Information Technology · service-desk Service Desk
Service Desk Orchestrator
orchestrator agent in the observe layer, owned by Tomas Berger (Principal Engineer, Agent Platform). This is the whole lifecycle record: where it sits, what it holds, what it is missing, and every transition anyone has recorded against it.
The ladder
Where this agent sits, how far it is allowed to go and what the next rung would cost.
- ✓Evaluation at or above the promotion floor on a held-out set the agent has never seen
- ✓Adversarial test executed against this agent with no unmitigated high finding
- ✓Rollback rehearsed on the line, with a measured time
- ✓Blast-radius cap set for any change affecting this agent
- ✓Service level attached with a named counterparty
- ✓Independent evaluation review by someone outside the team that built the agent
- ✓Ninety days at delegated with the full override record intact
- ·Kill switch tested on this agent, with a date and a measured stop time
- ·Named owner for every exception class this agent can raise
- ·Executive sign-off recorded against the accountable function leader
Held at this stage. The service level attached to this line has no counterparty signature, so there is nothing to breach and nothing to defend.
Two priority-one exceptions in a class this agent owns within 30 days, or an evaluation score below the floor, returns it to supervised automatically and notifies the function leader.
Wired to a live threshold. It fires and moves the agent down without anyone deciding to.
Transition history
Each entry names who decided, what they held and whether a rule or a person made the call.
Evaluation on the held-out set cleared the promotion floor with the override log intact for the full supervised period.
The specification was tightened after the first evaluation failure, the golden set was extended to cover the failure class, and the rerun cleared the floor.
Evaluation record
The golden set this agent is measured against, and every run scored against it.
Cases the service desk orchestrator must get right before it is allowed to move a stage. Written against the work as the process owner specified it, not against the model output.
Refusal cases were added after the first production incident, so anything before that date was never tested for correct refusal.
- ·Fairness sample too small to detect a disparity below eight points
- ·Nothing tests what the agent does when its own confidence signal is miscalibrated
- ·No non-English inputs, although two jurisdictions in scope submit in local language
- ·No adversarial cases in this suite at all
- ·No disparate-impact pairs in this suite at all
The golden set itself
Every case, what it expects and how it last scored. A test set nobody can read is a test set nobody can challenge.
| Case | Category | Scenario | Expected | Difficulty | Last result |
|---|---|---|---|---|---|
| C-01 | happy-path | A complete, well-formed unit arrives with every reference field populated and a counterparty already on file. | Processed end to end with no human touch, inside the committed handling time, with the decision written to the evidence spine. | low | Pass |
| C-02 | happy-path | A repeat unit from a counterparty seen fourteen times this quarter, matching the established pattern exactly. | Matched to the established pattern and released, with the match basis recorded rather than assumed. | low | Pass |
| C-03 | edge | A unit arrives with a valid but unusual currency and rounding convention that appears roughly four times a quarter. | Handled correctly without special-casing, with the convention recorded on the unit so the next occurrence is not a surprise. | medium | Pass |
| C-04 | edge | Two units arrive that are near-duplicates differing only in a reference number, one of which is a legitimate second instance. | Both retained, the duplication flagged for a human rather than silently resolved, and the reasoning shown. | high | Pass |
| C-05 | regression | The exact input that caused a priority-one exception in production, retained verbatim with its original context. | The failure does not recur, and the case stays in the suite permanently even after it has passed for a year. | medium | Pass |
| C-06 | regression | An input class that a previous model version handled correctly and a later version regressed on. | Handled correctly, with the regression tracked by version so the fix is attributable to a change rather than to luck. | medium | Pass |
Every evaluation on this page ran against golden sets we wrote ourselves, on a modeled estate. A passing suite proves an agent behaves the way we specified, not that the specification is right, and no evaluation here has been reviewed by anyone outside the team that built the agent.
This agent can be tested. That is not the same as this agent being safe. The golden set holds 6 cases written by Tomas Berger, drawn from human overrides captured at the supervised stage, labeled by the process owner, and it carries the blind spots listed above. A run scoring well against it says the agent handles the situations we thought of.