Each agent is grounded in approved enterprise sources and produces structured outputs. Run the investigation to watch each agent move from Analyzing to Finding to Recommended Action.
Incident Resolution Agent
Standby
Triages incidents, classifies severity, correlates tickets and alerts, recommends resolution steps, and creates incident updates.
Data sources
· ServiceNow incidents
· Azure Monitor alerts
· Microsoft 365 service health
· Log Analytics
· Endpoint telemetry
· Defender alerts
· Historical incidents
Outputs
· Incident classification
· Severity recommendation
· Related incidents
· Recommended fix
· Suggested assignment group
· Executive update
Knowledge Agent
Standby
Searches approved knowledge sources, runbooks, SharePoint, Teams files, ServiceNow KB, Azure DevOps wiki, and prior incident records to provide trusted answers.
Data sources
· ServiceNow KB
· SharePoint
· Teams files
· Azure DevOps wiki
· Runbooks
· Prior incidents
Outputs
· Recommended KB article
· Confidence score
· Missing knowledge gaps
· Draft article updates
· Suggested employee self-service answers
Service Desk Agent
Standby
Handles common employee support requests, gathers diagnostics, deflects repetitive tickets, checks ticket status, creates tickets, and routes unresolved cases to the right support team.
Data sources
· ServiceNow tickets
· Teams conversations
· Endpoint diagnostics
· Employee directory
Outputs
· Ticket deflection
· Self-service instructions
· Ticket status
· Diagnostic questions
· Assignment recommendation
· Employee communication draft
Change Management Agent
Standby
Reviews planned and completed changes, identifies conflicting changes, evaluates business impact, checks historical outcomes, and generates risk assessments.
Data sources
· Change records
· CMDB
· CAB minutes
· Deployment pipelines
· Incident history
Outputs
· Change risk score
· Impacted applications
· Impacted employee groups
· Related incidents
· Rollback recommendation
· CAB summary
Root Cause Analysis Agent
Standby
Correlates tickets, logs, alerts, telemetry, configuration changes, and historical incidents to identify probable root cause and prevention actions.