Function cockpit
Information Technology
Agents resolve, provision and remediate. Humans hold cyber and change authority.
Phase: Phase 4 — Governed autonomy
Run service, identity and infrastructure as a self-healing estate: classification, routine resolution, approved provisioning, telemetry correlation and patch staging are agent work; privileged access, architecture and major incident command remain human.
Trust score
0
Touchless
0%
Human review
0%
Override rate
0%
Capacity released
30-50% reduction in routine service effort, with sustained human investment in architecture and cyber
Accountable human
Chief Information Officer
CoS agent: IT Chief of Staff
Autonomy, trust, and throughput at a glance
Health
Is this function holding
Four readings with a printed rule behind each, then the outcome measures the function is judged on. A reading without a rule is decoration.
Autonomy against target
76%
9 points short of the 85% target
Trust score
89
at or above the 85 floor for a rung promotion
Touchless rate
79%
21% of items still take a person somewhere in the run
Override rate
5%
people are agreeing with the agents on the overwhelming majority of calls
Autonomous resolution
+1974%
Tickets closed without human handling
Mean time to recover
-64%18min
Severity two and three incidents
Privileged actions
-3146/wk
All human-authorized and time-bounded
Change failure rate
-1.92.8%
Changes requiring rollback
Unresolved high alerts
-114open
High-severity security alerts past SLA
Operations
What the function is running
The roster and where it sits on the ladder, the split between what runs alone and what a person still signs, and a slice of the floor as it stands.
Where this roster sits on the autonomy ladder
A0 assisted through A4 autonomous. Moving an agent up a rung is a governance decision, not a config change.
Agents
10
Active now
10
Tasks / 24h
17,940
Mean success
94%
Work mix, as it stands
How the function's volume divides between the agents and the people.
Runs end to end without a person
79%
cleared inside the ceiling, no queue, no signature
A person reads it before it clears
16%
evidence posted, a named reviewer signs
A person reverses the agent
5%
the agent proposed, the human decided otherwise
Capacity released
30-50% reduction in routine service effort, with sustained human investment in architecture and cyber
What runs without a person
Committed to autonomy inside a defined ceiling.
- Ticket classification, routing and routine resolution
- Password, cache and known-error remediation
- Approved software provisioning within role rules
- Telemetry correlation and incident enrichment
- Standard patch evaluation, staging and documentation
What stays with people
Judgment, accountability, and anything a regulator would ask a human about.
- Privileged access grants and role design
- Architecture and platform standards
- Major incident command and communications
- Destructive remediation and material production change
- Cyber-risk acceptance and disclosure
On the floor right now
A slice of live work. The full board carries every item.
- IT-6621Awaiting human
Emergency patch — exploited edge vulnerability
Change · Change board · 41m old · 46 assets
- IT-6622Escalated
Containment — impossible-travel authentication
Triage · Security operations · 22m old · 1 identity
- IT-6623Complete
Certificate expiry remediation — field endpoints
Resolve · IT CoS · 2h 58m old · 214 devices
- IT-6624Autonomous
Access provisioning — September joiner cohort
Resolve · IT CoS · 34m old · 42 identities
- IT-6625Awaiting human
Privileged entitlement — migration window
Change · Identity governance · 1h 36m old · 1 grant
- IT-6626Drafted
Capacity forecast — storage exhaustion risk
Assure · Platform owner · 5h 20m old · $84K/yr
Actions
What this function is asking a person to do
Ordered by size. Each figure is a live count from this function's own work and governance records, not a target.
3
Items awaiting a person
queued against a named human, clock running
2
Governance decisions pending
an agent stopped at a gate and asked
0
Items older than 48 hours
on the floor long enough to be a problem
0
Agents below 80 confidence
running, but not at a level that supports a promotion
Brakes available right now
What a named human can pull today to stop this function, without waiting for an engineer.
- Credential abuse or impossible-travel authentication
- Lateral movement pattern across segments
- Abnormal command sequence issued by an agent
- Monitoring blindness or telemetry gap
- Failed rollback during an agent-prepared change
Live observability
What has actually been decided, and where each agent stops
A dashboard that shows only outcomes hides the decisions that produced them. This is the governance record as written, and the ceiling every agent is held to.
Governance record
Most recent first. Each entry names the actor and the call.
Impossible-travel authentication contained
ContainedCyber Triage Agent detected authentication from two continents within nine minutes, suspended the session, forced re-authentication and escalated to security operations with a full indicator pack.
escalation · Cyber Triage Agent · materiality high
Emergency patch window requested
PendingPatch Agent scored an actively exploited vulnerability against 46 exposed assets and prepared an out-of-cycle change with tested rollback.
approval · Change board · materiality high
Privileged access request pending
PendingA temporary database administrator entitlement was requested for a migration window. Identity Agent assembled justification, duration and monitoring plan for identity governance.
approval · Identity governance · materiality high
Known-error remediation applied at scale
Auto-executedIncident Agent applied an approved runbook to 214 endpoints affected by a certificate expiry, restoring service without human handling.
notify · Incident Agent · materiality low
Escalation ceilings
Past the line the agent stops and hands the decision to the named human with the evidence attached.
- A4
IT Chief of Staff
Ceiling: Coordination only — no privileged or change authority
Then: Any severity-one incident or contested change escalates immediately to human incident command.
- A3
Service Desk Agent
Ceiling: Published catalog items only; no privileged operations
Then: Unresolved after two attempts or any user dissatisfaction routes to a human technician.
- A3
Identity Agent
Ceiling: Standard role grants only; privileged access always requires human approval
Then: Any request outside the role catalog or any standing-access request routes to identity governance.
- A3
Incident Agent
Ceiling: Known-error runbooks only; no destructive commands
Then: Novel signatures and severity-one events move immediately to human incident command.
- A3
Problem Agent
Ceiling: Analysis and proposal only
Then: Structural fixes requiring architecture change route to the platform owner.
Is policy and strategy coming to fruition
Does the intent above this function reach the work inside it
Counted per sub-function, where each step only counts if the step before it did. A policy that never reaches a running workflow has not landed, however well it reads.
Chain from stance to transaction
2 of 11 sub-functions carry a ratified position, an active policy and a live workflow
Ratified position
2
of 11 sub-functions — a stance the leadership signed, not a draft
...and an active policy
2
a rule in force, with a version and an approver
...reaching a live workflow
2
the rule reaches something that actually runs
...and landing in a GBS tower
2
the run is executed on the shared transaction spine
9 of the 11 sub-functions are executing at volume without the full chain behind them. They run to a general standard rather than to a rule with a version and an approver, and the gap first appears at the position step.
What this page is, and what it is not
Every reading here is computed live from this function's own records, which makes it exact and makes it narrow. Volumes, unit costs, autonomy and trust are modeled: none has been reconciled against an enterprise resource planning system, a service management tool or a payroll register. Read the outcome measures as the shape of the argument, not as an audited result.
McKinsey describes a movement toward agent-managed observability, networks and hosting, termed "ZeroOps" as a direction rather than a proven universal endpoint. Accenture's Advanced Technology Agent supported more than 100 active agents by mid-2025 and reduced VPN configuration time from 30 minutes to two minutes; its broader internal deployment reported 60% higher efficiency in processes using more than 450 agents.