The business problem
A small IT team supported a large, distributed workforce. Much of each ticket was repeated groundwork: searching past tickets, checking the asset record, finding the right knowledge article, running the same diagnostics, and drafting a reply. That groundwork consumed time that should have gone to solving the actual problem.
The goal was to remove that friction while keeping humans responsible for decisions and changes.
A data foundation first
The first prototype was a daily export into a local database. It worked for a week, then hit three limits: it could not show what was happening right now, it could not serve an unattended process, and its flat structure could not answer questions that spanned tickets, people, and devices.
That prototype was retired and replaced with a hosted Postgres backbone with row-level security, fed by scheduled cloud jobs from ticketing, Microsoft Graph, remote support, networking, endpoint security, and patch management. The jobs are idempotent and resumable, and they respect each source’s rate limits.
An agent that reasons about the whole ticket
When a ticket arrives, a webhook triggers an agent that reads everything: the message, the email thread, the requester’s recent history, and attached screenshots. It works out what is actually being asked, including who the ticket is about when that differs from who filed it. It grounds its read in live device and network context, how similar tickets were resolved before, and the knowledge base. Then it posts a private note that leads with a recommendation, followed by the evidence and a confidence level.
Technicians can talk to it in plain language from inside the ticket. It investigates, asks clarifying questions, and carries the conversation across notes.
Safety designed in
Judgment belongs to the model, and guardrails belong to the actions. The agent can analyze and recommend anything, but it cannot change anything without a human confirmation. Ticket text is treated as data to reason about and never as instructions, and action targets come from system records, not from what a ticket says. Telemetry is trusted over claims, so when evidence contradicts a description, the agent says so. Destructive operations are refused outright, and notes are private and secret-redacted.
Controlling cost and quality
A cheap model handles the first pass, and the agent escalates to stronger models only when its own confidence is low. Token and cache usage are measured on every call, so spend and caching behavior are observed instead of assumed. Technicians can grade suggestions from inside the ticket, and a poor fix demotes the precedent it was based on so it stops influencing future answers.
The result
Routine groundwork such as searching history, enriching the ticket, and drafting a first response is done before a technician opens it. Technicians keep decision-making and approval, and the team can support growth without needing headcount to scale in proportion.