Every AI action, verifiable

The AI help desk your auditor will want too.

DeskIA resolves your IT support tickets —your help desk— with AI, and leaves auditable proof of every action. It runs on the ticketing system you already have: you migrate nothing, you stop no service.

Auditable AI for IT support · Aligned with ITIL 4/5 · Runs on your own system · Serves in English and Spanish

FA
DeskIA is a startup specialized in AITSM — AI-powered ITSM — founded and built by Francisco Aponte, IT Operations & ITIL consultant. We share openly how we built it: the design decisions, what worked, and also the security findings we hit along the way. Transparency, not promises.
Follow on LinkedIn →
The problem

Speed or control. Almost everyone makes you choose.

An AI on the help desk promises to close tickets in seconds. But if that AI resets passwords, grants access, and closes cases, the CIO's question isn't "how fast?" — it's "who controls it, and can I prove what it did?" That's why DeskIA was designed to answer that question from day one.

The promise

Auto-resolution, lower MTTR, smaller queue. Real, and valuable.

🕳️

The hidden cost

An AI that acts without an auditable trail, on someone else's cloud, with your data locked in. On audit day, you have confidence — not evidence.

How it works

An ITIL-aligned AI team, with quality control that doesn't blink.

Every ticket runs through a flow of specialized agents and a quality control that blocks the close if it doesn't reach 95/100. Routine work resolves itself; anything irreversible is decided by a human.

1

Triage

Classifies the ticket and detects security signals before acting.

2

ITIL decision

One agent per process (incident, problem, change, request) assesses and plans.

3

Execution

Resolves within an allowlist of permitted actions, with identity verification.

4

QA + audit

95/100 gate. Every action lands in a tamper-evident event chain.

DeskIA leans on your organization's approved knowledge base to resolve — it doesn't improvise — and serves each user in their language (English or Spanish) from start to finish.

Diagnostics

Diagnoses on facts — installs nothing new, touches nothing.

A user says "it's slow" or "I have no internet" — and it's almost never precise. DeskIA reasons over the machine's real state (disk, network, services, power, events) with a read-only, signed, on-demand diagnostic: the user runs a shortcut your organization already deployed, sees on screen what it collects, and attaches the result. With facts, DeskIA resolves or guides with concrete steps, not generic ones.

🔒

Read-only and signed

It only reads state: it doesn't touch the registry, services, or your files. It's distributed signed by your organization and runs under AllSigned policy — a spoofed executable blocks itself. Nothing that "arrives by email": it's an already-installed tool.

🎯

On demand, with consent

It's not a heavy agent spying on the machine all day. The telemetry is triggered by the incident, the user sees what's collected and runs it themselves. No silent collection.

🧾

Audited like everything else

The result comes in as untrusted data (never as instructions), sensitive fields are redacted before storing, and every diagnostic lands in the audit chain.

In short: DeskIA diagnoses from the machine's real data, installing no surveillance and touching nothing — more precision, less back-and-forth with the user.

Today it covers Windows (desktop and laptop), deployed through your managed channel — Intune, GPO, SCCM, or MDM.

The differentiator

The board's questions, answered.

DeskIA doesn't ask you to trust that the AI "behaves." It puts deterministic controls in code and leaves you the evidence.

Can DeskIA make changes without authorization?No — allowlist of permitted actions + approval matrix in code.
Who approves each access request?DeskIA routes to the manager only what's within their authority; sensitive requests (data owner) never reach the wrong person — it respects your separation of duties.
Can we prove what DeskIA did and when?Yes — immutable audit chain, verified every night.
What if an account is compromised?DeskIA requires out-of-band verification on recovery; it never hands over credentials through the channel in dispute.
Who handles a security incident?DeskIA routes it to a human queue; it contains, it doesn't "restore" over a possible attack.
What if a service goes down and everyone reports at once?DeskIA doesn't open hundreds of duplicates: it reports status and ETA, with an exit for the user whose case really is different.
What about the personal data that shows up in a ticket?Before writing to the knowledge base, DeskIA redacts emails, phone numbers, IPs, and identifiers — and nothing is published without a person approving it.
Does DeskIA install an agent that watches the machines?No — the diagnostic is read-only, on-demand, and with the user's consent; it's distributed signed and runs under AllSigned. It reads machine state, not your files.
What if the server holding the evidence is lost?The audit chain is backed up every night with a verified backup: we test its integrity, we don't assume it.

In short: you can prove to an auditor exactly what the AI did, when, and with what permission — not "we trust it behaves," but evidence.

Full governance framework (controls + threat model + audit chain) in the one-pager.

Your backend, your control

It runs on your system. Not ours.

DeskIA operates on your ITSM instance (designed for ManageEngine, ServiceNow, Jira, and others). That means:

  • Your data stays home — no migrating your help desk to anyone's cloud.
  • You can audit every action on your own infrastructure.
  • If one day you don't want us, your system stays intact. No exit migration.
DeskIA vs. closed suites

What the big players promise — without handing over control.

The market consolidated into closed suites. Compared by category, these are the axes where a closed suite is structurally weak — and DeskIA is designed the other way around.

Decision axisDeskIAClosed suites
Where does your data live?In your ITSM backend In the vendor's cloud — your data migrates
Who controls the audit?Your immutable chain, verified and backed up Whatever the vendor decides to show you
The day you want outYou leave; your system stays intact Exit migration, pricier every month
Personal data in the knowledge baseRedacted + human approval before publishing Depends on the platform — not always visible
The logic that decidesOpen specs, editable by you Proprietary, black box

Comparison by category. Each vendor's specs change: verify before quoting any of them by name. Every DeskIA ✓ is backed by its real artifact (governance one-pager, audit chain) — we don't claim what we can't prove.

What if we just build it ourselves?

You can. The question is what happens in year two.

Your team can stand up a bot that closes tickets. Almost every help desk with an in-house bot tells the same story: built a couple of years ago, its auto-resolution rate plateaued at a low number, and stalled there. It doesn't improve, no one remembers how to edit it safely, and on audit day there's no trace of what it did or why.

🔓

Hidden security debt

Identity verification, prompt injection, compromised-account recovery, separation of duties on approvals — failure modes you only find in production, usually once they're already an incident. We already hit them and closed them.

🧊

An AI that calcifies

With no loop measuring it, a bot doesn't mature over time — it ages. Knowledge gets written by hand and auto-resolution plateaus.

🔍

Zero evidence

"We trust it behaves" doesn't work for your CISO. With no audit chain, you can't prove what each action touched.

DeskIA isn't the shortcut to building it — it's the cost of building it right, already paid: open specs your team can read and edit, controls in code, and audit from day one. If you ever decide to bring it in-house, you take a system you understand, not a black box.

Business value

Less support cost. More of your people's time for what matters.

When the repetitive resolves itself, two things move at once: the cost of running the help desk drops, and the whole organization's productivity rises. These are the levers — quantified with your data in the pilot.

💸

Cut the cost per ticket

Repetitive tickets (resets, access, installs) resolve without touching an L1 agent. You pay for the complex, not the routine.

🚀

Free up your IT team

Your technicians stop fighting the same fires and go back to projects: migrations, improvements, root-cause problems. Less turnover, more impact.

⏱️

Give hours back to every employee

Resolution in minutes, not hours. Every user back to work sooner is productivity not lost waiting on support.

And there's a lever we're turning on in the pilot: when a ticket doesn't ask IT to do something but to explain how to do it —convert a Word to PDF, set up a signature, schedule in Teams— DeskIA starts delivering the steps instantly, instead of sending you to wait for a person. Always with an exit at hand ("still not working" or "get me a human"), and with a gate in code that reserves for humans anything involving access, security controls, or cost. Every how-to resolved and confirmed seeds a draft for your knowledge base, with human approval before publishing.

DeskIA measures the real cost per ticket and the resolution time (MTTR) in your own operation — savings and productivity are reported with your numbers, not promises.

Design goals — validated in pilot

Honesty as the argument: these are the targets, not invented results.

DeskIA instruments its own operation and every number comes from an event (never an estimate). Below are the MVP targets; the real results are published with each pilot, with their source.

<95 min
Target resolution time
>60%
Target auto-resolution
95/100
Quality gate
10/10
Active controls

Rather see real numbers before believing? Fair. Let's talk in the diagnostic...

Demo

Prefer to see it running?

I'll show you DeskIA live on a test environment: a ticket comes in, gets resolved, and the audit chain logs every step. 30-45 minutes, no slides.

Schedule a demo →

Does your help desk look like the "before" in this story?

A 30-minute ITIL diagnostic: I'll tell you where AI saves you, where it puts you at risk, and how to govern it on your own system. No commitment.

Book a diagnostic