Tickets in.
Resolutions out.
An agentic AIOps layer on Amazon Bedrock that classifies, resolves, and closes the majority of L1 service-desk tickets directly in your existing ITSM platform — with every Active Directory, firewall, or bulk-impact action gated behind a human decision.
- 78% at month 6
- Auto-resolution rate, rising monthly
- 3-tier autonomy
- Never a single AI-does-IT switch
- Zero domain-admin
- Scoped service account only
Ticket feed
● Example- Auto-resolved
Password reset — user locked out
TCK-88412 · T1 - Auto-resolved
VPN access request — new hire
TCK-88417 · T2 - Approval gate
Bulk mailbox permission change — Finance
TCK-88423 · T3 - Tier 3 bulk-impact and domain changes always pause at a Systems Manager approval gate.
- Auto-resolved
Software install request — Slack
TCK-88429 · T2
Password resets, access requests, software installs — the same tickets, every day, while your team's actual expertise sits in a backlog. The obvious fix is automation. The trouble is most "IT chatbots" either can't really do anything beyond triage, or they execute changes through a shared admin account with no rollback — which is a bigger risk than the ticket backlog.
OpsIQ resolves the routine tickets end-to-end, and treats anything touching identity, network, or bulk scope as a decision for a human — every time, by design.
One layer between your tickets and your systems
OpsIQ works inside ServiceNow or Freshservice and uses a scoped, auditable path for Active Directory and network actions.
Employees & Tickets
Where requests start
- ServiceNow portal
- Freshservice
- Email / chat
Submitted
Algorims OpsIQ
Amazon Bedrock · AWS Systems Manager
- Classify
- Retrieve playbook
- Execute runbook
or Routed to
Reviewer
ITSM, AD & Systems
Where the fix lands
- Ticket write-back
- Active Directory
- Firewall / network
Tier 1/2 can resolve automatically. Tier 3 waits for human approval. Every action is scoped, logged, and reversible.
Your L1 desk is stuck between two bad options.
- L1 desks burn expert time on repetitive password-reset, access-request, and install tickets.
- Most AIOps tools ask for more access than they should — a shared admin login becomes the biggest single point of failure in the environment.
- Without a scoped, auditable execution path, automation itself becomes the risk.
Most tickets resolve in minutes. The moment a change touches identity, network, or more than one user, OpsIQ deliberately slows down.
Ticket lands in your ITSM
OpsIQ works inside ServiceNow or Freshservice — no new system for your team to learn.
Classification against your playbooks
Output is validated against retrieved playbook content before any action fires.
Tier 1/2 resolve automatically
Routine, low-risk categories close end-to-end, logged to an immutable audit trail.
Tier 3 pauses for a human
Active Directory, firewall, and bulk-impact actions always wait for a person — run under a service account scoped to specific cmdlets, never domain-admin.
Automatic rollback
Multi-step runbooks roll back automatically if a later step fails.
Classify what's being asked. Execute what's safe to execute. Escalate what needs a person. Control what's logged and where data lives.
Amazon Bedrock
Ticket classification and playbook-grounded reasoning.
Scoped service account
Active Directory actions run least-privilege, federated via SAML — never domain-admin.
Immutable audit log
Every automation run records inputs, outputs, and status.
Does OpsIQ ever get domain-admin access?
No. Active Directory operations run under a service account scoped to specific cmdlets — least privilege at the command level, federated via SAML.
What happens if a runbook fails partway through?
Multi-step runbooks roll back automatically, and every run is recorded to an immutable audit log.
Where does this data come from?
A live 6-month deployment at a 200-employee IT & BPO firm, measured — not modeled.
Where it fits
The economics, from a live service desk
Measured over six months at a 200-employee IT and BPO firm. The IT manager signs off each ticket category's automation tier before go-live.
Scoped execution
AWS Systems Manager runs remediation with rollback. Active Directory uses a service account limited to specific cmdlets, federated via SAML; no domain-admin login is shared.
Grounded and private
Classification is checked against retrieved playbooks before execution. Bedrock Guardrails redact PII before logging, and VPC PrivateLink keeps traffic off the public internet.
Deployment commitments
- The reference deployment scored 47 ticket categories; its top 10 categories covered 82% of volume.
- Tier 1 is autonomous and reversible, Tier 2 notifies the IT lead, and Tier 3 pauses for approval. The IT manager signs off the tiering category by category.
- Every run's inputs, outputs, and status go to an immutable DynamoDB and CloudTrail log. Monthly ticket reviews, including all low-confidence tickets, drive tuning.
Built region first, market by market
Singapore / SEA
Portfolio-consistent beachhead. Dense mid-market IT and regional shared-services-desk buyers, English-first sales motion.
- AWS region
- ap-southeast-1
- Compliance
- PDPA (SG, MY)
- Currency
- SGD
ANZ
Highest labor cost in APJ for L1 support headcount — the biggest per-FTE savings story — with strong AWS and ServiceNow penetration.
- AWS region
- ap-southeast-2
- Compliance
- Privacy Act 1988 / APPs
- Currency
- AUD
India
Reference market — the anchor case is India-native. Dense IT/BPO/GBS service-desk supply and a strong cost-out culture.
- AWS region
- ap-south-1
- Compliance
- DPDP Act 2023
- Currency
- INR / USD
Measured results
| Metric | Manual L1 desk | OpsIQ | Delta |
|---|---|---|---|
| Monthly run-rate | SGD $11,825 | SGD $1,790 | −85% |
| Auto-resolution | 0% | 78% at month 6 | ↑ from 71% |
| Classification accuracy | — | 91% after tuning | ↑ from 86% |
| Tier-3 false positives | — | 1.8% at month 6 | ↓ from 12% |
Reference deployment: IT & BPO firm, 200 employees, India, ap-south-1, 6 months live. Measured in INR (₹7,45,000 → ₹1,12,650/month) and converted at an indicative SGD→INR rate of ~63. Submitted as an AWS AI Competency case study — reproduced as submitted, not a projection.
The architecture
A defined path from intake to decision
- 01
Classify
- 02
Retrieve playbook
- 03
Execute runbook
- 04
Validate tier gate
- 05
Close or escalate
Let AI close the routine tickets. Let your team own what's risky.
Tell us your ticket mix and which ITSM you run — we'll walk through exactly which categories would be Tier 1, 2, or 3 for your desk.