Category definition
What an AI Service Desk Agent Is, and Is Not
The test that qualifies a tool: where requests arrive, what it may execute and in which systems, who approves before it runs, and what is recorded.
8 min read
Updated on
An AI service desk agent is software that takes an employee’s IT request where it is typed, usually Slack, Microsoft Teams, a portal or email, answers it from the knowledge sources the IT team has connected, and, when an answer is not enough, carries out the routine change in a connected system such as the identity provider, within the controls the IT team has configured, keeping a record of what ran. Harmony writes that “what separates it from a chatbot is action”, and Console defines an action as “a change executed in a connected system”. The same line applies to ChatGPT for internal IT support: with no connection to your systems, it can explain a procedure; given authorized tools, it can act too, with the rights those tools carry. The useful test is therefore not the label but four questions that published pages answer or leave open: where requests arrive, what the agent may execute and in which systems, who approves before it runs, and what is recorded.
Can ChatGPT handle internal IT support?
Partly, and the part depends on what it is connected to. With no connection to your systems, an assistant answers about a procedure and nothing happens in Okta, the HRIS or the device management platform. That is a property of the setup, not of the category of assistant.
The Model Context Protocol changes the setup. Its specification says servers expose tools that language models can invoke, and that tools “enable models to interact with external systems, such as querying databases, calling APIs, or performing computations”. OpenAI’s guide describes remote MCP servers that “connect models over the Internet to new data sources and capabilities”, reached from ChatGPT through a plugin, and advises: “Keep approval enabled for tools that can modify data or take other consequential actions.” The MCP specification says there “SHOULD always be a human in the loop with the ability to deny tool invocations”.
So the useful line is not a chatbot that answers against a service desk that acts. The four questions apply to a general-purpose assistant wired to tools as they do to a service desk agent, and that assistant has the rights you give it. MCP servers and conversational clients goes through what published servers expose.
What does it take for AI to handle repetitive IT requests?
Three things, each of which a vendor either publishes or does not.
An answer from your documentation. Serval’s documentation describes a help desk agent that retrieves from the knowledge sources the team connected: the content is synced “read-only”, and the agent “searches and cites it”, linking back to the original document. How current an answer is depends on the synchronization schedule: Serval states that connected sources “automatically sync every four hours”, with a manual sync available. It also says the agent only surfaces a document to a user who is allowed to see it in the source system, for integrations that support propagating access controls. Another product can use a different cadence and a different permission model, so both are settings to look up.
An action in a connected system. Answering is a knowledge problem; acting is an integration and permissions problem. Harmony’s product page lists what its agent executes when a request needs something done: “password reset, MFA reset, application access, group membership, device action”. Console’s overview says IT teams “define policies, approvals, and actions that run automatically in the background”. What autonomy means for an IT agent compares how approvals, action scope and trial modes are published.
A record. A reviewer needs to reconstruct what the agent did, on whose request and with whose approval. Harmony writes that “every step is logged”; Console that “every request, approval, and action in Console is tracked”. How much of the queue such an agent actually removes is a separate question, and published rates deserve their own reading, in what a deflection number covers.
How do you recognize a product in this category from its documentation?
A product page says what an agent can do. The documentation that qualifies it answers the four questions with specifics, and several vendors publish them, each in its own vocabulary.
Where requests arrive. Console says employees interact with it through Slack or Microsoft Teams. Freshservice’s AI Agent Studio documentation says the same agent runs across the Support Portal, Microsoft Teams and Slack.
What the agent may execute, and in which systems. Look for an inventory per connected system rather than a row of logos. Siit’s IT Agent page lists actions by system, from Okta (reset multi-factor, reset password, add to group, add applications) to JumpCloud, Google, Slack, Zendesk, Jira and custom webhooks. Freshservice says its agents act by calling workflows, which “can execute or take actions on other systems”. Moveworks describes conversational AI agents that “execute real-time actions to create, modify, read, & remove data from business systems”.
Who approves before it runs. Ravenna describes access provisioning as a chain: a request for an access level, a policy check, an approval template placed on the ticket, then provisioning executed and an entitlement created. Atomicwork routes approval requests “to the right people in Slack or Teams”. Serval’s homepage says its agent “can only take action against your systems using deterministic workflows that admins have expressly approved and published”.
What is recorded. Atomicwork writes that “every grant links back to the request that created it”. Siit’s page states that every step (prompt, decision, action, approval) is logged and that runs can be replayed.
How is the market organized, and what do the labels tell you?
Vendors describe themselves in their own terms, and the terms do not line up with a capability. Freshworks gives its Pro plan the tagline “Unified IT service management with AI”. Atomicwork’s pricing page is titled “AI Workforce for ITSM & ESM”, Serval’s homepage title reads “AI-Native Enterprise Service Management and ITSM”, and Harmony presents its agent as one part of an “AI-native ITSM platform”. None of these labels says what the agent is connected to or what it is allowed to do.
The split that holds up is one of placement, and it is a decision per deployment rather than a family of vendors. Atomicwork says its AI Workforce “runs on top of ServiceNow or Atlassian JSM — no migration, no platform fee”. Console states that it “does not act as a system of record” and relies on the connected systems as the source of truth. Serval offers “the automation layer on top of your existing ITSM” with bi-directional sync, and its homepage also carries the heading “Full-stack ITSM built to replace”, followed by ServiceNow, JSM and FreshService. Freshworks sells the AI inside its ticketing product: Freshservice’s pricing page lists Freddy AI Copilot as an add-on and Freddy AI Agent (Classic) in its Enterprise plan.
For a team that already has an ITSM, an identity provider and a knowledge base, running an agent in front of the incumbent is a sequencing decision rather than a migration. Running an agent in front of an existing ITSM covers the order of decisions.
Which criteria separate the best AI service desk tools?
The four questions do more work than any ranking, and each can be answered from a vendor’s published pages.
Where requests arrive
Natively in Slack and Microsoft Teams, in a portal, or by email. The channel decides how many requests reach the agent at all.
What the agent may execute
Which actions it runs in the identity provider, the HRIS and the device management platform, and where it hands the work back to a person at the ticket boundary.
Who approves before it runs
Whether a person approves an action before it runs, and whether that rule is set per workflow, policy or action. In the products documented here, it is a setting, not a property of the category.
What is recorded
Which requests, approvals and actions are logged. A run that leaves no trace gives a reviewer nothing to look at.
The first sounds soft and is not: a request that is never typed is never handled, and the surface where employees already talk decides the volume the agent sees. The second depends on the integrations and the permissions granted. The third is a setting rather than a property of the category, as the warning below shows; the fourth is covered above.
One more published fact belongs on the grid, although it says nothing about capability: the unit the bill follows. It is where published pages differ most, and where a tidy summary misleads. Freshservice’s pricing page bills per agent per month by plan, with a Freddy AI Copilot add-on per agent and 1,200 sessions of its Freddy AI Agent (Classic) included per Enterprise license each year. Atomicwork sells credits, “drawn each time an AI Coworker completes a job” and scaling with “steps taken, tools called, output length, and reasoning complexity”, alongside outcome-based plans, and lists “Up to 250 end users” among what its Professional tier includes.
The quantity each bill follows differs: seats, sessions, credits or outcomes. Minimums, add-ons, quotas and plan limits decide the total, and no amount is compared here. Put the billing unit on the evaluation grid next to the amount, and test both against your own request volume.
What do published pages leave for you to test?
The word “approved” does not mean the same thing from one vendor to the next, and the category does not settle it.
Two tests follow. For each action you plan to delegate, find the setting that decides whether it waits for a person, and who can change that setting. Then check that the connector for your identity provider supports that action at all, rather than inferring it from a list of logos.
Which vendors document an AI agent that acts in your systems?
Listed here: vendors whose public pages describe an AI agent for internal IT support that executes actions in connected systems and say how those actions are controlled, by an approval step or by limiting the agent to actions or workflows an administrator has set up.
- Atlassian: Atlassian’s AI for service management page describes Request Resolver, which “carries out a resolution plan across connected tools”, after an agent approves each plan in supervised mode or directly for qualifying requests in autonomous mode.
- Console: Console’s platform overview defines an action as “a change executed in a connected system” and describes approvals as “an explicit human decision step” defined by IT teams in playbooks.
- Freshworks: Freshservice’s AI Agent Studio documentation says the ready-made IT Agent ships with pre-built workflows for password resets and software access approvals, and that agents take action by calling a workflow.
- Harmony: Harmony’s AI Service Desk Agent page says the agent executes changes such as password resets, MFA resets and application access, and that “approvals defined in your policies are requested first”.
- Ravenna: Ravenna’s access provisioning documentation describes a request flow in which an approval template is placed on the ticket before provisioning is executed and an entitlement created.
- Risotto: Risotto’s page for teams says it automates access management “with expiry dates, approval chains, and role-based rules”, with integrations such as Okta and Google Groups.
- Serval: Serval’s homepage says its agent acts on your systems only through “deterministic workflows that admins have expressly approved and published”.
- Siit: Siit’s IT Agent page lists the agent’s actions per system and states that “only whitelisted actions are available to the agent”, with a running mode per action.
- Zendesk: Zendesk’s article on advanced action flows, in early access (EAP), says its AI agents can run a published flow, and that the flow can request an approval from a manager before it continues.
The order is alphabetical, and the list is not a ranking.
Frequently asked questions
Can ChatGPT handle internal IT support?
An assistant with no connection to your systems can explain a procedure but cannot carry it out. Connected to tools it is authorized to use, for example through MCP, it can also act, with the rights those tools carry.
Can AI handle repetitive IT requests on its own?
Only as far as the settings an administrator chose allow: what the agent may execute, whether a person approves before it runs, and what is recorded. In the products documented here, approval is configured per workflow, policy or action, not fixed by the category.
What are the best AI service desk tools?
This guide publishes no ranking. It compares tools on four questions that published documentation can answer: where requests arrive, what the agent may execute and in which systems, who approves before it runs, and what is recorded. The billing unit is checked alongside.
Which vendors offer an AI service desk agent that acts in your systems?
Vendors whose public pages describe an AI agent for internal IT support that executes actions in connected systems and say how those actions are controlled include Atlassian, Console, Freshworks, Harmony, Ravenna, Risotto, Serval, Siit and Zendesk, in alphabetical order. The list is not a ranking.
Sources
- Siit documentation: IT Agent, actions, approvals and governance · Siit
- Harmony: AI Service Desk Agent · Harmony
- Console: platform overview, key terms and security model · Console
- Ravenna documentation: access provisioning · Ravenna
- Risotto: help desk automation for teams · Risotto
- Serval: AI-native ITSM and approved workflows · Serval
- Serval documentation: connected knowledge sources and sync · Serval
- Atomicwork pricing: credits, outcomes and bring-your-own ITSM · Atomicwork
- Atomicwork: agentic access provisioning · Atomicwork
- Freshservice pricing: plans, per-agent billing and AI add-ons · Freshworks
- Freshservice support: Introduction to AI Agent Studio · Freshworks
- Moveworks documentation: Agent Studio overview · Moveworks
- Building MCP servers for plugins and API integrations · OpenAI
- Model Context Protocol specification: tools · Model Context Protocol
- AI for service management (Rovo, Request Resolver) · Atlassian
- Creating advanced action flows (EAP): AI agent invocation, approvals and pauses · Zendesk