
Service operations
The desk you already have, doing the work it was meant to do.
A hundred and eight named outcomes across the twelve domains of IT service management — running on the platform you already own, with every action gated, evidenced and attributable.
Where this runs
Your ITSM estate is the interface.
Nothing here asks you to replace the system of record. The agents work inside it — reading, preparing, routing and evidencing — through the platforms below.
A worked example
Ten resolved tickets, checked before anyone looks.
A desk closes tickets. An agent re-checks the condition of each one against monitoring, logs and asset state — and only the genuinely resolved are safe to close.
How the outcomes get delivered
Native agents work the queue. Your people work the exceptions.
Every one of the hundred and eight outcomes is delivered the same way: an agent senses the work where it arrives — a ticket, an alert, a change window — prepares it completely, passes through the gate that class of action deserves, acts inside the platform, and signs the record. The productivity is not a chatbot on the side of the desk. It is the removal of the reading, chasing, assembling and re-checking that used to consume the desk.
What the agent automates
Triage and classification on arrival. Enrichment — the user, the asset, the history, the similar cases, assembled before anyone opens the ticket. Routing to the right queue the first time. Resolution of the routine and reversible, end to end. Verification that a “resolved” ticket is resolved in the monitoring, the logs and the asset state — not just in the ticket’s own claim. And the follow-up nobody had time for: knowledge drafted from what was learned.
What your people keep
The decisions. Approvals for anything irreversible or expensive sit with a named person, enforced in the path the action has to travel — not in a guideline. What changes for the team is the shape of the day: the queue’s depth stops mattering because the agent reads all of it, and the person’s judgment is spent on the exceptions, where it was always supposed to be.
The measure we work to is not deflection. It is cost per resolved-and-verified outcome, with the evidence attached — a number your own records produce, before and after.
How to read the catalogue
Every outcome carries a gate and a status.
Auto
Completes within policy — alerts, reminders, routing and low-risk requests.
Approve
Prepares the work; a named person reviews and commits it.
Advise
Analysis and evidence only; nothing happens on the agent's initiative.
Runs in production on the platform today and can be demonstrated on working software.
Assembled from components already in production; the assembly for this use is a scoped build.
Specified with a clear data path but not yet built — scoped as a build, never presented as available.
We will tell you in the same breath which category an outcome is in. A design is scoped as a build and priced as a build — never presented as available.
Domain A · 12 outcomes
Intake and first-line triage
| Outcome | Gate | Status | |
|---|---|---|---|
| A1 | Category and subcategory correction at intake, with the reason the user's selection changed recorded | Auto | Live |
| A2 | Duplicate and child detection on asset, symptom and time window, then link or merge | Approve | Live |
| A3 | Priority correction against affected-user count, asset criticality and service map rather than the caller's severity | Approve | Live |
| A4 | Assignment routing on symptom, ownership and resolver history, with its own misroutes reported | Auto | Live |
| A5 | Missing-information chase, naming the specific field or artefact and holding the clock state correctly | Auto | Component |
| A6 | Ticket creation from unstructured email and chat threads, with the evidence attached | Auto | Component |
| A7 | Monitoring alert to incident already carrying metric series, asset, recent changes and prior occurrences | Auto | Live |
| A8 | Alarm storm collapse into one parent, with derived children suppressed | Auto | Live |
| A9 | Major-incident candidate flagging on the pattern that precedes one, before the volume arrives | Approve | Component |
| A10 | Language normalisation for offshore desks, original text preserved as the record of truth | Auto | Component |
| A11 | Contractual and priority-account detection at intake, applying the right handling path | Auto | Component |
| A12 | Misdirected request redirection — requests filed as incidents, employee matters filed to IT, security filed to the desk | Approve | Component |
Domain B · 12 outcomes
Verification and closure quality
| Outcome | Gate | Status | |
|---|---|---|---|
| B1 | Post-resolution condition check across monitoring, logs and asset state before an engineer looks | Approve | Live |
| B2 | Work-note quality scoring against what a future engineer would need, returning the unusable | Approve | Component |
| B3 | Close-code accuracy validation against what actually happened, correcting systematic miscoding | Approve | Live |
| B4 | Premature-closure detection by pattern rather than by sampling | Advise | Live |
| B5 | Reopen prediction, holding the highest-risk closures for a second look | Advise | Component |
| B6 | Resolution-to-knowledge conversion, deduplicated against what exists, for owner approval | Approve | Component |
| B7 | Full-population quality review against the rubric, reported by engineer and queue | Advise | Live |
| B8 | Asset attribution correction at closure, so problem management is not built on noise | Approve | Component |
| B9 | Resolution-time integrity check — clock manipulation, back-dating, pending-state abuse | Advise | Component |
| B10 | Confirmation chase and close on the substance of the reply rather than on the timer | Auto | Component |
| B11 | Repeat-caller and repeat-asset detection across separately closed tickets, raising a problem candidate | Advise | Live |
| B12 | Closure evidence pack — the evidence the decision rested on and the human who approved it, sealed | Auto | Live |
Domain C · 10 outcomes
Request fulfilment and catalogue
| Outcome | Gate | Status | |
|---|---|---|---|
| C1 | Access request eligibility pre-check against role, entitlement policy and segregation-of-duties rules | Approve | Component |
| C2 | Approval chase and stalled-request recovery, reporting which approvers are the structural bottleneck | Auto | Component |
| C3 | Catalogue item selection help — interpreting what was actually asked for | Auto | Component |
| C4 | Fulfilment orchestration across systems, reconciling what was granted against what was requested | Approve | Component |
| C5 | Licence request against the entitlement pool, reclaiming unused allocations | Approve | Component |
| C6 | Joiner, mover and leaver completeness, surfacing tasks silently never completed | Advise | Component |
| C7 | Hardware request and stock reality check, offering the approved alternative | Auto | Design |
| C8 | Catalogue hygiene analysis — unused items, always-amended items, requests filed outside the catalogue | Advise | Component |
| C9 | Recurring manual request detected and the catalogue item and workflow proposed | Advise | Component |
| C10 | Recertification packs per manager with usage evidence rather than a bare entitlement list | Approve | Design |
Domain D · 10 outcomes
Change, release and advisory board
| Outcome | Gate | Status | |
|---|---|---|---|
| D1 | Change record quality review — real implementation plan, test evidence, rollback plan, correct asset scope | Approve | Component |
| D2 | Collision and blackout detection on asset, dependency, window, freeze and business calendar | Advise | Component |
| D3 | Risk scoring from what actually failed before on this asset, team and change type | Advise | Component |
| D4 | Board pack with each change summarised, risks named and unanswered questions listed | Approve | Component |
| D5 | Post-implementation review from monitoring and incident data rather than the implementer's assertion | Approve | Live |
| D6 | Change-to-incident causation linking, quantifying change-induced volume by team | Advise | Live |
| D7 | Unauthorised change detection — discovered drift against approved changes | Advise | Component |
| D8 | Standard-change candidate identification with the template drafted | Advise | Component |
| D9 | Emergency-change justification audit, reporting teams routinely bypassing the board | Advise | Component |
| D10 | Release readiness evidence assembly, blocking the gate when the evidence is absent | Approve | Live |
Domain E · 8 outcomes
Problem management and root cause
| Outcome | Gate | Status | |
|---|---|---|---|
| E1 | Problem candidate detection from incident clusters, with the problem's cost quantified | Advise | Live |
| E2 | Investigation file assembly — every related incident, change, alert and log excerpt, structured | Advise | Live |
| E3 | Workaround coverage check, closing the gap where agents are not applying an existing one | Approve | Component |
| E4 | Ageing and ownership pressure, ranked by ongoing incident cost | Advise | Component |
| E5 | Major incident timeline reconstruction from ticket, chat, alert and change records | Advise | Component |
| E6 | Remediation action tracking until actually done and evidenced | Advise | Component |
| E7 | Recurrence detection after closure, reopening with the comparison attached | Advise | Component |
| E8 | Chronic-asset reporting by total incident cost, for the remediate-or-replace decision | Advise | Component |
Domain F · 10 outcomes
Configuration, discovery and asset
| Outcome | Gate | Status | |
|---|---|---|---|
| F1 | Discovery-to-record reconciliation, each difference classified as stale, missing or a discovery gap | Approve | Live |
| F2 | Orphan and duplicate resolution to a single governed record with merge evidence retained | Approve | Live |
| F3 | Service map completeness testing against observed traffic and incident co-occurrence | Advise | Component |
| F4 | Ownership inference from change, incident and access history where the field is wrong | Approve | Component |
| F5 | Installation to entitlement reconciliation, exposing over-deployment and shelfware | Advise | Component |
| F6 | Lifecycle and refresh planning against end-of-life and warranty exposure | Advise | Component |
| F7 | Cloud resource mapping and cost attribution, reclaiming orphans | Advise | Component |
| F8 | End-of-support exposure by asset, ranked by service criticality | Advise | Component |
| F9 | Certificate and key expiry control, raising renewal work before the outage | Auto | Live |
| F10 | Health scoring on completeness, accuracy and freshness per class, reporting the trend | Advise | Live |
Domain G · 8 outcomes
Knowledge management
| Outcome | Gate | Status | |
|---|---|---|---|
| G1 | Gap detection from ticket volume, with the missing article drafted | Approve | Component |
| G2 | Stale and contradictory article detection against recent resolutions and decommissioned systems | Advise | Component |
| G3 | Accuracy testing — what articles instruct against what engineers actually did | Advise | Component |
| G4 | Duplicate consolidation into one canonical version with redirects preserved | Approve | Component |
| G5 | Article surfacing inside the ticket with the matching passage highlighted | Auto | Live |
| G6 | Runbook extraction from chat and notes into a reviewable artefact | Approve | Component |
| G7 | Multi-language variants maintained from the approved source article | Approve | Component |
| G8 | Review cycle enforcement with the reviewer's sign-off evidenced | Auto | Design |
Domain H · 8 outcomes
Self-service, voice and conversational
| Outcome | Gate | Status | |
|---|---|---|---|
| H1 | Deflection with an actual answer from governed knowledge and live system state | Auto | Component |
| H2 | Guided diagnostic before ticket creation, with results recorded on the ticket if one is still needed | Auto | Component |
| H3 | Status answering from the real downstream state, not the ticket's stage label | Auto | Live |
| H4 | Permitted self-service actions with identity verification and full logging | Auto | Component |
| H5 | Handover to a human with transcript, attempted steps and system state summarised | Auto | Live |
| H6 | Voice intake over telephony with structured capture and a sub-second response target | Auto | Live |
| H7 | Proactive notification of a known degradation, sized from the service map, ahead of the call volume | Approve | Component |
| H8 | Frustration detection in-conversation, routing to a human before the complaint becomes formal | Auto | Component |
Domain I · 8 outcomes
Service level, reporting and audit
| Outcome | Gate | Status | |
|---|---|---|---|
| I1 | Breach prediction with intervention on the reason, not a report after the fact | Approve | Live |
| I2 | Service review pack with movement explained and likely questions pre-answered | Approve | Live |
| I3 | Service credit calculation from governed data, evidenced for both parties | Approve | Component |
| I4 | Reporting integrity audit — clock states, reclassifications, backdating, bulk closures | Advise | Component |
| I5 | Cost-to-serve attribution by service, queue and client | Advise | Component |
| I6 | Shift handover briefing with live risks, ageing tickets and open majors | Auto | Component |
| I7 | Capacity forecast by queue, skill and shift | Advise | Component |
| I8 | Control evidence in the reviewer's own template, sealed and attributable per action | Auto | Component |
Domain J · 8 outcomes
Security operations
| Outcome | Gate | Status | |
|---|---|---|---|
| J1 | Security incident enrichment and triage with asset, identity, exposure and prior-case context | Approve | Component |
| J2 | Vulnerability prioritisation by exploitability, exposure and service criticality | Advise | Component |
| J3 | Remediation task creation and ownership routing with the right team and window | Approve | Component |
| J4 | Phishing report triage, clustering the campaign and closing the benign with reasons | Approve | Component |
| J5 | Insider-risk signal correlation into a reviewable case rather than isolated alerts | Advise | Live |
| J6 | Certification exception handling with the revoke-or-retain recommendation prepared | Approve | Design |
| J7 | Continuous control evidence collection as it happens rather than at audit time | Auto | Live |
| J8 | Third-party risk review file assembled from questionnaires, contracts and incident history | Advise | Component |
Domain K · 8 outcomes
Employee service delivery
| Outcome | Gate | Status | |
|---|---|---|---|
| K1 | Policy answering from approved sources only, with the clause cited and a refusal where nothing covers it | Auto | Component |
| K2 | Onboarding completeness reconciled across functions, surfacing what silently did not happen | Advise | Component |
| K3 | Offboarding access and asset assurance — actually revoked and actually returned, with evidence | Approve | Component |
| K4 | Document request handling from governed employment data, for approval and release | Approve | Component |
| K5 | Case routing with sensitivity handling and restricted visibility enforced at the data layer | Auto | Component |
| K6 | Work-pass and right-to-work expiry control, driving renewal before the breach | Auto | Component |
| K7 | Payroll input query reconciliation against time, leave and pay records | Approve | Design |
| K8 | Case pattern reporting by unit, de-identified where required | Advise | Component |
Domain L · 6 outcomes
Customer and field service
| Outcome | Gate | Status | |
|---|---|---|---|
| L1 | Case triage with entitlement and severity verification before a support engineer is consumed | Auto | Component |
| L2 | Case-to-defect linking with customer impact quantified per defect | Advise | Component |
| L3 | Dispatch with skill, parts and geography matching, re-planned on the day's actuals | Approve | Component |
| L4 | First-time-fix failure analysis — wrong part, wrong diagnosis, wrong skill — each cause quantified | Advise | Component |
| L5 | Field evidence capture and work verification, offline-first, sync resuming where it dropped | Auto | Live |
| L6 | Warranty and contract reconciliation against work performed, stopping absorbed service cost | Advise | Component |
Beyond the desk
Platform operations: thirty-four agents in five groups.
The same machinery runs the platform itself — provisioning, monitoring, cost, defensive security and audit.
Provisioning and configuration management
Failure classification, corrective commands and rerun from the failed step — with fixed, not-fixed or escalated stated every time.
Monitoring, observability and incident response
Correlation across alarms, application errors and logs, so one failure pages once.
Cost, capacity and governance
Spend deviations traced to the account, service and recent change responsible.
Cybersecurity, defensive only
Posture assessment, vulnerability re-ranking by actual exposure, and security operations that run with no telemetry leaving the network.
Audit and compliance reporting
Readable reports in the reviewer's own template, saved as re-runnable scenarios.
The fast-build library
A hundred and fourteen agents across eleven domains.
Reusable agent patterns beyond service management, assembled on the same governed foundation and adapted to each estate.
Pick three outcomes
Tell us which rows of the catalogue hurt most. We will tell you honestly which are live, which are a scoped build, and what each would take on your estate.
Talk to us