Advisory review
AI security assessment: find every AI tool in use, then rank the gaps.
Most companies can list the AI tools they bought. Almost none can name the ones staff signed up for, or the AI a vendor switched on inside software you already run. We count all of it, work out what data reaches which tool, and hand you a ranked list of what to fix first.
Sample client, month 1. Illustrative findings.
In one sentence
We find every AI tool already in use, including the ones staff signed up for, and rank what to fix first.
- Advisory review
- Delivery
- Monthly watch
One engagement, in this order. You can start at the stage that fits you.
Advisory review
What this work involves
Most companies can name the AI tools they bought. Few can name the ones staff signed up for on their own, or the assistants and add-ons that vendors switched on inside systems you already run. The AI security and governance assessment finds both. Governance here means the rules for AI use and who enforces them, so this is an AI governance assessment as much as a security one.
Each finding is measured against your AI Use Policy and ranked by what it exposes: what data is reaching which tool, under whose account, and how long it is kept. The result is a short list of gaps in priority order, not a hundred-page report.
Those priorities then decide what happens next. Which systems connect to the dashboard first, and what the AI security subscription watches from day one, both come from this list.
Who does what
You keep your team, and we take this part.
- You — Give us access and tell us what matters most.
- Third Shift — Find the tools, rank the gaps, and set the order.
- Your IT firm — Fix what sits inside its own systems.
- Software vendors — Answer for the AI they switched on.
Who it is for
A fit when
- Leadership that suspects AI use is wider than the license count
- Firms holding client, patient, or financial data under regulation
- IT teams that want an outside read before AI is connected to live systems
Scope
What it is not
- Not a penetration test or a general security audit
- Not a replacement for your IT firm's security tools. It reads the AI layer on top of them
- Not a one-time snapshot. The AI security subscription keeps it current
Where this has run
Profiles using this work.
- Tax season copilots, zero policy.
Regional accounting firm · ~45 staff - Reporting was three exports reconciled by hand.
Light manufacturer · ~120 staff - Patient data was being entered into a public AI tool.
Multi-site healthcare practice · ~60 staff - Grant reports took a week, though the data was already available.
Regional nonprofit · ~25 staff - The IT director left mid-project, but the project continued.
Regional construction firm · ~180 staff
Who buys this
Industries that start here.
- Accounting, tax, and CPA firms — Client financials in personal AI accounts, and partner reporting rebuilt by hand every quarter.
- Light manufacturing and industrial — An unenforceable ban upstairs, and a monthly report assembled from three exports by hand.
- Construction, trades, and engineering — Job costing that depends on one person's spreadsheet, and an IT director who left mid-project.
- Medical, dental, and specialty practices — Patient letters drafted in an unapproved AI tool, and no rule to point to when someone asks.
The order
Part of the sequence, not the whole of it.
In the method this work usually leads into Applications assessment (Assessment). Nothing obliges you to buy it: the order is how the work is delivered, not what you have to purchase.
Questions
Questions about ai security & governance assessment
How do you find the AI tools staff signed up for on their own?
Third Shift finds AI tools staff signed up for on their own by reading sign-in records, network activity, browser add-ons, and expense claims. We also ask team leads what people are actually using. Personal AI accounts and browser add-ons are the most common finds, followed by AI features a software vendor switched on without anyone noticing.
Will the assessment conflict with our MSP's security work?
No, the assessment does not conflict with your IT firm's security work. Your IT firm protects the computers, the sign-ins, and the network. The assessment reads the AI layer on top of that: which AI tools are in use, what information reaches them, and under whose accounts. Where a fix lands on your IT firm, we share the finding with them.
What do we get at the end of the assessment?
At the end of the AI security assessment you get four things. A list of every AI tool in use, approved or not. A map of where your information goes and who can reach it. The gaps ranked by what they expose. And a short list of what to fix first, which sets what happens next.
Start here
Start with the review.
The first conversation covers your environment, and this work is scoped from what it finds.