09:02 · 38 min active
The service desk your auditors and your employees both like.
Incidents, service requests, changes, problems and releases, with an asset register and configuration model underneath, and the same desk extended to HR, finance, facilities and legal, so an employee has one place to ask for anything.
SSO-04 · topology rel 44 · CHG-2184
Billing events remain queued.
Four smoke tests stay attached.
The ticket, service graph and change record are one incident story.
INC-8831 begins as business impact, not alert volume. CHG-2184 becomes a credible correlation only because time, dependency and trace evidence agree.
Name the service, not the flood.
Eighteen alerts become INC-8831 with Finance ERP, cohort and business work attached.
Read the same service graph.
The desk joins topology, telemetry and CHG-2184 instead of reconciling three exports.
Keep options and consequences.
Hold, rollback and bypass remain visible with runbook and change effects.
Preserve change authority.
Maya validates impact, Arjun validates rollback readiness and CAB authorises the path.
What changes
Keep ITIL discipline. Make the service consequence easier to see.
These are the rows an IT head and an auditor both read. The difference is that the change record, the asset it touches and the employee who asked for it are the same meta model, not three integrations.
Incident management
Tickets, priority matrices and an on-call rota.
Intake from portal, chat, email and monitoring alerts; the triage agent groups the flood into one incident and names the affected service, not just the symptom.
Service catalogue
A request form per service, and an approval by email.
Catalogue items carry cost, entitlement and approval chain, so a request for a licence checks budget and role: before it reaches anyone to approve.
Change management
A CAB meeting, and a change form filled afterwards.
Change risk scored from blast radius, history and freeze windows; standard changes pre-approved, and emergency changes still leave a complete record.
Asset & configuration
A discovery tool feeding a CMDB nobody trusts.
Assets, licences, contracts and dependencies live in the same meta model as the tickets against them, so impact analysis reads one graph, not a nightly export.
Problem & known error
A problem record opened after the third outage.
Recurring incidents roll into a problem automatically with the pattern named, and the workaround becomes a knowledge article the desk actually cites.
Employee service (ESM)
A second helpdesk for HR, a third for facilities.
The same catalogue, SLAs and approval engine serve HR, finance, admin and legal, so the employee asks once, in one place.
One command room from correlated signal to controlled mitigation.
The service graph, change trail and runbook prepare the decision. Maya, Arjun and Emergency CAB retain the authority to act.
Finance ERP latency during period close
P1 · Major incident · Mitigation decision
18 latency alerts joined to Finance ERP
Maya Krishnan opened commander bridge
AP, close batch and billing dependencies traced
CHG-2184 joined by time, dependency and trace evidence
Three options retained; no action executed
Change log · event clock
Service topology · rel 44
Trace panel · SSO-04
DB-02 · ERP-CPU
09:00–09:32 window · Token validation is 64% of ERP request wait
Package idp-policy-7.4 · Rollback package and test steps attached
Reviewed 03 Jul · 11-minute rollback with smoke-test gates
PRB-0418 known error · Symptom match; prior workaround documented
92 users · Blocked
34 users · +42 min
1 integration · Delayed
All employees · Healthy
The commander sees service impact and change authority together.
The phone is a complete decision surface: incident, exception, evidence, blast radius, prepared mitigation and named checkpoints.
Finance ERP · P1 major incident
SSO validation change correlates to onset.
AP, consolidation and billing impacted.
No remediation or change approval is inferred.
12 min · dependency rel 44 · SSO-04
RB-17 estimates 11-minute controlled rollback.
Billing events queued · employee portal healthy.
Emergency CAB remains the release gate.
The practices, generated.
Your priority matrix, escalation hierarchy, change policy and freeze calendar are modelled in the session. Incident, request, change, asset, dependency and employee entitlement stay connected to the same governed work.
Incident & major incident
Priority matrix, on-call escalation, major-incident declaration with a comms lane and a timeline for the post-incident review.
p1 · comms · pirService catalogue
Published items with cost, entitlement, fulfilment workflow and approval chain, ordered from a branded portal.
entitlement · cost · approveChange & release
Standard, normal and emergency changes with risk scoring, freeze calendars, approval boards and linked release records.
risk · freeze · cabProblem management
Problem records from recurring incidents, root-cause analysis with a dated owner, and known-error entries with workarounds.
rca · known errorAsset & licence register
Hardware, software, licence and contract records with assignment, warranty, renewal dates and end-of-life tracking.
assign · renew · eolConfiguration model
Services, applications and infrastructure with dependency relationships, so change impact and incident blast radius read the same graph.
ci · relation · impactEmployee request desk
HR, finance, facilities and legal request types on the same SLA engine, routed to the department that owns them.
esm · one portal · slaAccess & joiner-mover-leaver
Access requests and revocations tied to the HR record, with recertification campaigns and evidence for the auditor.
jml · recertify · evidenceA change that cannot skip its own gate.
Prepared mitigation never becomes an implicit emergency approval. The current state, rollback evidence and smoke-test gates remain on the incident.
“which changes went in outside an approved window last quarter, and who approved them”
Three agents on the desk. The change board still decides.
Agents group, score, reconcile and fulfil. Incident command, change ownership and CAB authority remain human.
Classifies and groups incoming incidents and requests, and collapses an alert storm into one incident with the affected service named.
grouping is shown and reversibleScores every change on blast radius, change history and freeze calendar, and drafts the rollback plan.
the board approves, alwaysReconciles discovered estate against the register and raises what is unaccounted for, unassigned or out of support.
write-offs need an approverRuns catalogue fulfilment end to end, chasing approvals and provisioning steps against their SLA.
entitlement checked before spendBring your change policy. See it enforced by Friday.
A 90-minute working session: your priority matrix, catalogue items and change policy drafted as an FRS, approved, and generated to a staging tenant with the asset register modelled.
The desk is meta on the platform: the asset register, the employee record and the ticket are one model, durable execution runs every approval chain, and access revocations are evidenced against the leaver record.