Monthly watch
AI security features: a watch that does not go home at five.
A rule no one enforces is a wish. This subscription connects your AI Use Policy to the network your IT team runs. Approved tools are allowed. Sensitive data is blocked from public AI tools. New AI sign-ups go to someone for a decision. Every month you get a read on what appeared and what changed.
Sample client, month 3. Illustrative watch summary.
In one sentence
We make the AI rules real: approved tools allowed, sensitive data blocked, new AI sign-ups flagged.
- Advisory review
- Delivery
- Monthly watch
One engagement, in this order. You can start at the stage that fits you.
Monthly watch
What this work involves
A policy no one enforces is a wish. The AI security subscription connects your AI Use Policy to the network your IT team runs. Approved tools are allowed, sensitive data is blocked from public AI tools, and new sign-ups go to someone for a decision.
Each month the watch reports what appeared, what was blocked, what was approved, and what changed. AI tools that staff signed up for do not stay hidden for long.
The security subscriptions behind the watch are bought from Third Shift, alongside the Azure subscription, on one monthly bill. Our management of the watch is a set monthly fee.
Who does what
You keep your team, and we take this part.
- You — Decide the exceptions when one comes up.
- Third Shift — Run the watch and report what it found.
- Your IT firm — Keep the network and the computers running.
- Security vendors — Supply and run the security subscription.
Who it is for
A fit when
- Firms that adopted the AI Use Policy and want it enforced, not filed
- Regulated businesses that must show ongoing control of AI use
- Leadership that wants a monthly read on AI in the business
Scope
What it is not
- Not antivirus, firewalls, or backups. Your IT firm keeps those
- Not surveillance of staff. It watches tools and data, not people
Where this has run
Profiles using this work.
- Tax season copilots, zero policy.
Regional accounting firm · ~45 staff - Patient data was being entered into a public AI tool.
Multi-site healthcare practice · ~60 staff - A capable IT firm with no one directing its work.
Regional wholesale distributor · ~90 staff
Who buys this
Industries that start here.
- Medical, dental, and specialty practices — Patient letters drafted in an unapproved AI tool, and no rule to point to when someone asks.
The order
Part of the sequence, not the whole of it.
In the method this work usually leads into AI development (Build · priced per feature). Nothing obliges you to buy it: the order is how the work is delivered, not what you have to purchase.
Questions
Questions about ai security features
How do AI security features fit with our MSP's security stack?
AI security features sit on top of your IT firm's security tools, not in place of them. Your IT firm runs antivirus, sign-in protection, backups, and the firewall. The Third Shift AI security subscription controls which AI tools may touch which information, and reports on that to leadership every month.
Can you block staff from putting client data into public AI tools?
Yes, Third Shift can block staff from putting client data into public AI tools, for the information and the tools your AI Use Policy names. It uses controls already inside your Microsoft cloud account, plus the security subscriptions you buy from us. Approved tools keep working; the block applies only where the policy says it should.
What does the monthly AI report show?
The monthly AI report shows what leadership needs to know. New AI tools that appeared. What was blocked and what was approved. Open policy exceptions. What changed in your environment since last month. It is written for an owner or a COO, not for a security operations team.
Start here
Start with the review.
The first conversation covers your environment, and this work is scoped from what it finds.