Real IT Solutions has formally launched an AI advisory practice for small and midsize businesses in West Michigan, placing Microsoft Copilot deployment, workflow automation, data-readiness work, and AI governance beside its established managed IT services. The important practical change is not a new AI product: it is a regional MSP packaging assessment, implementation, training, and continuing oversight into a billable service line for organizations that have already begun experimenting with generative AI without clear controls. The announcement, distributed through ACCESS Newswire on August 3, names Service Manager Donald McArthur as the firm’s new Chief AI Officer and says the practice will operate through an Assess-Deploy-Sustain method. Real IT Solutions’ own newly rebuilt website independently confirms that it is now selling AI readiness assessments, Copilot enablement, policy work, prompt training, automation work, and ongoing governance to Grand Rapids-area customers.
For Windows administrators and Microsoft 365 owners, that framing is more significant than the new executive title. A managed service provider can sell a Copilot license or a ChatGPT workshop in an afternoon. The difficult work is finding overshared SharePoint sites, incomplete access controls, poorly organized files, unmanaged consumer AI use, and processes that have never been documented well enough to automate safely. Real IT’s public service description at least recognizes those prerequisites, although it does not yet provide independently verifiable customer outcomes, pricing, or a defined service-level commitment for the AI practice.

Team discusses a data dashboard and secure AI implementation, outlining assess, deploy, and sustain phases.An MSP is turning AI adoption into an ongoing managed service​

Real IT Solutions serves businesses across Grand Rapids, Kent County, Kentwood, Wyoming, and the wider West Michigan area. The firm already sells conventional managed IT under its RealCare model: infrastructure management, security, help desk work, and strategic reviews. The new practice extends that relationship from keeping the environment running to advising customers on what information and work should enter AI tools at all.
The company’s methodology has three phases. Assess covers infrastructure, data quality, workflow documentation, staff readiness, and risk tolerance. Deploy covers selecting a tool, configuring it, automating work, and training staff. Sustain covers governance, adoption monitoring, and adjustments as tools and business needs change.
That is an appropriate structure for SMBs, but it also exposes where a traditional MSP’s interests can collide with the customer’s. The firm says its advice is vendor-agnostic, while its site positions Microsoft Copilot as the most credible route for businesses already running Microsoft 365 and says it can implement Power Automate and Copilot Studio. Those are sensible choices for a Microsoft-centric customer, but “vendor-agnostic” should not be read as tool-neutral implementation. A business should expect an assessment to distinguish between a need for a policy, a cleanup project, a lower-cost Microsoft 365 capability already licensed, and a paid Copilot deployment.
Real IT has not published a rate card, package boundaries, a list of supported AI products, or case studies showing time savings, error reductions, adoption figures, or revenue gains from this service. Its press release says the frameworks have been used with clients in professional services, manufacturing, and financial services, but it names no customer and gives no measurable result. No other outlet appears to have independently reported deployments, client timing, or commercial terms for the new practice.
That does not invalidate the launch. It defines it accurately: this is a formalized advisory offering, not evidence yet of a proven regional AI implementation program at scale.

The data-readiness emphasis is the part IT departments should take seriously​

McArthur’s public pitch centers on an inconvenient fact that many AI rollouts postpone: AI does not repair fragmented data, undocumented procedures, or broad permissions. It makes those weaknesses more visible—and, in some cases, makes their consequences easier to spread.
Microsoft’s own deployment guidance makes the same point more bluntly. Microsoft 365 Copilot bases answers on content a user already has permission to access. If SharePoint libraries, Teams channels, OneDrive folders, or mailboxes are overshared, Copilot can make information discoverable and summarizable to users who were technically entitled to reach it but would not have found it through normal navigation. Microsoft recommends remediating oversharing and applying guardrails before broad deployment.
This gives Real IT’s readiness assessment a potentially useful role, provided it results in actual remediation rather than a questionnaire and a Copilot sales proposal. A credible assessment should inventory AI tools already in use; identify where business data resides; review Microsoft 365 sharing and sensitivity labels; test whether privileged or confidential data is exposed through ordinary employee accounts; map records-retention obligations; and establish who owns approval for each proposed use case.
The firm calls unapproved employee use of free tools “shadow AI.” That is a real operational issue, especially for companies where staff paste customer emails, financial records, contracts, source code, or production details into consumer services. Yet an approved-tools list alone does not solve it. IT teams need a policy that says which data classifications may be used with which service, who can connect third-party AI tools to Microsoft 365, how prompts and generated content are retained, and who reviews automated outputs before they leave the company.
The release’s “Hand It Off or Hold On” model is a plain-language attempt to address that boundary. Routine, high-volume, rule-driven work may be suited to summarization, sorting, draft generation, extraction, or workflow routing. Work requiring professional judgment, authority, a signature, or a customer relationship remains with people. That distinction is sensible, though businesses should add a third category: tasks that can be AI-assisted but require documented human review before the output becomes a record, decision, payment instruction, or external communication.

Microsoft Copilot’s protections are real—but the implementation caveats are not optional​

Real IT’s website makes a broad case for Microsoft Copilot by saying business data stays in the Microsoft 365 tenant and is not used to train external models. Microsoft’s published enterprise data-protection documentation supports the core of that claim for organizational Copilot use: prompts, responses, and customer data are covered by Microsoft’s commercial terms, and they are not used to train foundation models.
But the company’s marketing compresses meaningful conditions into a simpler message. Microsoft says its HIPAA support applies to properly configured implementations, not every possible Copilot use. Microsoft also specifically notes that web search queries are outside the Data Protection Addendum and Business Associate Agreement coverage. Organizations with healthcare, financial, legal, export-control, or contractual confidentiality obligations cannot treat a Copilot license as a compliance control by itself.
The same caution applies to “your data stays in your tenant.” For mainstream Microsoft 365 Copilot scenarios, the tenant boundary and existing identity, encryption, retention, and access controls remain central protections. But Copilot can also use web search, third-party agents, connectors, Copilot Studio components, and external applications. Each can introduce different data handling, permissions, retention, regional processing, and contractual terms. Microsoft itself advises customers to review the privacy statement and terms for agents.
This is where a local advisory practice can be valuable if it is technically disciplined. The customer needs someone to answer specific questions: Are we deploying Microsoft 365 Copilot, Microsoft 365 Copilot Chat, Copilot Studio agents, or a consumer Copilot experience? Is web grounding enabled? Are third-party model providers involved? Which Microsoft 365 data sources can the tool see? Are existing permissions accurate? Is the tenant using Purview labels, data-loss-prevention policies, audit logging, and conditional access in a way that matches the proposed use case?
Those questions are more useful than a generic assurance that AI is “secure.” They also determine whether the rollout belongs under IT operations, compliance, legal, records management, or all four.

The named frameworks are training tools, not a substitute for controls​

The practice is built around three branded concepts: the CRAFTED prompting framework, the Hand It Off or Hold On decision model, and the “Five Hidden Costs of AI Adoption” analysis. CRAFTED expands prompts into context, role, audience, format, tone, explanation, and deliverable. The cost model focuses on unused subscriptions, training overhead, failed adoption, data risk, and vendor lock-in.
These may help nontechnical users write clearer prompts and leaders avoid purchasing licenses that nobody uses. Better prompting can reduce rework, and task triage can keep staff from treating generative output as an authoritative answer. Neither framework, however, verifies factual accuracy, enforces access controls, prevents sensitive data from being entered into the wrong service, or creates an auditable approval path.
Businesses should therefore measure this practice by what comes after the workshop. A useful engagement should leave behind an approved AI-use policy, a data classification matrix, a tool inventory, role-based access decisions, a prioritized remediation list, pilot success metrics, training records, an incident process, and a recurring review cadence. If the deliverable is primarily prompt cards and broad productivity claims, the company has bought education rather than governance.
Real IT’s own site says CRAFTED sessions can cover Copilot, ChatGPT, Claude, and Gemini. That broad tool coverage is practical for training, but it increases the need to separate consumer accounts from approved business services. Staff must understand that a prompt acceptable in a commercial Microsoft 365 tenant may be inappropriate in a personal account or an unapproved third-party chatbot.

What West Michigan SMBs should ask before signing​

The launch reflects a growing business opportunity for MSPs: customers want AI help, but few have the internal staff to handle data cleanup, identity controls, change management, and user training at the same time. Real IT is positioning itself to be that intermediary in West Michigan.
Prospective customers should insist that the initial assessment produce a written inventory of data sources, permissions, current AI use, and risk findings before any tool recommendation. They should also ask whether remediation of oversharing is included in scope; which Copilot SKU and features are proposed; whether web search, agents, or connectors are enabled; how success will be measured; and what ongoing governance costs after the initial deployment.
The release says Real IT’s AI practice is intended to move companies from readiness to measurable business outcomes. The first measurable outcome worth demanding is more basic: a Microsoft 365 environment where AI can only surface information the business has deliberately decided each user should be able to access.

References​

  1. Primary source: Digital Journal
    Published: 2026-08-04T03:28:49+00:00
  2. Related coverage: cbinsights.com
  3. Related coverage: my.linkedin.com
  4. Related coverage: support.microsoft.com
  5. Related coverage: techcommunity.microsoft.com
  6. Related coverage: learn.microsoft.com
  7. Related coverage: learn.microsoft.com
  8. Related coverage: techcommunity.microsoft.com