Skip to content
AI 4 AllEnterprise AI Assistant
Open AI 4 All
EGUARDIAN Lanka · User Manual

Your governed AI assistant for everyone

AI 4 All gives every EGUARDIAN Lanka employee secure, cost-controlled access to Claude — connected to your email, calendar, CRM and helpdesk, with privacy guardrails built in.

Powered by Anthropic Claude Secured by Microsoft Entra ID Hosted on Azure (Singapore)
Open the assistant Get started

Getting started

You can send your first message in under five minutes — no training required.

Open AI 4 All in Chrome, Edge, Firefox or Safari using the link from IT. Bookmark it.
Sign in with Microsoft. Use your EGUARDIAN account. You'll be asked to approve multi-factor authentication (MFA).
Accept the Acceptable Use Policy on first login. This is a one-time step.
Type your question in the message box and press Enter. The answer streams back word by word.
First prompt ideasTry: “Summarise my unread emails from today”, “Draft a polite follow-up to this customer”, or “What deals are closing this month in CRM?”

Find your role

What you can do in AI 4 All depends on the role your administrator assigned. Pick yours to see what's available.

Standard Employee

Day-to-day AI assistance for the whole workforce.

  • Chat with the Haiku model — fast and cost-efficient
  • Connect to Microsoft 365 (Mail, Calendar, Contacts) and attach OneDrive files
  • Strong privacy profile: personal details are masked, sensitive data blocked
  • Monthly token allowance with an in-app usage indicator

Power User

For designated advanced users who need more capability.

  • Access to both Haiku and the more capable Sonnet model
  • Higher monthly token quota and broader tool (MCP) access
  • A relaxed guardrail profile for advanced work

Platform Administrator

IT / Operations staff who run the platform.

  • Full admin console: users, roles, token quotas, virtual keys
  • Manage MCP servers, guardrail rules and system prompts
  • View SCIM provisioning status, audit logs and FinOps dashboards

Super Administrator

VP Technology or delegate — the highest level of control.

  • Everything an administrator can do, plus manages administrators
  • Sets the global guardrail master policy and daily spend cap
  • Sensitive actions require dual-authorisation

Read-Only Auditor

InfoSec / Compliance — observe without changing anything.

  • Read-only access to audit logs, guardrail logs and shadow-AI logs
  • Usage and compliance reports
  • No ability to chat, change settings or manage users

Signing in

AI 4 All uses Microsoft Entra ID single sign-on — the same account you use for email. There is no separate password to remember.

Multi-factor authentication

You'll confirm your identity with MFA (e.g. the Microsoft Authenticator app). This is enforced by company policy and keeps your conversations secure.

Sessions & sign-out

Sessions are short-lived and refresh silently while you work. Signing out of Microsoft — or being disabled by IT — ends your AI 4 All access within a minute.

Sign in onceYour session is shared across the assistant, the admin console and this manual — sign in on any one and the others recognise you automatically. Use the menu in the bottom-left corner to move between them, switch theme, or sign out.
No account yet?Access is provisioned automatically from Entra ID. New joiners typically gain access shortly after their Microsoft account is created. If you can't sign in, contact IT Operations.

The chat interface

A familiar three-part layout: your history on the left, the conversation in the middle, your message box at the bottom.

Conversations Today's emails CRM deal review Draft proposal + New chat Summarise my unread emails You have 4 unread. The most urgent is from Finance about the Q3 invoice, due tomorrow… ● used 1,240 tokens · Haiku Message AI 4 All…

Streaming answers

Responses appear word by word so you can start reading immediately. Markdown is rendered — headings, lists, tables and code blocks all display cleanly.

Conversations are saved

Each chat is stored privately to your account so you can resume later. Start a new conversation any time without losing the old one.

Tool activity inline

When the assistant looks something up in email or CRM, you'll see the tool it used — expandable if you want the detail.

Export & save

Copy any answer, export a chat as text/Markdown, or save it straight to OneDrive in one click.

Models & smart routing

AI 4 All runs on two Claude models and automatically picks the right one for each request — you don't have to choose.

Claude Haiku default

Fast and economical. Handles everyday questions, summaries and drafting. Available to everyone.

Claude Sonnet Power User+

More capable for complex reasoning, analysis and longer tasks. Used when the request needs it and your role allows it.

How routing works

The AI Gateway Layer scores each request's complexity and routes it within your role's ceiling, optimising for cost by default. Simple questions always go to Haiku — even for power users — which keeps the platform fast and affordable.

Automatic failoverIf a model is briefly unavailable, AI 4 All retries on a backup within seconds. This is invisible to you — your answer still arrives.

Privacy & safety

Every message passes through the AI Gateway Layer (AGL) before it reaches Claude. This is what keeps EGUARDIAN's data safe — and it runs in milliseconds.

1Virtual key check
2PII & secrets scan
3Input guardrails
4Model routing
5Ask Claude
6Output guardrails
7Cost accounting
8Audit log

What you'll notice as a user

Personal data is masked

Names, contact details, ID numbers and card numbers are detected and replaced before anything leaves Azure — so you can paste real content safely.

Some content is blocked

If a request breaks a safety rule, you'll see a short, plain-English notice. You won't see technical rule details — just what to do next.

Your conversations are never used to train models. EGUARDIAN operates under a data processing agreement with Anthropic, and prompts are PII-masked before they're sent.

Your data & tools

AI 4 All can act on your behalf in connected systems using secure, permission-scoped connectors (MCP servers).

Microsoft 365

Read and summarise Mail, Calendar and Contacts. Uses your own permissions — it only sees what you can see.

Zoho CRM

Look up accounts, contacts, deals and activities to answer sales questions in plain language.

Zoho Desk

Search tickets, agents and knowledge-base articles to speed up support work.

Coming laterSAP Business One is planned for Phase 2. Available tools depend on your role.

Files & OneDrive

Bring documents into a conversation, and save results back — without files ever being stored on AI 4 All servers.

ActionHowNotes
Attach a fileUse the file picker to choose from OneDrivePDF, DOCX, XLSX, PPTX, TXT, MD
Use as contextThe file's text is passed to the assistant for the questionScanned for PII first
Save a resultSave an answer or whole transcript to OneDriveOne click
DisconnectRevoke OneDrive access in profile settingsAny time
Privacy by designFile contents are read at the moment you ask and discarded right after — nothing is kept on the platform.

Usage & cost

AI 4 All measures usage in tokens (pieces of text). Each role has a monthly allowance, and the platform shows you where you stand.

You've used 80% of your monthly allowance — usage may pause at 100%. Here's a summary of this month's closing deals… Three are due before Friday. ● 1,240 tokens · Haiku · $0.0021 Monthly usage 160,000 / 200,000 tokens
In-chat usage indicators — per-answer token cost, the 80% warning banner, and your monthly usage bar

Live counter

A small indicator shows the token cost of each answer and your monthly usage.

80% warning

A banner appears when you reach 80% of your monthly allowance so there are no surprises.

100% limit

At 100% new requests pause with a clear message. An admin can grant a one-time top-up.

Quotas reset monthly on the 1st. A daily platform spend cap also protects against runaway costs. Need more? Ask your Platform Administrator.

Admin console Admins only

Platform & Super Administrators manage AI 4 All from a single console.

Open the Admin Console →

User management Search name or email… Export CSV USER ROLE STATUS ACTION Alice Smith alice@eguardian.com Standard Active Suspend Bob Jones bob@eguardian.com Power User Active Suspend Chandni R. chandni@eguardian.com Platform Admin Suspended Reinstate 3 of 5 users · roles & suspensions are written to the audit log
Admin console — user management (search, filter, role assignment, suspend/reinstate, CSV export)
Users & roles
Search, filter and export the user list. Assign roles, suspend a user's AI access without touching their Microsoft account, and review SCIM provisioning status. All role changes are written to the immutable audit log.
Token quotas & FinOps
Set per-role quotas, grant one-time top-ups, and view real-time spend by user, role and department. Export FinOps data as CSV. Routing-efficiency savings are shown against a Sonnet-only baseline.
Guardrails & system prompts
Configure input/output guardrail rule sets per role, set role-based system prompts, and test a rule against a sample prompt before deploying it. Changes take effect within a minute — no restart.
MCP servers & virtual keys
Register, enable or disable MCP servers and see their health (last call, error rate, latency). View all active virtual keys with associated user, last use and cumulative spend. Real provider keys never leave Azure Key Vault.
Audit & shadow-AI logs
Browse the immutable audit trail and shadow-AI enforcement log (blocked attempts to reach AI providers directly). Viewing a user's conversation history requires dual-authorisation and is itself logged.

Roles & permissions

CapabilityStandardPowerPlatform AdminSuper AdminAuditor
Chat (Haiku)
Sonnet model
MCP toolsScopedBroad
Admin console
Manage admins
Audit & logsRead
Token quotaStandardElevatedElevatedUncapped

Acceptable use

By using AI 4 All you agree to the Acceptable Use Policy, acknowledged on first login.

Use the platform, not back doors

Accessing AI providers directly for work — bypassing AI 4 All — is prohibited and blocked at the network level ("shadow AI"). The gateway is the only authorised path.

Be mindful of content

Conversations are logged (without raw personal data) for security and compliance. Don't attempt to bypass guardrails or extract the system prompt.

Heads upAttempts to reach AI providers directly are recorded and reported to the Super Administrator. Stick to AI 4 All and you're covered.

Troubleshooting

I can't sign in
Confirm you're using your EGUARDIAN Microsoft account and have completed MFA. If your account is new, access may still be provisioning. Persisting? Contact IT Operations.
My request was blocked
A guardrail or PII rule may have stopped it. Rephrase without restricted content, or remove highly sensitive identifiers. The on-screen notice suggests a next step.
I've hit my token limit
Quotas reset on the 1st of each month. For urgent needs, ask a Platform Administrator for a one-time top-up.
A tool (email/CRM) isn't responding
The connected system may be temporarily unavailable, or the tool isn't enabled for your role. Try again shortly; admins can check MCP health in the console.
Answers seem cut off
Very long conversations can reach the model's context limit. Start a new chat for a fresh, faster session, or ask the assistant to summarise so far.

FAQ

Is my data safe with AI 4 All?
Yes. Personal data is masked before any request leaves Azure, traffic is encrypted, conversations are private to you, and your content is never used to train models.
Do I need to pick a model?
No. AI 4 All routes each request automatically within what your role allows.
Why was a name or number replaced with [REDACTED]?
That's the PII protection working. The assistant still understands the context, but the raw sensitive value is shielded.
Can I use AI 4 All on my phone?
Yes — it's a responsive web app that works in mobile browsers. A dedicated mobile app isn't part of Phase 1.
Who do I contact for help?
IT Operations for access and accounts; your Platform Administrator for quotas, roles and tools.

Glossary

AGLAI Gateway Layer — the security checkpoint every request passes through.
Entra IDMicrosoft's identity platform that signs you in (formerly Azure AD).
MCPModel Context Protocol — how AI 4 All connects to tools like email and CRM.
PIIPersonally Identifiable Information — data the AGL masks to protect privacy.
GuardrailA rule that blocks or transforms unsafe content.
TokenA small unit of text used to measure usage and cost.
Virtual keyA safe stand-in credential; the real AI provider key stays locked in Azure.
Shadow AIUsing AI providers directly, bypassing AI 4 All — not allowed.