About the session
For decades, IT self-service has meant one thing: help people help themselves so they file fewer tickets. Deflect the request, publish the article, count the win. But deflection was always a proxy, a measure of the work we avoided, not the problems we solved. And the problems that matter most were never in the ticket queue to begin with: the access that should be revoked, the entitlement that should be cleaned up, the work no employee ever thinks to request.
At enterprise scale, that gap becomes the whole problem. A GCC, an IT-services major, a large bank doesn't have a volume problem, it has a scale problem. Thousands of joiners, movers, and leavers a month. When a contractor rolls off, no one files a ticket to revoke their access, so it lingers. Multiply that by a workforce churning by the hundreds, and the invisible half of IT isn't one forgotten account; it's a continuous, growing pile of standing access nobody is measuring. Onboarding failures complain loudly and get fixed fast. Offboarding failures stay silent, and in an audit-heavy environment, that silence is a compliance and security liability that compounds every month.
This is the half that IT self-service, as most of the market sells it, still can't touch because it's built to answer, not to act. A knowledge article can't revoke access; a chatbot can't deprovision an account across your systems. Read-only AI deflects the request, logs a win, and leaves the real exposure exactly where it was.
This session makes the case for what changes when self-service moves from answering to resolving, and shows live what that takes at enterprise scale. Not a smarter search box, but an agent that acts inside real systems, writes results back to the systems of record, and operates within the permissions, policy, and audit trail the enterprise already runs on. The point that matters most for anyone accountable to auditors: what decides whether AI can safely resolve isn't the sophistication of the model, it's whether the organization can state its own rules clearly enough to hand them to a machine. The hard part is the clarity, not the technology.
What you'll take away:
- At enterprise scale, the invisible half is the real exposure: Deflection rate, cost per ticket, and resolution time describe only the tickets employees file. In an organization onboarding and offboarding people and vendors by the thousands, the work nobody requests like lingering access, un-revoked entitlements, silent offboarding gaps etc. is where the compounding risk lives. The session reframes what good self-service means when success is measured by problems resolved and exposure closed, not just requests deflected.
- Answering is not resolving and the difference is visible on screen: A live demonstration of the gap between a system that explains how to get access and one that grants it, writes it back to the system of record, confirms it's done and then revokes it automatically the moment an engagement ends.No ticket filed, full audit trail, with a human approving the calls that warrant it. Governance isn't a constraint bolted on; it's how resolution runs.
- The constraint is rarely the AI; it's rule clarity, and that's what makes it safe to scale: What holds most enterprises back isn't how advanced the model is; it's how clearly they've defined their own policy. When rules are explicit and live in one place, automating against them across a large, complex estate becomes straightforward and defensible to an auditor. The permissions and audit layer around the model matter more than the model itself.
Agenda
The invisible risks beyond the ticket queue
Answering versus resolving
Governed actions and human approvals
Policy clarity, permissions, and auditability





