A public portfolio proof of concept showing how AI can reduce friction across end-user support, deskside/EUC engineering and IT operations management—while remaining constrained by approved knowledge, permissions and human decision points.
Portfolio demonstration: this site is a deterministic simulation of AI-enabled workflows. It is not connected to a live LLM, ServiceNow, Jira, Intune, a former employer, or any production environment. All users, incidents, devices and metrics are synthetic.
AI should remove operational friction—not create another layer of complexity.
The project focuses on measurable operational outcomes: fewer avoidable tickets, faster engineer preparation, better handovers, earlier problem detection, proactive endpoint review and less administrative work during major incidents.
Approved data→Policy-constrained decision layer→Recommendation / self-service→Human escalation when required
Illustrative self-service deflection
36.6%
183 of 500 synthetic sessions
Illustrative engineer prep target
~5 min
Demo assumption · not benchmarked
Recurring issue signal
+71%
Synthetic VPN incidents vs prior month
Endpoint review candidates
12
Human review—not auto-refresh
Suggested 5-minute tour
About this project
Why it exists
To demonstrate practical AI use in IT Operations and EUC: reduce repetitive work, improve preparation and surface useful operational signals rather than adding a generic chatbot.
What production would add
Live platform integrations, identity and RBAC enforcement, audited tool permissions, approved enterprise knowledge, telemetry connectors, human approval workflows and production security controls.
End-User AI Self-Service
Approved-KB troubleshooting for actions a standard user can perform. Privileged, ambiguous, unsupported or security-sensitive requests are escalated rather than improvised.
No admin stepsKB grounded
AI Support Assistant Simulated AI
Safe demo scenarios
Normal self-service never asks for admin credentials, registry changes, elevated PowerShell, security-policy changes or recovery keys.
Knowledge grounding
Approved KB matches appear here once the user describes an issue.
Deskside / EUC Engineer Copilot
Combines the current ticket, synthetic endpoint telemetry, recent support history and approved knowledge into a concise diagnostic brief. The engineer remains accountable for technical decisions.
Read + recommendNo autonomous changes
Engineer queue AI-ready context
Ticket
User / Site
Issue
SLA
Status
AI Diagnostic Brief
Select a ticket to prepare the engineer brief.
Deskside Visit Preparation
Transforms the ticket and endpoint context into a pre-visit checklist so an engineer can arrive with likely spares, relevant history and approved first checks.
Engineer decidesSynthetic case
Selected field-support case
IncidentINC0012854
LocationSingapore · Level 18
IssueDocking station intermittently disconnects both external monitors.
DeviceDell Latitude 7450
DockDell WD22TB4
Related tickets2 in previous 60 days
Endpoint stateCompliant No active alerts
AI Visit Brief
Generate the brief before leaving the support area.
AI Operations Handover Assistant
Summarises open incidents, SLA risk, vendor dependencies, planned changes and watch items into a structured handover. Designed to reduce manual shift-report preparation.
SummariseNo ticket ownership changes
Open tickets
43
Across APAC synthetic queue
SLA risks
7
2 require attention < 60 min
Vendor dependencies
4
Awaiting external action
Changes tonight
2
One M365, one network
Operational input snapshot
Type
Reference
Current state
P1
INC004391
Intermittent iManage access affecting Hong Kong users; application team investigating.
SLA
INC004377
Executive laptop issue; 42 minutes remaining.
Vendor
INC004355
Printer fault; MPS vendor due tomorrow 09:00.
Change
CHG001281
Microsoft 365 client update 22:00–23:30 SGT.
Change
CHG001287
Tokyo switch firmware 23:00–00:30 JST.
Trend
VPN
Ticket volume 42% above 30-day baseline.
AI-Generated Handover Draft
Generate a concise shift handover from the operational snapshot.
Ticket Trend & Problem Detection
Uses synthetic incident volumes and resolution outcomes to surface recurring issues, probable knowledge gaps and candidates for human-led problem management.
Detect patternsDraft only
Tickets analysed
650
Synthetic 30-day dataset
Recurring clusters
5
2 above watch threshold
Knowledge gaps
3
Suggested for KB owner review
Improvement opportunities
48
Synthetic model flags for review
AI Findings
VPN / Remote Access incidents increased 71%
84 tickets this month vs 49 prior month. 67% of the affected synthetic endpoints share the same recent Windows update window. This is correlation—not root cause.
84 ticketsCorrelation detected
Teams microphone KB may be incomplete
31 incidents reference “microphone not detected.” Of 18 interactions using KB002, 6 still escalated. A repeated successful analyst step—confirming the Windows default input device after docking/undocking—is not explicit in the current article.
KB reviewPattern from resolutions
Printer tickets concentrated at one floor
22 printer incidents came from Singapore Level 18, compared with 4–7 on comparable floors. Recommend checking shared-device health and vendor maintenance history.
Site concentration
Human Review Workspace
AI proposes; IT owns the decision. No problem record, change, KB edit or vendor action is created automatically.
Select “Draft Problem Record” to prepare a human-reviewable draft.
EUC Device Health & Refresh Advisor
Prioritises endpoint review by combining age, warranty, support demand and health indicators. It does not automatically replace, retire or remediate devices.
600 synthetic endpointsRecommend only
Healthy
481
No immediate review
Watch
76
Monitor trend
Attention
31
Engineer review
Refresh candidates
12
Manager review
Priority device review list
Device
Site
Age
Tickets / 90d
Battery
Risk
AI Assessment
Select a device to see the evidence supporting the recommendation.
Major Incident Assistant
Maintains a clean incident timeline and drafts stakeholder communications from approved operational updates. Technical decisions and external communications remain human-controlled.
Summarise + draftHuman approval required
P1 Timeline · Synthetic Example
14:02
Monitoring alert triggered for application latency.
14:04
Service Desk receives first Hong Kong user report.
14:07
Incident declared P1; incident bridge opened.
14:11
Application and infrastructure teams engaged.
14:18
Database latency identified as common technical symptom.
14:27
Application vendor engaged.
14:36
Workaround implemented and validation starts.
14:42
Service restored; monitoring continues.
AI Communication Workspace
Generate an update or PIR structure from the approved incident timeline.
Enterprise AI Control Model
The same principle applies across every module: give AI enough access to reduce work, but not enough authority to silently expand scope or make high-impact changes.
Least privilegeHuman escalation
AI MAY
✓ Retrieve approved KB
Only content authorised for the current role.
✓ Summarise permitted data
Tickets, endpoint signals, alerts, changes and approved notes.
✓ Guide safe self-service
Standard-user actions that require no elevation.
✓ Classify and enrich
Categories, summaries, attempted steps and suggested routing.
✓ Draft operational output
Handover, problem draft, refresh recommendation, MI update.
✓ Escalate uncertainty
Low-confidence or sensitive cases go to people.
AI MAY NOT
✕ Expand its own permissions
Prompt text cannot override RBAC or policy.
✕ Retrieve secrets
No passwords, recovery keys, tokens or admin credentials.
✕ Browse unrelated records
Role, user and case boundaries remain enforced.
✕ Execute privileged change
No access, policy, endpoint, firewall or backend changes.
✕ Invent unsupported fixes
No KB match / ambiguous match → human hand-off.
✕ Make final high-impact decisions
Problem creation, device refresh, major incident comms and remediation require approval.
Decision boundary examples
Scenario
AI action
Human boundary
End user has Teams microphone issue
✓ Guide approved KB steps
Escalate if unresolved.
User asks for BitLocker recovery key
→ Create controlled hand-off
Authorised support performs identity verification and recovery process.
Recurring VPN incidents detected
→ Draft problem candidate
Problem Manager validates evidence and decides whether to open problem record.
Device scores as refresh candidate
→ Recommend review
EUC/asset owner approves refresh based on policy, budget and business need.
Major incident update ready
→ Draft stakeholder message
Incident Manager validates and sends.
How This Maps to Enterprise Platforms
The prototype is intentionally vendor-neutral. In production, these patterns would use capabilities already available across ITSM, endpoint management, monitoring and collaboration platforms.
Conceptual mapping
Platform capability mapping
Prototype capability
Typical ServiceNow mapping
Typical Jira / Atlassian mapping
Typical Microsoft / EUC mapping
End-user conversational self-service
Virtual Agent / Now Assist
Virtual Service Agent / Rovo
Copilot / Teams front-end as applicable
Approved knowledge grounding
Knowledge Management
JSM + Confluence knowledge base
SharePoint / approved enterprise knowledge
Ticket enrichment and routing
ITSM incident workflows / AI features
JSM request/issue workflows + Rovo
Graph / Power Platform integration where appropriate
Endpoint context
CMDB / Discovery / integrations
Assets / integrations
Intune / Defender / endpoint analytics
Operations handover / incident drafting
ITSM + Major Incident Management
JSM incident management
Teams / Copilot / monitoring integrations
Role and data boundaries
ACLs, roles, AI governance controls
Permissions, app/agent configuration
Entra ID, RBAC, Intune scope controls
What this prototype proves
Understanding of AI-enabled ITSM/EUC workflow design and control points.
Ability to define useful data inputs and operational outputs.
Awareness of access controls, auditability and human decision boundaries.
Focus on measurable service outcomes rather than chatbot novelty.
What it does not claim
It is not an official ServiceNow, Jira or Microsoft product.
It is not connected to a production environment.
It contains no real employer or customer data.
The current version does not call a live LLM; responses and outputs are deterministic simulations of the intended operating model.