ESEN

DeskIA — AI Governance for ITSM

One-pager · for leadership and audit

AI that resolves tickets and that you can also audit, govern, and contain — running on the ITSM backend you already have.

The question your organization must be able to answer before putting AI on the help desk: "If an AI can reset passwords, grant access, and close tickets… who controls it, what is it allowed to do, and can we later prove what it did and why?"
DeskIA is designed so the answer is yes, with evidence — not with confidence.

What it is

A team of ITIL-aligned AI agents (incidents, problems, changes, requests) that operates on your own ITSM system (ManageEngine today; multi-backend architecture). Control and data stay home: DeskIA isn't a closed suite you migrate your data into. It resolves by leaning on your organization's approved knowledge base (it doesn't improvise) and serves each user in English or Spanish from start to finish.

The governance framework (not "the AI behaves" — these are controls in code)

Identity verification (C1)No account action runs without verifying identity. Credential recovery requires an out-of-band channel — never a chat self-confirmation.
Allowlist of permitted actions (C2)DeskIA only executes actions on an explicit allowlist. A plan saying "add to Domain Admins" is not authorization: it's rejected.
Untrusted input (C3)Ticket text is data to classify, never instructions to follow. Blocks prompt injection ("ignore the previous instructions…").
Tamper-evident audit chain (C5)Every action and transition emits a hash-chained event. Deleting or editing breaks the chain and is detected. No event = it didn't happen.
Budget and circuit breakers (C7/C9)A per-ticket operation limit and a breaker on repeated failures: DeskIA doesn't fire without a cap or fall into loops.
95/100 quality gate (QA)Every resolution is scored against a rubric; below 95 it doesn't close. Security hard-zeros: an account action without verification = automatic failure + integrity alert.
Personal-data redaction in the KB (C6/C8)Before writing to the knowledge base, DeskIA redacts emails, phones, IPs, and identifiers; the article is born in quarantine and nothing is published without human approval. Defense in layers, not blind trust.
Verified backup of the auditThe event chain (C5) is backed up every night with a verified backup that tests its integrity before trusting it. The evidence survives the loss of the host.

Threat model T1-T8 mapped to OWASP Agentic Security (ASI) Top 10. Deterministic controls instead of "another AI watching the AI."

The board's questions, answered

What leadership / audit asksHow DeskIA addresses it
Can DeskIA make changes without authorization?No — allowlist (C2) + approval matrix in code; anything unlisted goes to a human.
Can we prove what it did and when?Yes — hash-chained immutable audit chain (C5), verified every night.
Where does our data live?In your ITSM backend. DeskIA operates on it; it doesn't migrate or lock the data in.
What if an account is compromised?Recovery requires out-of-band verification; DeskIA never hands over credentials through the same channel in dispute.
Who handles a security incident?Routed to a human security queue; DeskIA doesn't "restore" over a possible attack (containment first).
Can DeskIA spend without control?No — per-ticket operation and cost cap, measured and visible in the executive dashboard.
What about the personal data in tickets?Redacted before it reaches the knowledge base (C6) and a human approves each article (C8). Names are reviewed by that person — the control isn't delegated to a regex.
Does the endpoint diagnostic install an agent that watches?No — it's read-only, on-demand, and with consent; distributed signed and run under AllSigned (a spoofed executable blocks itself). It reads machine state, not user files; the output comes in as untrusted data (C3) and stays audited (C5).
What if we lose the server with the evidence?Verified nightly backup of the audit chain: integrity and chaining are tested on the copy. The evidence is recoverable.

DeskIA vs. closed suites (by category)

Decision axisDeskIAClosed suites
Where does the data live?In your ITSM backend In the vendor's cloud (migrates)
Who controls the audit?Your own chain, immutable and backed up Whatever the vendor shows
Exit / lock-inYou leave; your system stays intact Exit migration
Personal data in the KBRedacted + human approval Depends on the platform
The logic that decidesOpen specs, editable Proprietary, black box

Comparison by category. Verify each vendor's specs before quoting them by name; every DeskIA ✓ is backed by its real artifact.

ITIL 5 alignment (AI-native)

DeskIA maps to ITIL 5's 6C capability model and stands as an AI Governance artifact you can present to audit:

ClarificationCognitionCreationCurationCommunicationCoordination

Design principles

· Deterministic controls > model judgment on what's critical.
· Least privilege: credentials separated by function.
· Containment before restoration in security.
· The human decides the irreversible; the AI does the routine and auditable.

Evaluating AI for your help desk this year?
30-min ITIL diagnostic: where AI saves you, where it puts you at risk, and how to govern it.
Book a diagnostic →