AI IT & Security Manager
aka “IT Security Manager” in the catalog
The moment a key is pushed to your code or a critical CVE hits it, you get the rotate or upgrade steps. Every 15 minutes sites and SSL watched, weekly a real restore test, Monday a plain report.
- Category
- Operations, Engineering
- Scheduled tasks
- 8every few minutes, daily, weekly
- Runtime
- Hermes
- Works with
- ResticAWSPostgresGitHubHave I Been PwnedGoogle WorkspaceSentrySnykIMAP mailboxCloudflareSlack
- Hosting
- Fully managed, always on
- Weekly Client ReportWeekly on Monday at 09:00
- Site CheckEvery 15 minabout 672 runs a week
- Weekly Restore TestWeekly on Sunday at 03:00
- Weekly Security CheckWeekly on Monday at 06:00
- Daily Drift CheckDaily at 05:30
- Weekly Appsec SweepWeekly on Monday at 04:00
- Secret Leak WatchDaily
- Canary Mailbox SweepDaily
- Mon
- every 15mSite Check
- 04:00Weekly Appsec Sweep
- 05:30Daily Drift Check
- 06:00Weekly Security Check
- 09:00Weekly Client Report
- Tue
- every 15mSite Check
- 05:30Daily Drift Check
- Wed
- every 15mSite Check
- 05:30Daily Drift Check
- Thu
- every 15mSite Check
- 05:30Daily Drift Check
- Fri
- every 15mSite Check
- 05:30Daily Drift Check
- Sat
- every 15mSite Check
- 05:30Daily Drift Check
- Sun
- every 15mSite Check
- 03:00Weekly Restore Test
- 05:30Daily Drift Check
The moment it happens.
The AI IT & Security Manager does not wait for its next scheduled check. Connect a trigger and it starts the second the event arrives. Until you do, its schedule covers the same work.
GitHub webhook
When: Code pushed
Pushed commits scanned for leaked keys, rotate steps sent within minutes
GitHub webhook
When: Vulnerability alert
Critical CVE in code you run flagged with the exact upgrade command
How the AI IT & Security Manager works
Every run reads from the tools you connect, works through its brief, and keeps what it learns in a persistent workspace, so context carries forward instead of starting from scratch.
Connect the ones you use. It works with what it has.
- Weekly Client ReportWeekly on Monday at 09:00
- Site CheckEvery 15 min
- Weekly Restore TestWeekly on Sunday at 03:00
- Weekly Security CheckWeekly on Monday at 06:00
- Daily Drift CheckDaily at 05:30
- Weekly Appsec SweepWeekly on Monday at 04:00
- Secret Leak WatchDaily
- Canary Mailbox SweepDaily
Keeps in its workspace
- Who the owner is: business, timezone, quiet hours, delivery channel, what downtime costs
- Who the agent works for: business or agency mode, report reader, sign-off and tone for the weekly report
- The client access checklist: what to ask for per duty, least-privilege scope, and what each connection unlocks
- The owned sites, domains, hosts and repos in scope, with the authorization statement. Nothing outside this file is ever checked
- The standard systems are graded against: stack, cost budget, recovery targets, disaster scenarios, urgent interrupts, accepted risks
- What is backed up, the freshness policy, what the weekly restore test pulls, and the checks that prove a clean restore
A report after each run
Sent to your Slack, Telegram, or another channel you connect.
Drafts that wait for you
Anything that leaves your business is written for your approval, not sent on its own.
Answers in chat
Ask it about its work any time from the agent's chat in your dashboard.
The AI IT & Security Manager, on autopilot
Each task runs on its own schedule in a managed environment. Adjust any of them, or add your own.
Task 01Weekly on Monday at 09:00
Weekly Client Report
Write the weekly IT and security report covering the last 7 days. Read ~/workspace/BRAND.md (mode, reader, technical level, sign-off, tone), ~/workspace/OWNER.md and ~/workspace/STANDARDS.md (accepted risks)…
Once a week
Task 02Every 15 min
Site Check
Run the site check. Targets: every address in the WATCHED_URLS environment variable plus the 'Watched sites' list in ~/workspace/TARGETS.md. If there are none, end silently with no message. First, if quiet hours…
About 672 runs a week
Task 03Weekly on Sunday at 03:00
Weekly Restore Test
Run the weekly restore test. If no backup source is configured (RESTIC_REPOSITORY with RESTIC_PASSWORD, read-only AWS keys with a bucket named in ~/workspace/BACKUPS.md, or DATABASE_URL), end silently with no message…
Once a week
Task 04Weekly on Monday at 06:00
Weekly Security Check
Run the weekly security check on the assets in ~/workspace/TARGETS.md only, and only if its authorization statement is completed; otherwise end silently. Observe and report, never probe…
Once a week
Task 05Daily at 05:30
Daily Drift Check
Run the daily drift check: deltas only since ~/state/infra-seen.json (update it), exit fast when nothing changed. Each part runs only if its source is configured; skip the rest silently. (1) Cost…
About 7 runs a week
Task 06Weekly on Monday at 04:00
Weekly Appsec Sweep
If GITHUB_TOKEN is not set, or ~/workspace/TARGETS.md lists no repositories under a completed authorization statement, end silently. For those repositories only, run the weekly code security review: read-only, static…
Once a week
Task 07Daily
Secret Leak Watch
If GITHUB_TOKEN is not set, or ~/workspace/TARGETS.md lists no repositories under a completed authorization statement, end silently. Scan only the commits pushed since ~/state/secrets-seen.json…
About 7 runs a week
Task 08Daily
Canary Mailbox Sweep
If CANARY_DOMAIN, IMAP_HOST, IMAP_USER or IMAP_PASSWORD is not set, or ~/workspace/VENDORS.md has no seeded alias, end silently. First…
About 7 runs a week
What it delivers
Each run ends with a message in your channel. Here is the brief the AI IT & Security Manager's first task works from.
AI IT & Security ManagerAGENTWeekly on Monday at 09:00
Weekly Client Reportcompleted
The brief: Write the weekly IT and security report covering the last 7 days. Read ~/workspace/BRAND.md (mode, reader, technical level, sign-off, tone), ~/workspace/OWNER.md and ~/workspace/STANDARDS.md (accepted risks)…
Deploy this template and Qoren provisions a dedicated, managed cloud environment: no Docker, VPS, or server upkeep. Tailor the persona, schedules, and tools, use the managed model key or bring your own, and the agent stays online with activity, usage, and spend in one dashboard.
How deployment worksSee pricing
Product names and logos are trademarks of their respective owners, shown here to indicate what this template connects to.
Sell the IT & Security Manager to your clients
Run one IT & Security Manager per client, each in its own isolated environment, and bill it as a monthly retainer.
- A sample week before the sale. Give it a prospect's website and it builds a sample week of its work from public information, ready to attach to your pitch.
- A weekly report under your name. It opens with the counts your client can check, written as your agency, and comes to you to forward.
- A client access checklist. Exactly which logins to ask the client for, and what each one unlocks.
- Hosting from $19 a month per client. A dedicated environment for one agent, plus model usage, which depends on volume. On the agency plans, each client's cost shows on its own line.
AI IT & Security Manager template questions
What does the AI IT & Security Manager template do?
The moment a key is pushed to your code or a critical CVE hits it, you get the rotate or upgrade steps. Every 15 minutes sites and SSL watched, weekly a real restore test, Monday a plain report. It runs 8 scheduled tasks on a managed cloud environment.
Which runtime does the AI IT & Security Manager use?
It runs on the Hermes runtime in a dedicated cloud environment that Qoren provisions and keeps online for you.
How often does the AI IT & Security Manager run?
On a schedule you control. Out of the box it runs weekly on monday at 09:00, every 15 minutes, weekly on sunday at 03:00, weekly on monday at 06:00, daily at 05:30, weekly on monday at 04:00, daily. You can change the cadence, or trigger it on demand. It also reacts the moment something happens: code pushed, vulnerability alert, once you connect those triggers.
Will the AI IT & Security Manager do things without my approval?
No. It drafts and prepares the work, and you stay in control of anything that leaves your business. A reply, an invoice reminder, or a public post is written for your approval, not sent on its own.
Can an agency resell the IT & Security Manager to its clients?
Yes. Deploy one IT & Security Manager per client, each in that client's own isolated environment with its own keys. It ships with a client access checklist and writes a weekly report under your agency's name, ready for you to forward. Nothing goes to your client without your approval.
Does the IT & Security Manager need every tool connected?
No. Each duty starts when its tool is connected and stays silent until then. Give it a website and it builds a sample week from public information alone, before you connect anything.
What do I need to connect before it works?
Start from the template and connect the tools it needs, then set a model key: use the managed key included with your plan, or bring your own on any plan. The AI IT & Security Manager runs on the Hermes runtime.
6 duties, one agent.
Each duty is also a specialist template that deploys on its own.
Explore use cases- Operations
Website Uptime Monitoring Agent
aka “Site Watchdog”
Knows your site is down before your customers do. Uptime, SSL, errors, and CVEs watched around the clock
Every 15 minutes+2 more
Works with GitHub, Sentry, Snyk, Slack.3 tasks - Operations
Backup Recovery Testing Agent
aka “Backup Verifier”
Proves your backups actually restore. A real restore every week into a scratch space, integrity verified, so you find out before disaster does, not during.
Weekly on Sunday at 03:00+1 more
Works with Restic, AWS, Postgres, Slack.2 tasks - Operations
Security Hygiene Audit Agent
aka “Security Hygiene Auditor”
The boring security checks nobody runs, run monthly: leaked credentials, email auth, MFA gaps, dependency alerts on your own assets, each with the exact fix.
Monthly on day 1 at 07:00+1 more
Works with Have I Been Pwned, GitHub, Google Workspace, Slack.2 tasks - Operations
Leak Canary
Privacy and security monitoring that names names: a unique email alias per vendor, watched around the clock, so the day spam or phishing arrives you know exactly which vendor leaked or breached your data. Full-header evidence, immediate alerts, and a vendor trust ledger that grows with every signup.
Every 15 minutes+2 more
Works with IMAP mailbox, Cloudflare, Slack.3 tasks - Operations
Infrastructure Audit Agent
aka “Infra Guardian”
One agent that keeps your whole setup honest: costs not drifting, backups fresh and restorable, no single points of failure, and a real answer to "what happens if this breaks?". Graded weekly against your standards, with the gap and the fix on each. It watches; it never touches production.
Weekly on Monday at 07:00+2 more
Works with AWS, Postgres, Restic, Slack.3 tasks - Engineering
Application Security Review Agent
aka “Appsec Reviewer”
The security holes already sitting in your codebase (injection, broken auth, leaked secrets, unsafe data flows) found, ranked by exploitability, and explained with the fix. Your code only, read-only, propose-only.
Reacts toCode pushedWeekly on Monday at 04:00+1 more
Works with GitHub, Linear, Jira, Slack.2 tasks
Deploy the AI IT & Security Manager today.
Sign in, start from this template, and go live in minutes. Plans from $39/mo.