Advisory review
A written AI Use Policy, adopted by your leadership.
Your staff are already using Copilot and unapproved AI tools, and most firms have never written down what is allowed. We write those rules with you: which tools are approved, what may go into them, who signs off on exceptions. Then we run the meeting where your leadership agrees to it, so the policy is one people follow.
Sample client, month 1. Illustrative policy matrix.
In one sentence
A one-page rule that says who can use AI, on what work, and who decides.
- Advisory review
- Delivery
- Monthly watch
One engagement, in this order. You can start at the stage that fits you.
Advisory review
What this work involves
An AI use policy for a business is a short written document. It says who may use which AI tools, on what kinds of information, and who decides when someone wants an exception. Staff are already using unapproved AI tools and Copilot. In most firms no one has written down what is allowed, so the answer to can I put this in a public AI tool becomes whatever each person decides that day.
We write the policy with your leadership, not for them. The adoption meeting is where the rules get argued about and settled. That is why the document matches how the business actually runs, instead of how a template says it should.
The policy is the reference point for everything after it. The assessment measures what you run against it, the dashboard enforces parts of it, and any automation we build stays inside its limits.
Who does what
You keep your team, and we take this part.
- You — Agree the rules and adopt the policy.
- Third Shift — Draft it, run the meeting, and keep it current.
- Your IT firm — Turn the rules into settings on your systems.
- Software vendors — Supply the tools the policy approves or bans.
Who it is for
A fit when
- Firms where staff already use AI tools and no rules are written down
- Leadership that has been asked by a board, an auditor, or a client what the AI policy is
- Companies about to connect AI to real systems and customer data
Scope
What it is not
- Not a downloaded template with your logo on it
- Not a ban on AI. It sets the rules for use; it does not stop it
- Not legal advice. We work with your lawyer where the policy touches contracts or regulation
Where this has run
Profiles using this work.
- Tax season copilots, zero policy.
Regional accounting firm · ~45 staff - Reporting was three exports reconciled by hand.
Light manufacturer · ~120 staff - They asked for automation and needed a foundation first.
Professional services firm · ~30 staff - Patient data was being entered into a public AI tool.
Multi-site healthcare practice · ~60 staff - Grant reports took a week, though the data was already available.
Regional nonprofit · ~25 staff - Two Microsoft accounts, one renewal, and Copilot waiting.
Regional insurance agency · ~70 staff - A capable IT firm with no one directing its work.
Regional wholesale distributor · ~90 staff - The IT director left mid-project, but the project continued.
Regional construction firm · ~180 staff
Who buys this
Industries that start here.
- Accounting, tax, and CPA firms — Client financials in personal AI accounts, and partner reporting rebuilt by hand every quarter.
- Legal, consulting, and agency firms — They asked for an automation, and the environment needed a written rule first.
- Light manufacturing and industrial — An unenforceable ban upstairs, and a monthly report assembled from three exports by hand.
- Wholesale distribution and logistics — A capable MSP, no one directing it, and fill rate answered by three exports and a phone call.
- Construction, trades, and engineering — Job costing that depends on one person's spreadsheet, and an IT director who left mid-project.
- Medical, dental, and specialty practices — Patient letters drafted in an unapproved AI tool, and no rule to point to when someone asks.
- Nonprofits and associations — Grant reports that take a week, volunteers using free AI on donor lists, and no IT staff.
- Insurance agencies and brokerages — Two systems of record, shared carrier logins, and a renewal calendar no one watches.
The order
Part of the sequence, not the whole of it.
In the method this work usually leads into AI security & governance assessment (Advisory review). Nothing obliges you to buy it: the order is how the work is delivered, not what you have to purchase.
Questions
Questions about ai use policy
What is an AI Use Policy and why do we need one?
An AI Use Policy is a short written rule for your business. It says who may use which AI tools, on what kinds of information, and who signs off when someone wants an exception. Your staff are almost certainly using unapproved AI tools or Copilot already. The policy is what turns that use from something no one can see into something leadership has agreed to and can enforce.
Why does the policy come before connection?
The AI Use Policy comes before any system is connected because what gets connected depends on it. The review measures what you run against the policy, the dashboard only connects to what the policy allows, and any automation stays inside its limits. Connect first and write the rules later, and you usually end up rebuilding both.
How long does the AI Use Policy take?
The AI Use Policy usually takes two to four weeks from the first conversation to a policy your leadership has adopted. That includes the meeting where the rules get argued about and agreed. The AI security assessment, which finds every AI tool already in use, runs alongside it in the same window.
Can we just use a template policy?
You can use a template AI policy, and it will sit in a folder. A policy only works when your leadership has argued the rules through and agreed to them. Third Shift writes the policy for your roles and your kinds of information, then runs the meeting where that agreement happens. That is the part a download cannot do.
Start here
Start with the review.
The first conversation covers your environment, and this work is scoped from what it finds.