CtrlShiftIT
Our Process · How We Work

Engineers Who Treat Your ITLike It's Our Own

We're a hands-on team of systems engineers who genuinely love this stuff. We assess your setup, close the security gaps, document everything, and protect your business like it's our own — because watching a company get burned by a preventable failure is the one thing we can't stand.

Obsessed with uptimeSecurity-first onboardingDocs for everything
How We Work

Our 5-Step Process

One proven pipeline, from first look to long-term partnership. No skipped steps, no shortcuts.

01

Discovery & IT Review

We dig into your business, users, devices, network, and cloud apps — and listen to what's actually been driving your team nuts.

  • Business & user review
  • Environment inventory
  • Pain points & goals
02

Security & Risk Assessment

We hunt down the gaps — missing MFA, weak configurations, untested backups — before someone else finds them.

  • MFA & access controls
  • Endpoint & backup gaps
  • Risk & insurance readiness
03

Stabilization & Documentation

We clean up, lock down, and write everything down. Your environment becomes reliable, repeatable, and yours — not a mystery only we understand.

  • Access cleanup
  • Backup validation
  • Documentation baseline
04

Managed Support & Monitoring

We watch your systems around the clock and jump on issues before they ever reach your team.

  • Helpdesk & tickets
  • Monitoring & patching
  • Microsoft 365 support
05

Continuous Improvement

We keep tuning. Quarterly reviews, honest recommendations, and a roadmap that grows with your business.

  • Quarterly reviews
  • vCIO-style guidance
  • Future-ready planning
Onboarding

Your First 30 Days

A typical onboarding timeline. Exact pacing depends on your environment and company size.

Week 1

Discovery & Inventory

  • Kickoff & discovery
  • Access review
  • Environment inventory

Week 2

Security Baseline

  • MFA review & rollout
  • Backup validation
  • Risk & configuration review

Week 3

Documentation & Setup

  • Documentation creation
  • Endpoint & security configuration
  • Support workflow setup

Week 4

Stabilization & Roadmap

  • Environment stabilization
  • Reporting & recommendations
  • Roadmap & next steps
Why It Works

Not Your Typical IT Provider

Built for 5–50 employee businesses in the GTA, by engineers who care more about keeping you protected than closing a sale.

// security_first

We sweat the security details

MFA, backups, patching — we obsess over the boring stuff, because the boring stuff is what keeps your business running when it matters.

// docs_or_it_didnt_happen

We write everything down

Every system documented, every credential accounted for. You own the knowledge of your own IT — you're never locked in to us.

// protection_over_profit

We'd rather prevent the breach than sell the cleanup

We recommend what keeps you safe — not what earns a commission. If you don't need it, we'll tell you. No bloated licensing, no upsells, no fear-based selling.

// we_love_this_stuff

We genuinely love systems

Homelab nerds turned professionals. We read patch notes for fun, test restores on weekends, and treat your infrastructure like our own.

practices

Two practices, one operating discipline.

The same scoping, documentation, and change-control rhythm underpins both sides of the work.

Practice · 01

Security-first IT operations

Identity, endpoint, and tenant controls designed and operated against published frameworks. Built for small professional teams that need defensible posture without enterprise overhead.

  • Microsoft 365 / Entra ID hardening against CIS + Secure Score baselines
  • Endpoint posture with Defender for Business or comparable EDR
  • Conditional Access and identity perimeter design
  • Audit-ready documentation produced as engagement output
Reference doc · M365 Hardening Playbook · v1.0
Practice · 02

AI automation, governed

Workflow automation that sits on the identity, audit, and change-control surface already in use. Scoped pilots, named reviewer, reversible rollouts — the same change discipline applied to infrastructure work.

  • Intake, routing, and document workflows on top of M365 / Workspace
  • Tenant-inherited permissions — no new admin surface
  • Activity logging with named reviewer and weekly review cadence
  • Fallback paths and rollback documented before production
Reference doc · AI Governance Starter · v0.9
operating model

How the practice works.

Not a methodology page — the operating commitments the practice runs on, applied to every engagement regardless of which side it lives on.

01

Scoped, written engagements

Every engagement begins with a written scope: objective, target environment, deliverables, exclusions, and acceptance criteria. Nothing starts without it.

scoping doc · acceptance criteria
02

Documented before deployed

Configurations, control mappings, and runbooks are written before changes are applied. The documentation is the change record — not a deliverable produced after the fact.

design doc → change record
03

Change control on every action

Production changes follow a named reviewer + rollback pattern. Reversible by default; pilot-scoped before broad rollout; logged where the rest of your IT is logged.

reviewer · rollback · audit log
04

Handover, not lock-in

You receive the source of every artifact — configuration baselines, runbooks, threat models, automation definitions — in a format you can read, audit, and operate without us.

portable artifacts · documented exits
security thesis

Stated positions, cited sources.

Where the practice differs from generic SMB IT advice — each position grounded in current threat data and public frameworks.

Position · 02

M365 defaults are not a baseline

Out-of-the-box Microsoft 365 tenants leave legacy auth, oversharing, and unrestricted external mailflow available. A baseline is what you produce after deliberately configuring against a published control set.

Position · 03

EDR without response is alerting theatre

An endpoint product that fires alerts no one triages is not a security control. The response path — who sees the alert, in what window, with what authority — is the control.

ai automation thesis

Where AI earns its keep — and where it doesn't.

Counter-positions to most SMB AI marketing. Automation is a control surface; safety lives in the tenant, not the model.

Position · 01

Automate the repeated, not the strategic

AI workflows return on investment when applied to high-volume, low-judgement work — intake, routing, document extraction. Strategic decisions remain with named humans.

Position · 02

Govern the tenant, not the model

Workflow safety lives in the tenant: permissions, data residency, retention, audit logging. A governance framework that targets only the model misses where the actual risk sits.

Position · 03

Pilot small, reverse fast

Every production workflow ships with a fallback path and a rollback step. If the assistant is wrong, the work routes to a named human — and the change reverts without a war room.

methodology library

Published methodologies, treated as products.

Versioned playbooks the practice operates against. Read before engaging — audit during — keep after. The same artifacts every client receives.

Microsoft 365 · Identityv1.0

M365 Hardening Playbook

Sequenced control implementation against CIS M365 Foundations Benchmark, with Conditional Access, mail-flow, and external-sharing posture.

28 pages · updated 2026-04Published
Assessmentv0.8

Identity Perimeter Assessment

Methodology for evaluating MFA coverage, Conditional Access gaps, legacy authentication exposure, and session-token risk in small tenants.

16 pages · updated 2026-05Draft
AI Operationsv0.9

AI Governance Starter

Starter framework for small teams adopting AI workflows: permissions inheritance, activity logging, reviewer assignment, rollback paths.

22 pages · updated 2026-05Draft
Cloudv1.1

Tenant Migration Runbook

Pre-migration discovery, identity reconciliation, mailbox and OneDrive cutover sequencing, and post-migration verification for SMB tenants.

34 pages · updated 2026-03Published
Incident Responsev1.0

SMB IR Playbook

Tabletop-tested response sequence for small professional teams: containment, identity rotation, evidence handling, communications.

20 pages · updated 2026-02Published
Architecturev1.0

Reference Architectures

Opinionated reference architectures for professional services firms (5–50 staff) across M365, Azure, and AWS deployments.

40+ pages · updated 2026-04Published
sample deliverables

What you actually receive.

Sanitized first pages of real deliverables the practice produces. Format, structure, and depth — visible before you engage.

POSTURE ASSESSMENTPA-0142SAMPLE
1.0Executive Summary
64/100
RISK INDEX
p.01 / 18CONFIDENTIAL
Sample · sanitized

Security Posture Assessment

PDF · 18 pages · control mapping appendix
SECURE-SCORE BASELINESS-0088SAMPLE
2.0Current Posture
CURRENT62
90-DAY84
p.01 / 12CONFIDENTIAL
Sample · sanitized

M365 Secure-Score Baseline

PDF · 12 pages · baseline + 90-day plan
AI WORKFLOW DESIGNAI-0231SAMPLE
3.0Approval Workflow
TriggerGateAction
p.01 / 14CONFIDENTIAL
Sample · sanitized

AI Workflow Design Doc

PDF · 14 pages · governance + rollback
reference architecture

An opinionated baseline for a small professional team.

Microsoft 365 + Entra ID, hardened for 5–50 staff. Drawn by the practice; downloadable as PDF; tooling labels are real products used to convey opinion, not endorsement.

M365 · professional services · v1.0

Tenant-perimeter baseline for a 25-person firm

4 lanes · 15 nodes
Identity · endpoint · observability planesData planeProcess / change-control surfaceTrust cascade · hover a node for the rationale

Reference architectures are starting points, not deployments. A production architecture is produced as a discovery output, scoped to your tenant, and reviewed before any change is queued.

See how we work
operating principles

Six commitments we work under.

Stated commitments that govern engagement behavior. They are linked from the engagement letter and apply to every piece of work the practice executes.

  1. 01

    We recommend only tooling we have operated.

    No vendor recommendation enters a proposal unless the practice has run it in production conditions long enough to know its failure modes.

  2. 02

    Documentation is the deliverable.

    Every engagement produces written artifacts — design docs, runbooks, control mappings, change records — in a portable format you can operate without us.

  3. 03

    Reversible by default.

    Production changes ship with a documented rollback path. Pilots precede broad rollouts. Reviewer is named before the change is queued.

  4. 04

    Frameworks over opinions.

    Recommendations cite a public framework or measurable baseline (CIS, NIST CSF, M365 Secure Score). “Best practice” without a source is not a control.

  5. 05

    We name what we do not do.

    Out-of-scope items are written into every engagement. Where another provider is the right answer — 24/7 SOC, audit certification, legal counsel — we say so.

  6. 06

    No claim without verification.

    Every framework, benchmark, and number we cite traces to a public source or our own records. We do not invent certifications or imply partner tiers we have not earned — capability is demonstrated through published methodology and sample work you can audit before engaging.

Operating Principles · v1.0Updated 2026-04
engagement process

From inquiry to portable handover.

No surprise scope, no rolling retainer creep. Each phase produces a written artifact; the engagement ends with you holding the source.

  1. 01

    Scoping call

    45 min

    Discovery of environment, current pain, and desired outcome. No deliverable produced; you receive notes and a recommended next step.

    Output · scoping notes
  2. 02

    Discovery

    1–2 weeks

    Read-only access to your tenant and documentation. We map the environment, list findings, and reference each against a published control set.

    Output · discovery report
  3. 03

    Proposal

    3–5 days

    Written engagement letter: scope, deliverables, acceptance criteria, exclusions, and fixed-fee or T&M structure. You review before signing.

    Output · engagement letter
  4. 04

    Engagement

    2–6 weeks

    Work executed against the written scope. Weekly written status; production changes follow the reviewer + rollback pattern. No surprise scope.

    Output · weekly status + artifacts
  5. 05

    Handover

    1 week

    Full artifact handover: design docs, runbooks, control mappings, change records. Walkthrough with your internal owner. You can operate without us.

    Output · portable artifact set
ops@ctrlshiftit: ~/next-step

Ready to bring structure to your IT?

Book a security-first IT review — no sales pitch, just an honest look at where your environment stands and what we'd fix first.

no obligation~30 minutesGTA-based engineers

FAQ

Common questions

6 results
OnboardingHow long does onboarding take?

Most businesses are fully onboarded in 2–4 weeks depending on environment size, complexity, and documentation readiness.

OnboardingDo you replace our current IT setup immediately?

No. We assess what's working, stabilize the gaps, and improve incrementally. Disruptive changes are planned carefully with your team.

CoverageCan you work with Microsoft 365 or Google Workspace?

Yes. We support both platforms — licensing, configuration, security hardening, and ongoing management for either environment.

OnboardingDo you support businesses without existing documentation?

Absolutely — that's one of the most common situations we encounter. Building your IT documentation baseline is a core part of our onboarding.

CoverageIs this only for companies with existing IT problems?

Not at all. Many clients come to us proactively — they want better security, cleaner documentation, and a reliable support model before problems occur.

SecurityCan this help with cyber insurance readiness?

Yes. Our security assessment and documentation process directly supports cyber insurance applications. We help you demonstrate the controls insurers look for.