Skip to main content
Back to blog

How I Assess a Business Before I Recommend Anything

frameworkassessmentbuild-in-public

How long would it take you to tell me how many active clients you have and what each one pays annually?

When I ask that question, most business owners hesitate. Not because they don't know their business, but because the answer lives in three different systems and someone's head. That hesitation tells me more about your technology situation than any audit ever will.

I've spent 12 years in IT. Started at Microsoft, then nearly a decade in the MSP world managing infrastructure for organizations of every size. I've seen what works. I've seen what doesn't. And the thing that separates a good technology engagement from a wasted one is what happens before anyone recommends anything.

Most IT providers show up and start selling. I show up and start asking questions.

Over the years, I built a framework for those questions. Five areas I check before I recommend a single product, service, or change. I call them pillars because they hold everything else up. If one of them is cracked, it doesn't matter how solid the others are.

Here's the framework I use. By the time you finish reading, you'll have a pretty good sense of where your business stands.

AI Readiness: Is Your Data Ready for What's Next?

"Has anyone on your team actually used AI for real work, or is it still people playing with ChatGPT?"

That question separates companies that are ready for AI from companies that want to be ready. The difference isn't enthusiasm. It's foundation. AI doesn't fix broken fundamentals. I wrote about this pattern before, companies reaching for AI when they haven't sorted out the basics.

Here's what I'm actually checking:

Level 1, Scattered. Data lives in spreadsheets, email inboxes, and people's heads. There's no single source of truth. You couldn't tell me how many active clients you have without checking three different places. This is where most small businesses start, and there's no shame in it. But AI isn't the next step. Organization is.

Level 2, Collected. You have systems (a CRM, accounting software, maybe a ticketing tool) but nothing talks to each other. The raw material exists, but it's siloed. Someone is re-typing information from one system into another. This is the most common place I find businesses.

Level 3, Organized. Your systems are connected or at least export cleanly. Data is consistent. Someone is responsible for keeping it that way. If you handed someone a report, they'd trust the numbers. This is where AI starts to make sense.

Level 4, AI-Ready. Your CRM updates itself from intake forms. Invoices go out without someone pressing send. When a report says "these five clients are at risk," your team knows what to do about it. Most small businesses aren't here yet, and that's fine. But this is the target.

The diagnostic question I ask: "Do your core systems share data automatically, or does someone re-type information between them?" The answer tells me your level almost immediately.

This approach is informed by what IBM calls the AI Ladder, a progression from collecting data to embedding intelligence into operations. I've adapted it for companies that don't have a data science team or a seven-figure AI budget.

Cloud & Infrastructure: Is Your Foundation Solid?

"If your office was inaccessible tomorrow (fire, flood, power outage) could your team keep working from home with full access to everything they need?"

Most business owners pause here. They know the honest answer.

Level 1, On-Premise. Servers under desks or in a closet. Backups are manual or nonexistent. If the office floods, you're down for days. I still find this more often than you'd think.

Level 2, Partial Cloud. Email is in the cloud (usually Office 365), but critical systems still run locally. Backups exist but have never been tested. There's no documented disaster recovery plan. This is the most dangerous level. You think you're covered, but you've never verified it.

Level 3, Cloud-First. Most workloads run in cloud or managed services. There's one place to manage who has access to what. Backups are automated and someone has actually tested them by restoring from them.

Level 4, Optimized. You could double your headcount next month and IT wouldn't need to scramble. Costs are tracked, security is automatic, and nobody is managing servers. Infrastructure becomes invisible. It just works.

The question that reveals the most: "If you fired someone today, how many different apps would you need to log into to cut off their access?" If the answer is more than one, your identity management has a gap.

This maps to Microsoft's Cloud Adoption Framework, a structured approach to moving from on-premise to cloud. I've simplified it for companies that aren't running enterprise Azure deployments.

Security: Are You Protected or Just Hoping?

"If an employee clicked a phishing link right now, do you have a plan for what happens next, or would everyone be figuring it out in real time?"

This is the question that gets the most uncomfortable silence. And that silence is the answer.

Level 1, Reactive. No formal security practices. You deal with problems when they happen. Passwords are weak or shared. You couldn't tell me how many devices have access to your company data. This isn't negligence. It's just that nobody made it a priority.

Level 2, Aware. You have antivirus. MFA is turned on for some systems (email, probably) but not everything. Someone loosely "owns" security. You know the risks but haven't documented anything or tested your response to an incident.

Level 3, Managed. Written security policies that people actually follow. Every device is inventoried and monitored. MFA is on everywhere it can be. Your team has practiced what happens when something goes wrong, not just talked about it.

Level 4, Adaptive. Your systems watch for problems themselves and alert you before damage is done. Security is part of how you make business decisions, not an afterthought bolted on after an incident.

The revealing question: "Could you name every device that can get to your company data right now? Laptops, phones, tablets, personal machines?" Most businesses can't. That's the gap.

This pillar draws from the federal government's cybersecurity framework, specifically the small business guide they published because they know most companies can't implement the enterprise version. I've taken the parts that matter for a 15-50 person company and dropped the rest.


If you've recognized your business in two or more of these pillars, that's worth a conversation. Not a sales pitch. Just a conversation about where the gaps are and what's actually worth fixing first. Talk to Janus, the AI concierge I built. He's a good place to start.


How Your Team Works: Are You Using What You're Paying For?

"Walk me through the last time someone had to print something, sign it, scan it back in, and email it. How often does that happen?"

When I ask this, people either laugh or groan. Both mean the same thing.

Level 1, Basic. Email and maybe Word and Excel. Files are saved on desktops or emailed back and forth. Everyone does things their own way. There's no shared workspace.

Level 2, Connected. Files are in a shared drive somewhere. Teams or Slack exists. Some people use it, some don't. The tools are available but adoption is uneven.

Level 3, Managed. Everyone is on the same tools, using them the same way. A new hire gets a standard setup on day one. Files have a home that isn't someone's desktop. There are actual processes for how work flows through the organization.

Level 4, Optimized. Routine approvals and repetitive tasks happen automatically. Nobody chases signatures or fills out the same form twice. You're making decisions based on actual data from your tools, not gut feel and tribal knowledge.

The telling question: "If a new employee started Monday, do they get a standard set of tools automatically, or does someone set it up from scratch each time?" The answer reveals how mature your operational processes really are.

This maps to Microsoft's maturity model for workplace technology. I use their framework to assess how much value you're getting from the tools you're already paying for. Most businesses are paying for about 80% more than they use.

Who Owns IT: Where Do Technology Decisions Get Made?

"When something breaks, is there a process for reporting and fixing it, or does someone yell across the office?"

This one usually gets a knowing smile. Because in most small businesses, the answer is the yelling.

Level 1, Chaotic. No IT processes. The "IT person" is whoever knows the most about computers. No ticket system, no documentation, no budget. When something breaks, everyone scrambles. Sound familiar?

Level 2, Reactive. There's a point of contact for IT, maybe an internal person, maybe an outsourced provider. Some things are documented. But there's no proactive maintenance, no formal budget tied to business goals. IT is a cost center that only gets attention when something is on fire.

Level 3, Defined. IT processes are documented and followed. There's a clear path for what happens when something breaks, how new people get set up, who manages vendors. An IT budget exists and someone is accountable for it.

Level 4, Measured. You know what IT costs, what it delivers, and whether that's getting better or worse. Technology spending connects to business goals, not just break-fix emergencies. IT is a business function, not a mystery line item.

The question that cuts through: "Do you have a list of every vendor and software your business depends on, with costs and renewal dates?" If the answer is no, nobody truly owns IT at your company. It's just happening to you.

This draws from enterprise service management principles, the idea that IT should run like a business function with accountability, process, and measurement. I've stripped it down to what actually matters for a company that doesn't have an IT department.

How the Pillars Connect

These five areas aren't independent. The value of this framework is in the gaps between pillars.

A business at Level 3 on Cloud & Infrastructure but Level 1 on Security has built a beautiful house and left the front door open. Level 3 on infrastructure but Level 1 on How Your Team Works means you're paying for tools nobody uses. Strong AI Readiness but weak IT governance means you have the data but nobody to make decisions about it.

The assessment finds those mismatches. They're where the biggest risks hide, and usually where the fastest fixes are too.

What Makes This Different

Most IT assessments are a junior technician running a checklist, feeding the results into a sales proposal. You get a document. Nobody explains what it means. Then they recommend their own products.

That's not how I work. When I assess a business, it's one senior person with 12 years of experience sitting down, asking questions, and giving you an honest picture of where you stand. I'll tell you what's urgent, what can wait, and what you don't need to spend money on at all. Sometimes the most valuable thing I do is save someone from a $20,000 mistake by pointing them to the right $30/month platform.

The framework you just read is the same one I use on every engagement. Now you have it too.

Want Me to Run This for Your Business?

The initial assessment is a conversation, not a sales pitch, and there's no cost. I'll walk through these five pillars with you, tell you what I see, and give you a clear picture of where you stand. No surprises, no upsells, no commitment.

You can start right here. Talk to Janus, the AI concierge I built for Griffin Atlas. Tell him what you're dealing with and he'll point you in the right direction. If you'd rather skip ahead, the contact form on that same page comes straight to me.

Either way, the first step is the same one I always take: asking questions before recommending anything.