Who Is Using the AI in Your Office? If You Can't Answer, That's the Problem.
In every serious conversation we have with the leadership of a veterans service organization, the hard question is never "is the AI accurate?" It's a governance question, and one leader put it to us plainly this month: we will only put this in the hands of people we trust to use it the right way — as an aid to an officer's judgment, never a substitute for it. That instinct isn't resistance to technology. It's exactly correct, and any AI vendor who treats it as an obstacle is telling you who they are.
The real risk isn't the software. It's unmanaged use of it.
AI is already in your office, whether you invited it or not. Officers have browsers; free chatbots are a tab away; and a well-meaning volunteer pasting a veteran's medical history into a consumer chatbot is a privacy incident, a quality incident, and a trust incident all at once — invisible until it isn't. The choice in front of a service organization isn't AI or no AI. It's governed AI or ungoverned AI.
What governed looks like
Three mechanisms, none of them complicated:
1. Designated users, named by the organization. Nobody touches the tool unless leadership puts their name on a list. Access is granted the same day a name is added and removed the same day it's pulled. The organization — not the vendor, not enthusiasm — controls the roster, and can grow it exactly as fast as trust grows.
2. A per-person audit trail leadership can actually read. Every sign-in, every upload, every report viewed, every deletion — recorded under the individual officer's own name, in a tamper-evident log, available to the organization on request. "Trust but verify" only works when verification exists. If your vendor can't show you, person by person, how the tool is being used, then your access policy is a hope, not a control.
3. Outputs that are structurally incapable of replacing the officer. Everything the software produces is a draft until a service officer reviews, amends, and signs it. Nothing auto-files. Nothing goes to a veteran unreviewed. The tool reads; the officer decides. If a product can act without the officer, it isn't a tool — it's a liability with a login page.
Pricing has to make caution free. If a vendor charges per seat, every act of good governance costs money — and every shortcut saves it. That's backwards. Cover the whole office, and let leadership restrict freely.
That last point is why we price per office rather than per user: an organization should never face a bill for being careful, and never feel pushed to share logins (which destroys the audit trail) to save a seat fee.
Questions to put to any vendor — including us
- Who can create an account, and can we revoke one — how fast?
- Show me one officer's complete activity for last month. How long does that take you?
- Can anything the system produces reach a veteran or the VA without an officer signing it?
- What happens to a shared login in your audit trail? (Right answer: you prohibit them.)
- When an officer leaves, what's the offboarding — and is the removal itself logged?
These pair with our earlier checklist, Seven Questions for Any Vendor, which covers the data-handling side: training, retention, deletion, and breach duty.
The leaders asking the control question are the ones taking their accountability seriously. They're the people we build for. If that's you, the pilot is free — and it starts with exactly two accounts, or however many people you trust today.