AI for ITSM: How Agentic Orchestration Modernizes IT Service Management

Elementum Team••Industry Solutions
AI for ITSM: How Agentic Orchestration Modernizes IT Service Management

Your ServiceNow renewal now comes with AI metered in "assists," and your finance team can't forecast those charges. The board, meanwhile, wants to know when the service desk will close routine tickets without a human touching them. Two pressures. One question: what does AI for IT service management (ITSM) look like when it has to survive an internal audit and a budget review?

AI agents and service management controls start from different assumptions. An agent interprets a request and decides how to fulfill it using probabilistic reasoning, where the same input can produce different outputs. A service management control runs the same way every time and leaves evidence behind. Reconciling the two is the core design problem in AI for ITSM, and this article works through it one request type at a time.

What AI ITSM Means in Practice

Generative AI in ITSM drafts replies, summarizes incidents, and surfaces knowledge for a person to act on. Agentic AI has delegated authority to execute work across systems. Under defined controls, an agentic system carries a ticket from interpretation through validated closure.

AI in service management climbs a capability ladder from fixed automation to autonomous execution. Rules occupy the first rung and automate steps set in advance. Conversational tools come next: they gather details and pass fulfillment to a person.

Generative systems prepare replies and condense incident history, then leave execution to staff. At the agentic rung, software interprets the goal, selects tools across connected systems, carries out the work, and verifies the result.

Take a password reset or a software request. A conversational tool collects the details and hands off. An agent with the required authority performs the reset or the provisioning itself. The difference is authority.

Deployment lags the vocabulary. Only 17% of organizations have deployed AI agents so far, while more than 60% expect to within two years, according to Gartner. Many service desks will grant software execution authority for the first time in that window, and that authority is where audit questions start.

Why Autonomous Agents Alone Fail Service Management Controls

Autonomous agents fail audits on evidence. An agent that resets passwords on its own is useful until an internal auditor asks why it acted the way it did on a specific ticket. The output can vary from run to run, so reconstructing and testing why a control produced a particular result gets harder.

The same agent often holds authority to both execute and approve. Combining the two breaks segregation of duties, the control that keeps one party from executing and approving the same action. Broad permissions without an approval gate create governance risk a team could have designed out.

40% of enterprises will demote or decommission autonomous agents by 2027 because they discover missing controls only after production incidents, according to Gartner. Senior director analyst Shiva Varma traces the root cause to enterprises treating agent governance "as binary, either locked down or fully trusted."

Tickets themselves are an attack surface. In a proof-of-concept attack on Jira Service Management, researchers submitted a support ticket carrying hidden instructions. When a support engineer ran a connected AI action on the ticket, those instructions executed with the engineer's internal permissions and wrote internal data back into the ticket. An agent with execution authority and no input validation turns every inbound request into a possible command.

Where Deterministic Workflows Call AI Agents

The architecture that resolves the audit problem separates process from reasoning. A deterministic workflow decides what happens, in what order, and with which approvals. Same input, same output.

The workflow calls an AI agent only at the step that needs interpretation, passes it defined inputs, logs its outputs, and keeps a human escalation path open. Skip that separation and the agent's variability spreads across the entire process. Agents reason, engines govern, and people decide.

Consider an illustrative request. An employee types into a chat window that they need the same finance system access as a newly hired manager. Mapping that sentence to a catalog item takes reasoning, so an agent handles it. Checking the requester's role against the entitlement policy is fixed logic, so the workflow calls no model.

Standard access executes automatically. Privileged access routes to a named approver. Every step logs which agent or rule ran and what it produced, so an auditor can reproduce each non-AI step and see exactly where the AI step started and stopped.

The agent is the easy part to build. The hard part is the plumbing around it: durable workflows that retry and resume, approval chains with separation of duties, row-level access control in your own warehouse, a replayable audit trail, and safe promotion across environments. A team that builds its own service desk agents commits to maintaining all of it.

At Elementum, our Workflow Engine is built on this separation. A deterministic engine sequences AI Agents, automated logic, and human approvals in one flow, and calls an agent only where a step requires reasoning. It also runs your existing agents inside the process, and routes exceptions and approvals to the people who own them.

Configurable decision thresholds set where an agent acts alone and where a human approval checkpoint takes over. For example, a team might let an agent grant standard software licenses but send any admin-level grant to a named approver. The controls stay explicit.

Human approval on every action does not scale with ticket volume. Deterministic guardrails, the policy rules that decide what an agent may do, let routine actions run on their own. Keep checkpoints on identity, infrastructure, and change steps as volume grows, because those actions carry the highest audit and outage risk.

AI Reasoning and Deterministic Execution in ITSM Requests

The split between AI reasoning and deterministic execution pays off most where request volume is high and every action touches identity, infrastructure, or a change record. Access requests, tier-one incidents, and change drafting all fit that profile.

Access and Provisioning

Access requests split cleanly. An AI agent interprets the request, entitlement checks and standard grants run as logic, and privileged grants route to an approver. Test the handoff before you buy: ask each vendor for a live demonstration that removes a departing employee's access to identity, collaboration, productivity, and finance systems in one continuous flow.

A demonstration that pauses for repeated human intervention shows assisted handling. End-to-end deprovisioning closes the departing employee's access across every system on their last day, without waiting for each system owner to work the ticket. Access that lingers after departure is a standing audit finding.

Tier-One Incident Resolution

Tier-one incidents follow the same pattern. An AI agent classifies the incident and drafts the fix from your knowledge base. The workflow runs the remediation, validates it, and escalates with full context when validation fails. Validation closes the loop.

Routine incidents close without waiting in a queue. The ones that fail validation reach an engineer with the diagnosis already attached.

Read vendor resolution rates with care. Some headline autonomous-resolution figures count narrow tasks such as password resets alongside fully resolved incidents, so ask what the number includes before you model savings on it. Then ask a sharper question inside your own organization: if everything automatable were already automated, how many people would still staff the service desk, and what work would they be doing?

Change Drafting and Approval

Change is where the split needs the firmest line. An AI agent drafts the risk assessment and rollback plan, and the change advisory board (CAB) or a named approver authorizes the change. An agent that prepares a change should not approve it, because the approval is the independent checkpoint the auditor tests.

PeopleCert owns and certifies the Information Technology Infrastructure Library (ITIL) framework. In incident management, AI can prepare recommendations, but administrators must approve actions to prevent errors or misaligned outcomes. The drafting work shrinks, and the approval record stays intact.

AI ITSM Pricing and Forecasting Risk

Consumption-based AI pricing turns the service desk budget into a demand forecast. ServiceNow meters AI agent usage in assists and charges for them in addition to subscription fees, CIO reported. The number of assists a single agentic interaction consumes varies, so predicting the bill means predicting agent behavior.

SAP and Salesforce use similar models, according to an analyst quoted in the same report. Multiple vendors, multiple meters. Each meter moves forecasting risk from the vendor to you. Before signing, ask each vendor to model your AI cost at two or three higher ticket volumes and compare the curves.

AI Add-On Tiers and Module Replacement

Everybody is adding. Nobody is retiring. An agentic tier added to ServiceNow keeps every existing license and puts a new meter on top of it, so the estate gets bigger and nothing retires.

The alternative is to replace a specific module rather than add to it. Request intake and fulfillment is the usual first candidate, because volume, repeatability, and outsourced service desk spend are typically highest there. A full ServiceNow replacement is a bigger lift, given the configuration management database (CMDB) and the breadth of process that sits on it, so scope any replacement to the named module. Your current systems stay as sources of record while the way the work gets done changes.

Sanofi's approach shows that pattern at work. Employees bring requests to Concierge, which draws on ServiceNow data and Workday data and runs on Elementum workflows with the Claude model family.

Chief Digital Officer Emmanuel Frenehard has said he doesn't want Salesforce, ServiceNow, and SAP agents talking to each other. His aim is to run IT workflows on Sanofi's own data foundation rather than stack another vendor's agents on each system. Sanofi's approach makes the case for a ServiceNow alternative over another vendor agent tier.

How Elementum Builds AI ITSM on Your Data

Your next ITSM renewal can default you into a metered AI tier and an agent architecture your auditors find harder to test. Separate deterministic process from agent reasoning before you sign that contract, and pick one domain, one owner, and one number to prove it on.

Elementum is the Enterprise AI Apps Platform that allows you to deploy AI, deterministic workflows, and human-in-the-loop actions at scale, without moving your data off of your data cloud. For ITSM, we log every agent action and let your team revoke it, and every AI determination is logged and citable. Built-in guardrails and input validation check every model interaction for injected instructions like the ones in a poisoned ticket.

Pricing is one annual price per application, with no separate fee per seat, conversation, or AI action.

Elementum executes inside your own cloud data platform, starting with Snowflake. Databricks is a live second track, currently a minimum viable product (MVP). Under our zero persistence architecture, workflows use data in place and nothing is retained at the execution layer after the run. We never train on, replicate, or warehouse your data, and you can change the AI model, the data, the data platform, and the interface.

We build the first application with your team, and your team builds the next ones. Most customers start with IT service management, prove the result against a baseline their CFO already reports, and let that result carry the next domain. Global enterprises including Sanofi, Under Armour, and Elevance Health run on Elementum.

Contact us to map agentic AI apps into your ITSM architecture and the rest of your AI roadmap.

FAQs About AI ITSM

These are the questions IT and operations leaders most often raise when they evaluate AI for ITSM.

How can you use AI in ITSM?

You can use AI in ITSM to analyze service management data and to advise on or execute actions across incident, request, and change management. Some tools ship inside ITSM platforms as native add-ons, and others run as separate products. Agentic AI is the subset with delegated authority to carry a resolution through execution and validation.

How can your team distinguish a chatbot from an AI Agent in ITSM?

Your team can distinguish a chatbot from an AI agent by what each is allowed to do. Chatbots provide a conversational interface and, depending on their connected tools, may log a ticket or trigger a workflow. AI agents have delegated execution authority: they interpret the request, call approved systems, execute the change, and validate the result under defined controls. The test is whether the software can complete and validate the request without an engineer touching it.

Will AI replace your IT service desk?

AI will take over much of the reactive work on your IT service desk, because answering, logging, resolving, and closing routine tickets follows repeatable steps. People keep accountability. Higher-risk changes still need independent approval, and PeopleCert's ITIL discussion holds that administrators must approve AI actions in incident management. The service desk's role shifts toward owning approvals, exceptions, and knowledge, with automation freeing human judgment for the cases that need it.

How do you govern AI Agents in IT operations?

You govern AI agents in IT operations by giving every agent a named owner, a defined role, task-specific permissions, and an audit record, then running it inside a deterministic workflow with approval gates. Match the controls to each agent's autonomy level. Gartner warns that treating every agent the same way, fully locked down or fully trusted, is a leading cause of failed agent deployments.