AI IT & Security Manager

aka “IT Security Manager” in the catalog

The moment a key is pushed to your code or a critical CVE hits it, you get the rotate or upgrade steps. Every 15 minutes sites and SSL watched, weekly a real restore test, Monday a plain report.

Category
Operations, Engineering
Scheduled tasks
8every few minutes, daily, weekly
Runtime
Hermes
Works with
ResticAWSPostgresGitHubHave I Been PwnedGoogle WorkspaceSentrySnykIMAP mailboxCloudflareSlack
Hosting
Fully managed, always on
AI IT & Security Manager/Schedule
online, a typical week
  • Weekly Client ReportWeekly on Monday at 09:00
  • Site CheckEvery 15 minabout 672 runs a week
  • Weekly Restore TestWeekly on Sunday at 03:00
  • Weekly Security CheckWeekly on Monday at 06:00
  • Daily Drift CheckDaily at 05:30
  • Weekly Appsec SweepWeekly on Monday at 04:00
  • Secret Leak WatchDaily
  • Canary Mailbox SweepDaily
  1. Mon
    • every 15mSite Check
    • 04:00Weekly Appsec Sweep
    • 05:30Daily Drift Check
    • 06:00Weekly Security Check
    • 09:00Weekly Client Report
  2. Tue
    • every 15mSite Check
    • 05:30Daily Drift Check
  3. Wed
    • every 15mSite Check
    • 05:30Daily Drift Check
  4. Thu
    • every 15mSite Check
    • 05:30Daily Drift Check
  5. Fri
    • every 15mSite Check
    • 05:30Daily Drift Check
  6. Sat
    • every 15mSite Check
    • 05:30Daily Drift Check
  7. Sun
    • every 15mSite Check
    • 03:00Weekly Restore Test
    • 05:30Daily Drift Check

Default schedule from the template. Change any time, or run a task on demand.

The moment it happens.

The AI IT & Security Manager does not wait for its next scheduled check. Connect a trigger and it starts the second the event arrives. Until you do, its schedule covers the same work.

  • GitHub webhook

    When: Code pushed

    Pushed commits scanned for leaked keys, rotate steps sent within minutes

  • GitHub webhook

    When: Vulnerability alert

    Critical CVE in code you run flagged with the exact upgrade command

How the AI IT & Security Manager works

Every run reads from the tools you connect, works through its brief, and keeps what it learns in a persistent workspace, so context carries forward instead of starting from scratch.

Reads from
ResticAWSPostgresGitHubHave I Been PwnedGoogle WorkspaceSentrySnykIMAP mailboxCloudflare

Connect the ones you use. It works with what it has.

AI IT & Security Manager
  1. Weekly Client ReportWeekly on Monday at 09:00
  2. Site CheckEvery 15 min
  3. Weekly Restore TestWeekly on Sunday at 03:00
  4. Weekly Security CheckWeekly on Monday at 06:00
  5. Daily Drift CheckDaily at 05:30
  6. Weekly Appsec SweepWeekly on Monday at 04:00
  7. Secret Leak WatchDaily
  8. Canary Mailbox SweepDaily

Keeps in its workspace

  • Who the owner is: business, timezone, quiet hours, delivery channel, what downtime costs
  • Who the agent works for: business or agency mode, report reader, sign-off and tone for the weekly report
  • The client access checklist: what to ask for per duty, least-privilege scope, and what each connection unlocks
  • The owned sites, domains, hosts and repos in scope, with the authorization statement. Nothing outside this file is ever checked
  • The standard systems are graded against: stack, cost budget, recovery targets, disaster scenarios, urgent interrupts, accepted risks
  • What is backed up, the freshness policy, what the weekly restore test pulls, and the checks that prove a clean restore
Delivers
  • A report after each run

    Sent to your Slack, Telegram, or another channel you connect.

  • Drafts that wait for you

    Anything that leaves your business is written for your approval, not sent on its own.

  • Answers in chat

    Ask it about its work any time from the agent's chat in your dashboard.

The AI IT & Security Manager, on autopilot

Each task runs on its own schedule in a managed environment. Adjust any of them, or add your own.

  1. Task 01Weekly on Monday at 09:00

    Weekly Client Report

    Write the weekly IT and security report covering the last 7 days. Read ~/workspace/BRAND.md (mode, reader, technical level, sign-off, tone), ~/workspace/OWNER.md and ~/workspace/STANDARDS.md (accepted risks)…

    Once a week

  2. Task 02Every 15 min

    Site Check

    Run the site check. Targets: every address in the WATCHED_URLS environment variable plus the 'Watched sites' list in ~/workspace/TARGETS.md. If there are none, end silently with no message. First, if quiet hours…

    About 672 runs a week

  3. Task 03Weekly on Sunday at 03:00

    Weekly Restore Test

    Run the weekly restore test. If no backup source is configured (RESTIC_REPOSITORY with RESTIC_PASSWORD, read-only AWS keys with a bucket named in ~/workspace/BACKUPS.md, or DATABASE_URL), end silently with no message…

    Once a week

  4. Task 04Weekly on Monday at 06:00

    Weekly Security Check

    Run the weekly security check on the assets in ~/workspace/TARGETS.md only, and only if its authorization statement is completed; otherwise end silently. Observe and report, never probe…

    Once a week

  5. Task 05Daily at 05:30

    Daily Drift Check

    Run the daily drift check: deltas only since ~/state/infra-seen.json (update it), exit fast when nothing changed. Each part runs only if its source is configured; skip the rest silently. (1) Cost…

    About 7 runs a week

  6. Task 06Weekly on Monday at 04:00

    Weekly Appsec Sweep

    If GITHUB_TOKEN is not set, or ~/workspace/TARGETS.md lists no repositories under a completed authorization statement, end silently. For those repositories only, run the weekly code security review: read-only, static…

    Once a week

  7. Task 07Daily

    Secret Leak Watch

    If GITHUB_TOKEN is not set, or ~/workspace/TARGETS.md lists no repositories under a completed authorization statement, end silently. Scan only the commits pushed since ~/state/secrets-seen.json…

    About 7 runs a week

  8. Task 08Daily

    Canary Mailbox Sweep

    If CANARY_DOMAIN, IMAP_HOST, IMAP_USER or IMAP_PASSWORD is not set, or ~/workspace/VENDORS.md has no seeded alias, end silently. First…

    About 7 runs a week

What it delivers

Each run ends with a message in your channel. Here is the brief the AI IT & Security Manager's first task works from.

# agent-updatesScheduled run

AI IT & Security ManagerAGENTWeekly on Monday at 09:00

Weekly Client Reportcompleted

The brief: Write the weekly IT and security report covering the last 7 days. Read ~/workspace/BRAND.md (mode, reader, technical level, sign-off, tone), ~/workspace/OWNER.md and ~/workspace/STANDARDS.md (accepted risks)…

Reply to AI IT & Security Manager, or ask it anything

Deploy this template and Qoren provisions a dedicated, managed cloud environment: no Docker, VPS, or server upkeep. Tailor the persona, schedules, and tools, use the managed model key or bring your own, and the agent stays online with activity, usage, and spend in one dashboard.

How deployment worksSee pricing

Product names and logos are trademarks of their respective owners, shown here to indicate what this template connects to.

Sell the IT & Security Manager to your clients

Run one IT & Security Manager per client, each in its own isolated environment, and bill it as a monthly retainer.

Price the retainerHow agencies use Qoren

  • A sample week before the sale. Give it a prospect's website and it builds a sample week of its work from public information, ready to attach to your pitch.
  • A weekly report under your name. It opens with the counts your client can check, written as your agency, and comes to you to forward.
  • A client access checklist. Exactly which logins to ask the client for, and what each one unlocks.
  • Hosting from $19 a month per client. A dedicated environment for one agent, plus model usage, which depends on volume. On the agency plans, each client's cost shows on its own line.

AI IT & Security Manager template questions

What does the AI IT & Security Manager template do?

The moment a key is pushed to your code or a critical CVE hits it, you get the rotate or upgrade steps. Every 15 minutes sites and SSL watched, weekly a real restore test, Monday a plain report. It runs 8 scheduled tasks on a managed cloud environment.

Which runtime does the AI IT & Security Manager use?

It runs on the Hermes runtime in a dedicated cloud environment that Qoren provisions and keeps online for you.

How often does the AI IT & Security Manager run?

On a schedule you control. Out of the box it runs weekly on monday at 09:00, every 15 minutes, weekly on sunday at 03:00, weekly on monday at 06:00, daily at 05:30, weekly on monday at 04:00, daily. You can change the cadence, or trigger it on demand. It also reacts the moment something happens: code pushed, vulnerability alert, once you connect those triggers.

Will the AI IT & Security Manager do things without my approval?

No. It drafts and prepares the work, and you stay in control of anything that leaves your business. A reply, an invoice reminder, or a public post is written for your approval, not sent on its own.

Can an agency resell the IT & Security Manager to its clients?

Yes. Deploy one IT & Security Manager per client, each in that client's own isolated environment with its own keys. It ships with a client access checklist and writes a weekly report under your agency's name, ready for you to forward. Nothing goes to your client without your approval.

Does the IT & Security Manager need every tool connected?

No. Each duty starts when its tool is connected and stays silent until then. Give it a website and it builds a sample week from public information alone, before you connect anything.

What do I need to connect before it works?

Start from the template and connect the tools it needs, then set a model key: use the managed key included with your plan, or bring your own on any plan. The AI IT & Security Manager runs on the Hermes runtime.

6 duties, one agent.

Each duty is also a specialist template that deploys on its own.

Explore use cases

Deploy the AI IT & Security Manager today.

Sign in, start from this template, and go live in minutes. Plans from $39/mo.