Function cockpit
Information Technology
Agents resolve, provision and remediate. Humans hold cyber and change authority.
Phase: Phase 4 — Governed autonomy
Run service, identity and infrastructure as a self-healing estate: classification, routine resolution, approved provisioning, telemetry correlation and patch staging are agent work; privileged access, architecture and major incident command remain human.
Trust score
0
Touchless
0%
Human review
0%
Override rate
0%
Capacity released
30-50% reduction in routine service effort, with sustained human investment in architecture and cyber
Accountable human
Chief Information Officer
CoS agent: IT Chief of Staff
Strategy, policy, observe, workflow, and AI GBS side by side
Five layers
What Information Technology actually runs
A function is not one thing. It sets direction, writes the rules it is bound by, watches the world and itself, does the work on lines, and pushes repeatable transactions into a shared spine. Agents work in all five — not just the last two.
Strategy
13 agents
Agents that take positions, argue them, and get held to the outcome.
12 positions on the record
2 ratified, 2 in challenge
Policy
10 agents
The written rules every other agent is bound by, with version and owner.
34 binding rules
29 active, 5 superseded or retired
Observe
18 agents
Continuous sensing of the outside world and of the agents themselves.
18 watchers running
They watch the outside world and the agents themselves
Workflow
32 agents
Doing the work: lines, stations, and live units moving through them.
33 lines, 204 live units
27 held for a person right now
AI GBS
17 agents
Repeatable transaction processing run once for the whole enterprise.
3 shared towers
108 stations on this function run inside AI GBS
Strategy layer — positions on the record
Every position names its author, the agent paid to argue against it, and the conditions that would break it.
Service Desk Operating Position
SupersededHold the ceiling at A4 for service desk. The single highest-volume agentic surface in IT. Classification, knowledge retrieval and self-service resolution need no human at all below the escalation line. Raise it only after two consecutive quarters where the override rate stays under five percent and every override has a written cause.
Identity & Access Operating Position
SupersededHold the ceiling at A4 for identity & access. Standard joiner and leaver flows are fully touchless and faster than any human process. Privileged and out-of-role access always requires a named approver and expires automatically. Raise it only after two consecutive quarters where the override rate stays under five percent and every override has a written cause.
End-User Compute Operating Position
RatifiedHold the ceiling at A4 for end-user compute. Imaging, enrollment and patching are deterministic and reversible. Only spend commitments and persistent non-compliance reach a person. Raise it only after two consecutive quarters where the override rate stays under five percent and every override has a written cause.
Infrastructure & Cloud Operating Position
SupersededHold the ceiling at A4 for infrastructure & cloud. Scaling, waste detection and restore verification are automated inside a spend envelope. Anything outside the envelope escalates before it costs money. Raise it only after two consecutive quarters where the override rate stays under five percent and every override has a written cause.
Network Operating Position
In challengeHold the ceiling at A3 for network. Detection and known-fault remediation run without a human. Network configuration changes carry enterprise-wide blast radius, so peer review and a change board are mandatory. Raise it only after two consecutive quarters where the override rate stays under five percent and every override has a written cause.
Application Management Operating Position
RejectedHold the ceiling at A3 for application management. Health monitoring and known-fault remediation are agentic. Removing an application from service touches business processes, so the business owner signs it. Raise it only after two consecutive quarters where the override rate stays under five percent and every override has a written cause.
Policy layer — what binds the agents
Versioned rules with an owning agent, a human approver, and the agents they constrain.
Service Desk Decision Envelope
vv5.1Agents in this lane may act without a human when the ticket sits inside the stated value, risk and confidence envelope. Outside it, the unit holds at a gate with a named approver and a running clock.
Service Desk Evidence Standard
vv4.4Every autonomous decision writes inputs, the rule version applied, the model and prompt version, the output and a reversal path. An action with no evidence record is treated as a control failure, not a fast decision.
Identity & Access Decision Envelope
vv2.2Agents in this lane may act without a human when the access request sits inside the stated value, risk and confidence envelope. Outside it, the unit holds at a gate with a named approver and a running clock.
Identity & Access Evidence Standard
vv1.6Every autonomous decision writes inputs, the rule version applied, the model and prompt version, the output and a reversal path. An action with no evidence record is treated as a control failure, not a fast decision.
Identity & Access Escalation Rule
vv3.4Escalation is mandatory when confidence falls below the floor, when two options sit inside the confidence band, or when a break condition on a ratified position fires. Director, Identity & Access Management owns the response clock.
Identity & Access Autonomy Ceiling
vv2.8The ceiling for this lane is 86 on the platform scale. Standard joiner and leaver flows are fully touchless and faster than any human process. Privileged and out-of-role access always requires a named approver and expires automatically. The ceiling is a governance decision, not a technical limit, and only Director, Identity & Access Management can propose moving it.
Workflow layer — the lines doing the work
Each line is a workflow. Each station is a stage. Each unit is a live piece of work.
| Line | Sub-function | Kind | Units / wk | Touchless | Timetable | Actual | Stations |
|---|---|---|---|---|---|---|---|
| IT1A Ticket-to-Resolution | Service Desk | transactional | 1,453 | 96% | 14.0h | 15.5h | 8 |
| IT1B Password Reset | Service Desk | transactional | 2,857 | 94% | 23.2h | 18.6h | 5 |
| IT1C Escalation Handling | Service Desk | transactional | 6,587 | 87% | 14.1h | 16.5h | 4 |
| IT2A Joiner Provisioning | Identity & Access | transactional | 3,663 | 83% | 20.3h | 24.2h | 6 |
| IT2B Leaver Deprovisioning | Identity & Access | transactional | 7,389 | 86% | 10.9h | 12.2h | 6 |
| IT2C Privileged Access Request | Identity & Access | transactional | 6,952 | 88% | 2.1h | 1.6h | 7 |
| IT3A Device Provisioning | End-User Compute | transactional | 855 | 83% | 23.3h | 24.4h | 7 |
| IT3B Patch Cycle | End-User Compute | transactional | 391 | 89% | 7.9h | 7.6h | 5 |
| IT3C Device Refresh | End-User Compute | transactional | 983 | 84% | 2.6h | 2.7h | 7 |
| IT4A Capacity Response | Infrastructure & Cloud | transactional | 800 | 81% | 22.1h | 23.3h | 5 |
| IT4B Cost Optimization | Infrastructure & Cloud | transactional | 1,227 | 86% | 7.2h | 9.0h | 6 |
| IT4C Backup Assurance | Infrastructure & Cloud | transactional | 2,803 | 89% | 23.9h | 19.6h | 5 |
| IT5A Network Incident | Network | transactional | 6,075 | 83% | 25.8h | 21.2h | 6 |
| IT5B Configuration Change | Network | transactional | 1,274 | 84% | 13.9h | 12.6h | 7 |
| IT5C Circuit Lifecycle | Network | transactional | 3,081 | 77% | 6.8h | 5.5h | 6 |
| IT6A Application Incident | Application Management | transactional | 7,208 | 78% | 4.4h | 4.2h | 7 |
| IT6B Application Release | Application Management | transactional | 6,818 | 86% | 21.2h | 24.4h | 6 |
| IT6C Application Retirement | Application Management | transactional | 4,852 | 79% | 23.0h | 29.3h | 6 |
| IT7A Security Alert Triage | Cybersecurity Operations | transactional | 3,384 | 83% | 7.0h | 7.4h | 7 |
| IT7B Phishing Campaign Response | Cybersecurity Operations | transactional | 4,964 | 87% | 11.8h | 12.0h | 6 |
| IT7C Major Incident | Cybersecurity Operations | transactional | 2,187 | 82% | 0.8h | 1.0h | 8 |
| IT8A Pipeline Incident | Data & Integration Platform | transactional | 7,590 | 80% | 15.2h | 12.4h | 6 |
| IT8B Data Product Release | Data & Integration Platform | transactional | 4,118 | 84% | 1.9h | 2.1h | 6 |
| IT8C Data Access Grant | Data & Integration Platform | transactional | 1,175 | 83% | 5.4h | 4.7h | 5 |
| IT9A License Reconciliation | Asset & License | transactional | 2,993 | 95% | 10.2h | 8.5h | 6 |
| IT9B Renewal Cycle | Asset & License | transactional | 4,304 | 92% | 6.0h | 7.2h | 5 |
| IT9C Asset Audit Response | Asset & License | transactional | 3,634 | 87% | 22.3h | 27.9h | 4 |
| IT10A Standard Change | Change & Release | transactional | 1,797 | 90% | 4.5h | 5.4h | 7 |
| IT10B Normal Change | Change & Release | transactional | 7,302 | 92% | 5.7h | 6.0h | 7 |
| IT10C Emergency Change | Change & Release | transactional | 980 | 88% | 6.4h | 5.0h | 5 |
| IT11A Monthly Showback | IT Financial Management | analytical | 56 | 71% | 96.5h | 113.5h | 5 |
| IT11B Unit Cost Read | IT Financial Management | analytical | 9 | 61% | 151.2h | 156.3h | 4 |
| IT11C Sourcing Model Position | IT Financial Management | judgment | 5 | 54% | 621.9h | 785.4h | 5 |
Observe layer — the watchers
Sensing agents and the agents that supervise other agents.
Service Desk Orchestrator
Owns the service desk lane end to end. Sequences the other agents, holds the timetable, and decides what surfaces to a human.
Service Desk Challenger Agent
Adversarial reviewer for service desk. Argues the opposite case on every position and flags where the evidence does not carry the claim.
Identity Orchestrator
Owns the identity & access lane end to end. Sequences the other agents, holds the timetable, and decides what surfaces to a human.
Identity & Access Challenger Agent
Adversarial reviewer for identity & access. Argues the opposite case on every position and flags where the evidence does not carry the claim.
End-User Compute Orchestrator
Owns the end-user compute lane end to end. Sequences the other agents, holds the timetable, and decides what surfaces to a human.
Device Health Agent
Watches end-user compute continuously. Detects drift, quantifies it, and routes what matters without waiting for a reporting cycle.
End-User Compute Challenger Agent
Adversarial reviewer for end-user compute. Argues the opposite case on every position and flags where the evidence does not carry the claim.
Infrastructure Orchestrator
Owns the infrastructure & cloud lane end to end. Sequences the other agents, holds the timetable, and decides what surfaces to a human.
AI GBS layer — the shared spine
Repeatable transaction processing does not belong to this function. It runs once for the enterprise.
Service Desk · Identity & Access · End-User Compute · Infrastructure & Cloud · Application Management · Asset & License · Change & Release · IT Financial Management
Cybersecurity Operations
Data & Integration Platform
Stations running inside AI GBS
108 of 195 stations(55% of the function's stations)
Read this page as the honest answer to “what would an 80% agentic Information Technology look like?” The strategy and policy layers are where the argument happens. The workflow and AI GBS layers are where the volume goes. The observe layer is the only reason the other four can be trusted.
Sub-function breakdown