Solutions · IT & engineering

IT is where agents start, and where every other agent depends on.

IT teams get two things from AI agents: relief for their own work, from password resets to incident triage to legacy documentation, and the integration layer that lets agents in sales, finance and operations reach the systems they need. Both have to be done with least privilege, review gates and observability, or they will not survive the first security audit.

01

Where agents pay off in IT

The service desk, the backlog and the on-call rota are all queues of repetitive, well-documented work. Queues are what agents are good at.

A typical internal IT team spends a large share of its week on tickets that follow a known path: access requests, password resets, device problems, software installs, "why can't I open this file". Engineering teams spend theirs on reading unfamiliar code, writing tests, updating documentation and responding to alerts that turn out to be the same three root causes. All of it is necessary, and most of it is where senior people least want to be.

Coding agents have changed the second half of that picture quickly. Tools that write, test and refactor code under human review are now standard in many teams, and the question has moved from "should we use them" to "how do we use them without losing control of quality, security and licensing". The same question applies to service-desk agents that reset passwords and grant access.

IT also owns something no other department does: the integration layer. Agents in finance, sales or operations need controlled access to the ERP, the CRM and the ticketing system. Building that once, as a set of governed connectors, is the difference between an agent programme and a collection of shadow-IT experiments.

  • Typical starting pointService-desk agent for access and password requests
  • Human checkpointPull-request review, change approval, incident commander
  • SystemsITSM, identity provider, Git, CI/CD, observability, wikis
  • EnablerGoverned connectors and MCP servers for the whole company
Custom AI agent development →
02

Use cases

Seven workflows, from the service desk to the integration layer.

i.

IT service-desk agent

Handles password resets, access requests, device and software issues in chat, email or the ITSM portal, executes the safe actions itself through the identity provider and device management, and creates a well-formed ticket with diagnostics for everything else. Approvals for access follow your existing rules.

ii.

AI-assisted software delivery

Coding agents such as Claude Code, GitHub Copilot, Cursor or OpenAI Codex take on implementation, refactoring and test writing inside your repositories. Every change goes through a pull request with human review, automated tests, security scanning and licence checks. We design the workflow, the gates and the team practices.

iii.

Legacy documentation and migration support

Agents read undocumented code, produce architecture summaries, data-flow descriptions and API documentation, and prepare migration plans, for example from an old framework version or a discontinued platform. Engineers verify against the running system.

iv.

Test generation and maintenance

For modules with thin coverage, agents propose unit and integration tests derived from the code and the specifications, and keep tests updated when interfaces change. Reviewers reject tests that merely encode existing bugs.

v.

Incident triage and runbook automation

When an alert fires, the agent enriches it with logs, recent deployments, similar past incidents and the relevant runbook, proposes a first hypothesis and prepares the diagnostic commands. The on-call engineer decides what to run; remediation actions beyond the runbook require approval.

vi.

Security operations support

Summarising log anomalies, triaging reported phishing emails, checking configuration drift against baselines and preparing evidence for audits. Defensive use only, with analysts making every decision that changes a control.

vii.

The integration layer for the whole company

Governed connectors, usually as Model Context Protocol servers, for your ERP, CRM, ticketing, document and identity systems: scoped permissions, logging, rate limits and test environments, so agents in other departments get access without each team building its own glue code.

03

A worked example

AI-assisted delivery with pull-request gates

The engineering workflow below is how we typically introduce coding agents into a team that ships a business application, without giving up the quality bar. It applies equally to internal tools and to customer-facing software.

  1. A ticket is refined by a developer into a task with acceptance criteria and pointers to the relevant modules. Poorly specified tasks are the main cause of poor agent output, so this step is deliberately not automated.
  2. The coding agent works in an isolated branch and environment, with read access to the repository and the documentation and no access to production credentials. It implements the change, writes or updates tests and runs the test suite locally.
  3. The agent opens a pull request with a description of what it changed and why, the test results and any assumptions it made. A summary of the diff is generated for the reviewer.
  4. Automated gates run: the full test suite, static analysis, dependency and licence checks, secret scanning and a security scan. A failing gate sends the task back to the agent with the failure output.
  5. A developer reviews the pull request as they would a colleague's: design, correctness, edge cases, readability. Review comments go back to the agent, which revises. Nothing merges without a human approval, and production deployments follow your existing change process.
  6. Metrics are collected per pull request: cycle time, review time, defects found after merge, share of agent-authored changes. The team reviews them monthly and adjusts what the agent is trusted with.
04

Guardrails for IT and engineering

  • Least privilege for every agent

    Agents get scoped, auditable credentials: read access by default, write access per action, no standing production or admin rights. Service-desk agents act through the same identity and device-management APIs your team uses, under the same policies.

  • No unreviewed changes to production

    Code merges after human review and passing gates. Infrastructure and configuration changes follow the change process. Incident remediation beyond the runbook needs the on-call engineer's approval.

  • Secrets stay out of the model

    Agents never see production secrets or customer data in plaintext. Environments are isolated, and prompts, tool results and outputs are scanned for credentials before they are logged.

  • Licence and IP checks for generated code

    Generated code passes the same dependency, licence and provenance checks as any other code, and the team agrees on how agent-authored changes are attributed and documented.

  • Observability from day one

    Every agent action is traced: inputs, tool calls, outputs, cost. That is how you debug an agent, prove what it did in an audit, and notice when a model update changes its behaviour. Read more about managed AI operations.

05

How we start

  1. Assess

    Two to three weeks: ticket categories and volumes, engineering workflow and tooling, identity and access setup, security requirements and the systems other departments' agents will need. Output: ranked use cases, a connector map and a security concept.

    Weeks 1–3
  2. Design

    Permission model, approval gates, environment isolation, logging and the evaluation approach, agreed with IT security. For delivery workflows: coding standards, review rules and the metrics to track.

    Weeks 3–4
  3. Pilot

    Six to eight weeks to a service-desk agent on selected categories, a coding-agent workflow in one team, or the first two governed connectors, in production with real users and measured against the baseline.

    Weeks 5–12
  4. Scale

    More ticket categories, more teams, more connectors, and an internal platform team that owns the integration layer. We train that team and hand over documentation and runbooks.

    From month 4
06

Frequently asked questions

Will coding agents lower our code quality?

Not if the gates are in place. Quality is decided by the review and test process, and a coding agent goes through the same one as a human contributor. Teams that skip review to move faster do see problems; teams that keep review and use the agent for the mechanical work see better coverage and documentation than before. We measure after-merge defects so you can see it for yourself.

How do we stop an agent from doing something dangerous in production?

By not giving it the means. Agents run with scoped credentials, in isolated environments, and every write action beyond a defined safe list requires human approval. Kill switches and rate limits are part of the standard setup. Our guide to guardrails for AI agents describes the layers.

Which ITSM and engineering tools do you support?

ServiceNow, Jira Service Management, Freshservice and similar for the service desk; Entra ID, Okta and device-management systems for actions; GitHub, GitLab and Azure DevOps for delivery; common observability stacks for incident triage. Anything with an API can be connected; we check the details during the assessment.

Should we build MCP servers for our internal systems?

If more than one agent or team needs the same system, yes. A governed connector built once with scoped permissions and logging is cheaper and safer than each team writing its own integration. Our article on the Model Context Protocol explains what that involves and where the risks are.

What about data protection and the works council?

Service-desk agents process employee data and must be documented under the GDPR; in Germany, systems that could monitor employee behaviour need works council involvement, and coding-agent metrics should be designed to measure the process, not the person. We handle both in the design phase with your DPO and HR.

What happens to the IT team's jobs?

The queue of routine tickets shrinks and the team spends more time on projects, security and the integration layer, which is now a core responsibility. Where a team's workload changes materially, we say so early and plan it together.

07

Related

Next step

Let's find the first workflow worth automating.

A 30-minute intro call, no slides and no obligation. We listen, ask about your processes, and tell you honestly where AI agents would pay off and where they would not.