Essjay Solutions is a pharmacovigilance consultancy: drug safety work for pharmaceutical clients, with full regulatory accountability for everything it signs off. A small team, handling confidential case data every day. They wanted Microsoft 365 Copilot, done properly: no client or patient data in the wrong place, a written policy an inspector could read, and a team that would actually use it.
The Starting Point
A Regulated Team That Wanted Copilot, And An Estate Nobody Had Reviewed With Copilot In Mind.
The Microsoft 365 tenant was in place, but nobody had reviewed it with Copilot in mind, and the working documents still lived elsewhere. That matters because Copilot can read everything the user can read. Switch it on over an untidy estate and it will summarise whatever it finds, for whoever asks.
So this was a permissions and governance job before it was a training job.
What We Did
Permissions And Policy First, Then Two Days In Their Office, Then A Prompt Library Where The Work Is.
- Reviewed the estate first. A readiness assessment of the Microsoft 365 environment and the file stores around it, with a short list of what had to change before Copilot went live and what could wait.
- Put the governance in writing. An AI governance framework for a regulated pharmacovigilance business, and a responsible-use policy for staff with human review checkpoints, so nobody had to guess where the line was.
- Switched Copilot on in a controlled way. A readiness checklist before any licence went live, including which content to keep out of reach.
- Trained the team in their own office. Two hands-on days: AI fundamentals and safe use, a prompting masterclass, then Copilot task by task in the apps they use, on examples built for their work. Fictional data only, and AI drafts while a qualified person decides.
- Left them a prompt library. Role-based prompts published inside Copilot, with a short usage playbook covering the "escalate to a person" cases.
Where It Landed
Copilot Live The Week After Training, And A Roadmap Ordered By What Was Holding Usage Back.
Copilot went live the week after the training. In the first month most of the team had tried it, and one person had made it part of every working day. That's a normal first month. The point is that we measured it six weeks in and said so.
The review found two gaps, and both were sequencing rather than people: the tools showing no usage were the ones whose data hadn't moved yet. So the roadmap runs in that order: monthly refreshers to hold the habit, then the file move, then the first governed Copilot agent.
The sessions were great. I know the team are actively using Copilot now.
Sabita Mukherjee, Chief Operating Officer, Essjay Solutions
What We'd Tell Another Regulated Firm
Fix Who Can See What, Switch It On, Then Measure It Honestly.
- It's a permissions job before it's a training job. Fix who can see what, then switch Copilot on. The other order is how a summary of the wrong file ends up in front of the wrong person.
- Write the policy before the licences arrive. Staff use a tool the way the policy says, once there is one. Without it, they guess.
- Train in the room, on their own work. A recorded webinar doesn't change habits. Two half days with the team's own documents, in fictional form, does.
- Measure at week six, and be honest about it. Usage falls after training. Plan the refreshers before it does, and fix whatever is holding usage down.