Glossary
44 termesGlossary of AI service desk terms
The vocabulary of internal IT service management and AI agents, defined once so the rest of the site can be read precisely.
- 44Terms defined
- 17Letters covered
- 6Related sections
- Oct 2026Updated
A
-
AI service desk agent
AI IT agent, internal IT agent
Software that takes an internal IT request in the channel where the employee already works, answers it from the knowledge sources the IT team has connected, and, when an answer is not enough, can carry out a routine action in a connected system such as the identity provider, leaving a record a reviewer can read. Whether it can act depends on the tools connected to it and the rights those tools carry.
-
AI-native service desk
A market label, not a standardized category, for service desk products presented around an AI agent as the main way requests are handled. Vendors apply it to products of different scope, and on its own it does not say what the agent is connected to or allowed to do. Serval's homepage title, "AI-Native Enterprise Service Management and ITSM", and Harmony's description of an "AI-native ITSM platform" are two published uses.
-
Approval policy
The configured rule for who must sign off before an action runs: which approvers, how many of them must agree, and whether approval takes one step or several. Serval documents groups with an optional quorum and multi-step chains, and Moveworks runs sequential or parallel steps in which one denial denies the request. An approval by a designated person is not the same control as a confirmation by the requester.
-
Article state
A status a knowledge base attaches to an article, such as Visible or Hidden, that decides whether the agent can use it. Serval, for example, gives each synced document a Visible or Hidden status. The status sits between the sync and the agent: an article that has been synced is not necessarily available to the agent.
-
Audit trail
audit log
A chronological record of the events that changed a system or an access, with who or what acted, when, and on whose approval. Publishers record different things: Serval logs workflow runs step by step, and Ravenna states a trail of AI interactions, tool executions and configuration changes.
-
Autonomy level
autonomy setting, level of autonomy
The setting that decides whether an agent's action runs alone, waits for a confirmation or an approval, or is not exposed. Publishers attach it to different units: Ravenna sets an execution policy per tool (Auto-execute, Requires confirmation or Requires approval), Serval limits its agent to published workflows that can require approvers, and Siit sets one of three levels per playbook. Where the agent is deployed, such as Ravenna's channels, is a separate control: it decides where the agent is exposed, not whether an action may proceed.
C
-
Conversation surface
intake surface
The place where an employee raises a request to an agent and reads its outcome: a chat platform, a portal or another channel. It sets where requests can start, not what the agent may do once reached. Example: Slack and Microsoft Teams, where vendors document channels, direct messages, message actions and tabs. On Slack, message retention is set by Workspace Owners or Org Owners rather than by the service desk.
D
-
Deprovisioning
access removal
Removing an access that was granted: taking a user out of a group, removing an application assignment, disabling an account, or completing a manual task. Okta documents automatic deprovisioning when a user leaves a group that provided an app. The effective end of access can differ from the instruction: in some products automatic removals run through a queue, and a manual removal waits on whoever owns the task.
E
-
Entitlement
access entitlement
A right to reach a resource that an identity holds, such as an application assignment, a group membership or a role. A list of current holders says who has access today, not how each access arrived: group-granted and directly granted access can differ in how they are removed.
-
Escalation
escalate a request
Passing a request the agent has not resolved to a person or another system: a human agent, a specialist team, or a ticket in a separate ticketing platform. Atlassian's virtual service agent offers to create a work item for a human agent when the employee still needs help, and Siit escalates a request into a linked ticket in a chosen Zendesk group and form. It can also be a setting: in Harmony's knowledge-base-only mode, the agent escalates to a human rather than answer from general model knowledge.
-
Established ITSM platform
incumbent ITSM, installed ITSM
A service management product an organization already runs for tickets, approvals and records, such as Jira Service Management, Freshservice or Zendesk. The label describes an installed position, not a capability level: which processes a product supports, such as change or problem management, is checked product by product. An AI agent can run in front of it while it stays the system of record; replacing it is a separate decision, judged on history import, process coverage, API limits and how integrations authenticate.
F
-
Field mapping
The step that links a field on one system to a field on another so that data carries across a connection. Between an agent and a ticketing platform it covers request types, required fields, statuses and priorities. Harmony brings in the custom fields configured on a Jira Service Management portal form, Serval maps priorities with Zendesk and writes its "none" priority as low, and Ravenna warns that a status it maps has to exist in the Jira project's workflow.
G
-
General-purpose assistant
general-purpose AI assistant
A conversational AI assistant built for broad use rather than for one function, such as Claude or ChatGPT. With no tools connected, it can explain how an IT procedure works but holds no rights in the systems involved. Connected to a service desk, for example through an MCP server, it can also act, with the rights of the credential that authorized the connection: several vendors document the signed-in user's own permissions, and others accept an API key or a token issued from their dashboard.
-
Group
directory group
A directory object that collects users so that access can be granted to the collection rather than to each person. Removing a user from a group is meant to withdraw the access it carried, but the identity-provider pages document exceptions: a revocation can take effect after a delay, and an entry can remain in a downstream push group. An assignment made directly on an application is a separate grant, and a group removal is not documented as reaching it.
-
Group rule
A rule that adds users to a group, and removes them, according to a user attribute. In Okta, when a user's department attribute changes, the user leaves the matching group automatically. Okta publishes the limits on the same page: a maximum of 2000 rules per org, string attributes only in basic conditions, and no assignment of users to admin groups.
I
-
Identity provider
IdP
The system that holds user accounts, group memberships and application assignments, and authenticates users, such as Okta, Microsoft Entra ID or JumpCloud. An agent connected to one can read a requester's profile, manager, groups, application assignments and account status, which turns much of an access request into a lookup. What it can change depends on what the connector is granted: Okta bounds a service app by the OAuth scopes granted and the admin roles assigned to it.
J
-
Joiner, mover, leaver
JML
The three lifecycle events access is designed around, as Microsoft defines them: a joiner enters the scope of needing access, a mover moves between boundaries within the organization, which might require more access or authorization, and a leaver leaves that scope, which might require removal of access. Okta describes the same arc as provisioning on joining, moving and leaving.
K
-
Kill switch
A control that stops an AI agent, or one of its procedures, from starting new work. Siit documents a kill switch that pauses an agent or a single playbook, with requests falling back to humans; at Atomicwork, unpublishing an AI coworker stops new runs while a run already in progress still finishes. A pause can block new runs, interrupt a run already active or cancel queued actions, and a product may do only some of the three; effects already produced are a separate question.
-
Knowledge source
documentation source
A body of documentation an AI agent is allowed to read and answer from, such as a wiki, a document store or the desk's own article base. The IT team chooses what is connected, but the agent can still answer from elsewhere: Harmony, for example, defaults to a mode that supplements the knowledge base with general model knowledge. Serval, Ravenna and Harmony list Confluence and Notion among their sources; Serval states a four-hour refresh and Ravenna twenty-four.
M
-
Model Context Protocol
MCP
An open specification for connecting an AI client to external systems through a server that exposes tools. Tools can read and also write. The specification makes authorization optional, so "MCP support" alone does not say how a server checks the caller. Atlassian, Serval and Ravenna document that the assistant acts with the permissions of the signed-in user, while Atomicwork's connection page documents a bearer token generated in its dashboard.
N
-
No-training endpoint
no training endpoint
A model provider interface whose inputs are not used to train the provider's models. It is distinct from Zero Data Retention, which concerns whether prompts and responses are kept: Mistral AI states that the two are separate controls, and OpenAI, which does not train on API data unless a customer opts in, keeps abuse monitoring logs for up to 30 days by default. At OpenAI, Zero Data Retention needs the provider's prior approval, and once approved it applies only on eligible endpoints.
O
-
OAuth 2.0 (3LO)
three-legged OAuth, 3LO
An OAuth 2.0 flow, the authorization code grant, which Atlassian calls 3LO (three-legged OAuth). The user is sent to an Atlassian screen that shows the access requested and grants or denies it, and the external service exchanges an authorization code for an access token. The app stays bound by the permissions of that user, whatever its scopes. A connector can add its own condition, such as asking for an Atlassian administrator.
P
-
Page restriction
A Confluence setting by which only specific people can view or edit a page or folder. Atlassian describes content as open by default to everyone with view access to the space unless someone restricts it. For viewing, a restriction passes downwards: someone who cannot view a parent item cannot view any child item under it. Editing restrictions do not work this way. A connected account that cannot view an item near the top of a space does not read the branch below it.
-
Permission-scoped visibility
The principle that an integration reaches only what the account behind its credential can reach. Atlassian states that the permissions of the user an app acts for always constrain the app, regardless of its scopes. Freshworks ties API access to the permissions of the Freshservice profile in use, and Zendesk changes an OAuth token's permissions when the role of the user who requested it changes. In some connectors, a destination out of that account's reach is missing from the escalation picker.
-
Playbook
A written procedure that an IT agent follows, with a defined set of actions it may call. Console describes approvals as a human decision step that IT teams define in playbooks, and Siit sets one of three levels on each playbook: Suggest only, Execute with approval or Auto-execute. Other publishers attach the same decisions to another unit, such as Serval's published workflows or Ravenna's execution policy per tool, so a playbook is one way of organizing the work, not a shared standard.
-
Privileged access
Access to roles or resources that carry elevated rights. Microsoft Entra Privileged Identity Management keeps four settings apart: an assignment is eligible or active, an active member holding the role's privileges and an eligible member having to activate the role first; an assignment is permanent or time-bound; activation lasts a duration within a maximum set by administrators; and activation can require multifactor authentication, a justification or an approval, enabled for specific roles. The scoping guide proposes keeping it off the unattended list at first.
-
Profile source
In Okta, an app that acts as the source of truth for user identities. At any given time a user's profile can have only one profile source. The term names the app that owns the identities, not the user record that joiner and leaver runs start from.
-
Provisioning
Setting up, changing and removing a person's access in applications, whether one grant at a time (assigning the application, adding the user to a group) or as an automated lifecycle that follows joining, moving and leaving; Okta uses the word in that wider sense. Deprovisioning is the removal. Siit's app access policies describe four paths: a manual app owner task, an add-to-group call on the connected identity provider, a direct add to the app instance, or a mixed two-step.
R
-
Replayable log
A record of an agent's run detailed enough to reconstruct it afterwards: inputs, the procedure and version that ran, the actions called and the approver's decision. With inputs and procedure, a reviewer can tell a wrong procedure from a right one that ran on bad inputs. Serval logs workflow runs step by step with inputs, outputs and status; a log still records what the agent did, not what the team decided about it.
-
Request
A demand for help that an employee raises with IT, which an answer may settle or which may need an action, such as an access grant. In chat-based service desks it is raised in a channel, a direct message or a message action, and status updates return through the product's supported chat interface; thread behavior varies by platform. Siit's Slack page separates a request the team can see, raised by mentioning the app in a public channel, from a confidential one sent by direct message.
-
Retrieval
Selecting information from a connected source or index when a question arrives; the model then generates the answer from what was selected, rather than being trained on that documentation. A corrected article waits for a successful sync: Serval documents four hours, Ravenna 24 by default. After a successful sync, an eligible and visible revision can become available for retrieval, which does not guarantee its use in the next answer. Retrieval does not establish that a source is accurate or current.
-
Reversibility test
A screening question this guide proposes for an autonomy boundary: can a human undo this action in a few minutes, without data loss and without a second approval? In that method, a no keeps the action behind approval. A yes only makes it a candidate and releases nothing alone, since an undo does not erase the interval: whatever a group membership opened was open, and a removal is a second change, not an undo. Okta states that an MFA reset can't be undone.
-
Role-inherited API key
A credential whose reach is the role or permissions of the user account it belongs to, rather than scopes of its own. Freshworks documents this for the Freshservice v2 API: an agent's personal API key, used over HTTP Basic with no password, reaches what that agent's profile permits. Zendesk's API tokens are a different model, not tied to one account: a token acts as the user whose email address is supplied, so it can impersonate anyone in the account, admins included. Zendesk labels them deprecated.
S
-
Scheduled sync
periodic sync
A refresh of imported content or records from a connected source that runs on a timer rather than on each change. Publishers state different intervals: Serval four hours and Ravenna twenty-four, both with a manual trigger, while Harmony syncs periodically without an interval. A change made at the source waits for a successful run or a manual sync; after it, an eligible and visible revision can become available for retrieval, which does not guarantee its use in the next answer.
-
Self-service portal
employee portal
A web interface where employees raise requests and follow their status, as an alternative or a complement to a chat channel. Atlassian IT described moving requests into a Slack channel tied to a Jira customer portal, and Freshworks lists the Support Portal among Freddy AI Agent's channels. Chat-first products differ in how much of it they bring into the chat: Serval adds Home and Tickets tabs in Teams, and Harmony's Teams notifications deep-link to its portal.
-
Service account
dedicated integration account
An account created for an integration rather than borrowed from a named employee. Atlassian, Zendesk and Freshworks each document that what an integration can reach is bounded by the role or permissions of the account it acts for, so the account chosen sets the ceiling. Atlassian adds that for OAuth 2.0 (3LO) apps an administrator cannot revoke one user's access from the Connected Apps screen and can only uninstall the app.
-
Shadow mode
A trial mode in which an agent's procedures run and log what would have happened, without making changes. Siit's trust model uses the name and describes testing playbooks with simulate. Comparable modes cover different side effects: Ravenna's Testing Mode writes no tickets and sends no messages, and Serval's Simulations simulate workflow calls and access requests by default. For any of them, the question is which side effects it covers.
-
SOC 2 Type II attestation
SOC 2 Type II report, SOC 2 Type 2 report
An independent auditor's report on a service organization's controls over a stated period, measured against the Trust Services Criteria its scope selected. The criteria are the AICPA's yardstick, not the report. A report states the system described, the period, the auditor's opinion and any exceptions; its existence does not state its conclusion. It covers a closed period, and products or criteria outside the scope were not examined.
-
Source citation
answer citation
A reference attached to an answer that points to the source it drew on, usually a link back to the original document. Serval describes its agent as searching and citing connected sources and linking users back to the original document. A citation lets a reader open the source and compare it with the answer; an uncited answer can still be checked, but by other means.
-
System of record
record system
The platform that holds the authoritative records for a function. For IT support it is the ITSM where tickets are created, routed and closed. An agent added in front of Jira Service Management, Freshservice or Zendesk can leave that platform in the role, changing how requests arrive and are escalated. Replacing the platform itself is a separate decision, with its own criteria such as history import and API limits.
T
-
Ticket deflection
Avoiding a support ticket by settling an employee request through an answer or an action. Vendors also publish distinct automated-resolution metrics, including outcomes on tickets already created, such as Serval's tickets resolved without human intervention; Zendesk separates contained from verified resolutions. Each needs its own definition. To compare two rates, align definitions and observation windows, report eligibility coverage, and exclude outcomes whose observation window is still open.
-
Time-bound access
time-limited access
Access granted with an end date. Microsoft PIM assigns it using start and end dates inside the services it manages. Elsewhere an end date is a scheduled removal, which counts only once it has executed and been confirmed in the target application. A passed deadline does not prove revocation, and an expiry ends the grant, not what was read or changed during it.
-
Two-way sync
bidirectional sync
A link between two records in separate systems, such as an agent's request and an external ticket, where changes can travel in both directions. Products set it at different grains: Serval chooses the direction for new tickets only while updates to linked tickets sync both ways, Ravenna enables inbound and outbound replication separately per channel, and Siit picks a behavior per event in each direction. Which events cross, and with what default, decides what happens to a resolved ticket.
W
-
Whitelisted action
An action an agent is explicitly permitted to run, taken from a closed list. The list limits which tools exist for the agent; what each tool can do downstream depends on the tool, its destination, the arguments it accepts and the rights of the credential behind it. Siit's IT Agent page states that only whitelisted actions are available to its agent, and Serval's help desk agent only gets the tools a team explicitly turned on.
No term matches.