem isn’t malice. It’s visibility. Most IT and security teams have no idea what’s being pasted into which AI tool, by whom, or when. 

Chris’s fix starts at the paste itself. Enterprise browsers that can see and block the paste. Tools that give visibility into what was actually prompted. And here’s the part that matters most: that visibility isn’t just for blocking. It becomes a feedback loop. If you know what your team is actually inputting into AI tools, you know exactly where your organization’s AI maturity really sits. And you can train against that gap directly, instead of guessing. 

Governance starts with roles, not tools 

I asked Chris what an MSP with no AI governance program should do in the first 90 days. His answer went back to something old: role-based access control. 

Does this role need this workload? He walked me through how he thinks about AI maturity in tiers. Tier zero is the free public tools. Tier one is paid premium chat, something like Copilot chat. Tier two moves into agentic cowork style tools, Claude, Copilot cowork, Perplexity, doesn’t matter which. Tier three is full agentic workflows. 

His comparison landed for me immediately. Think about ERP access. An accounts payable manager, in a mature organization, doesn’t automatically get visibility into accounts receivable. Different module, different need. AI access should be treated the same way. Define the role. Match the tier. Build the training around that tier. AI is a new capability, but the governance logic underneath it isn’t new at all. 

Where this leaves us 

Here’s what I took away from this conversation. Start with why. Start with the outcome you actually want from AI, not the tool you want to install. Then build access by role and function. Finance needs AI differently than HR. HR needs it differently than service delivery. Sales needs it differently than both. 

Get that right, and you’re not just managing risk. You’re building the kind of AI maturity that compounds, one role, one training cycle, one access decision at a time. 

That’s the shift right there. Not more tools. Better governance around the tools you already have. 

Part 2 picks up where this leaves off, covering the ROI reality check and the question of who’s actually accountable for making AI work. 

For more content like this, be sure to follow IT By Design on LinkedIn and YouTube, check out our on-demand learning platform, Build IT University, and be sure to register for Build IT LIVE, our 3-day education focused conference, August 3-5, 2026 in Jersey City, NJ!