OpsIQ

Tickets in.
Resolutions out.

An agentic AIOps layer on Amazon Bedrock that classifies, resolves, and closes the majority of L1 service-desk tickets directly in your existing ITSM platform — with every Active Directory, firewall, or bulk-impact action gated behind a human decision.

78% at month 6
Auto-resolution rate, rising monthly
3-tier autonomy
Never a single AI-does-IT switch
Zero domain-admin
Scoped service account only

Ticket feed

● Example
  • Password reset — user locked out

    TCK-88412 · T1
    Auto-resolved
  • VPN access request — new hire

    TCK-88417 · T2
    Auto-resolved
  • Bulk mailbox permission change — Finance

    TCK-88423 · T3
    Approval gate
  • Tier 3 bulk-impact and domain changes always pause at a Systems Manager approval gate.
  • Software install request — Slack

    TCK-88429 · T2
    Auto-resolved
−85%Monthly run-rate vs. a fully manual L1 desk
78%Auto-resolution rate at month 6 (71% at go-live)
91%Classification accuracy after tuning (from 86%)
1.8%Tier-3 false-positive escalation rate at month 6
Overview

Password resets, access requests, software installs — the same tickets, every day, while your team's actual expertise sits in a backlog. The obvious fix is automation. The trouble is most "IT chatbots" either can't really do anything beyond triage, or they execute changes through a shared admin account with no rollback — which is a bigger risk than the ticket backlog.

OpsIQ resolves the routine tickets end-to-end, and treats anything touching identity, network, or bulk scope as a decision for a human — every time, by design.

How it fits

One layer between your tickets and your systems

OpsIQ works inside ServiceNow or Freshservice and uses a scoped, auditable path for Active Directory and network actions.

Employees & Tickets

Where requests start

  • ServiceNow portal
  • Freshservice
  • Email / chat

Algorims OpsIQ

Amazon Bedrock · AWS Systems Manager

  • Classify
  • Retrieve playbook
  • Execute runbook

ITSM, AD & Systems

Where the fix lands

  • Ticket write-back
  • Active Directory
  • Firewall / network

Tier 1/2 can resolve automatically. Tier 3 waits for human approval. Every action is scoped, logged, and reversible.

The challenge

Your L1 desk is stuck between two bad options.

  • L1 desks burn expert time on repetitive password-reset, access-request, and install tickets.
  • Most AIOps tools ask for more access than they should — a shared admin login becomes the biggest single point of failure in the environment.
  • Without a scoped, auditable execution path, automation itself becomes the risk.
The solution

Most tickets resolve in minutes. The moment a change touches identity, network, or more than one user, OpsIQ deliberately slows down.

01

Ticket lands in your ITSM

OpsIQ works inside ServiceNow or Freshservice — no new system for your team to learn.

02

Classification against your playbooks

Output is validated against retrieved playbook content before any action fires.

03

Tier 1/2 resolve automatically

Routine, low-risk categories close end-to-end, logged to an immutable audit trail.

04

Tier 3 pauses for a human

Active Directory, firewall, and bulk-impact actions always wait for a person — run under a service account scoped to specific cmdlets, never domain-admin.

05

Automatic rollback

Multi-step runbooks roll back automatically if a later step fails.

AWS services in the solution

Classify what's being asked. Execute what's safe to execute. Escalate what needs a person. Control what's logged and where data lives.

Amazon Bedrock

Ticket classification and playbook-grounded reasoning.

Scoped service account

Active Directory actions run least-privilege, federated via SAML — never domain-admin.

Immutable audit log

Every automation run records inputs, outputs, and status.

Frequently asked questions
Does OpsIQ ever get domain-admin access?

No. Active Directory operations run under a service account scoped to specific cmdlets — least privilege at the command level, federated via SAML.

What happens if a runbook fails partway through?

Multi-step runbooks roll back automatically, and every run is recorded to an immutable audit log.

Where does this data come from?

A live 6-month deployment at a 200-employee IT & BPO firm, measured — not modeled.

Where it fits

The economics, from a live service desk

Measured over six months at a 200-employee IT and BPO firm. The IT manager signs off each ticket category's automation tier before go-live.

Scoped execution

AWS Systems Manager runs remediation with rollback. Active Directory uses a service account limited to specific cmdlets, federated via SAML; no domain-admin login is shared.

Grounded and private

Classification is checked against retrieved playbooks before execution. Bedrock Guardrails redact PII before logging, and VPC PrivateLink keeps traffic off the public internet.

Deployment commitments

  • The reference deployment scored 47 ticket categories; its top 10 categories covered 82% of volume.
  • Tier 1 is autonomous and reversible, Tier 2 notifies the IT lead, and Tier 3 pauses for approval. The IT manager signs off the tiering category by category.
  • Every run's inputs, outputs, and status go to an immutable DynamoDB and CloudTrail log. Monthly ticket reviews, including all low-confidence tickets, drive tuning.

Built region first, market by market

Singapore / SEA

Portfolio-consistent beachhead. Dense mid-market IT and regional shared-services-desk buyers, English-first sales motion.

AWS region
ap-southeast-1
Compliance
PDPA (SG, MY)
Currency
SGD

ANZ

Highest labor cost in APJ for L1 support headcount — the biggest per-FTE savings story — with strong AWS and ServiceNow penetration.

AWS region
ap-southeast-2
Compliance
Privacy Act 1988 / APPs
Currency
AUD

India

Reference market — the anchor case is India-native. Dense IT/BPO/GBS service-desk supply and a strong cost-out culture.

AWS region
ap-south-1
Compliance
DPDP Act 2023
Currency
INR / USD

Measured results

MetricManual L1 deskOpsIQDelta
Monthly run-rateSGD $11,825SGD $1,790−85%
Auto-resolution0%78% at month 6↑ from 71%
Classification accuracy91% after tuning↑ from 86%
Tier-3 false positives1.8% at month 6↓ from 12%

Reference deployment: IT & BPO firm, 200 employees, India, ap-south-1, 6 months live. Measured in INR (₹7,45,000 → ₹1,12,650/month) and converted at an indicative SGD→INR rate of ~63. Submitted as an AWS AI Competency case study — reproduced as submitted, not a projection.

The architecture

A defined path from intake to decision

  1. 01

    Classify

  2. 02

    Retrieve playbook

  3. 03

    Execute runbook

  4. 04

    Validate tier gate

  5. 05

    Close or escalate

Let AI close the routine tickets. Let your team own what's risky.

Tell us your ticket mix and which ITSM you run — we'll walk through exactly which categories would be Tier 1, 2, or 3 for your desk.