Scaling enterprise AI, particularly in ITSM, requires moving beyond legacy operating models and adopting a risk-weighted delegation framework that clearly assigns work to agents or humans based on acceptable risk. This makes governance the driver of ITSM’s build-versus-buy decision for its agentic AI platform, ensuring enterprises have full control as they scale from low- to high-risk process automation.
The next step is putting the ITSM AI platform to work. Following is a blueprint CIOs can use to deploy governed ITSM automations.
Determining which ITSM actions are entrusted to agents
Lacking the proper context, data, and access to resolve an IT ticket, agents pass those tickets to humans. This blocks AI investments from reaching expected returns.
Unfortunately, approximately 70% of IT budgets are spent on maintaining current operations. Little remains for modernization, leaving clunky systems and lost context as common ITSM challenges. An existing tool’s native AI capabilities might seem like an easy win, but its agent can’t easily access other tools to fill in the blanks. A human must then jump in to gather context, even for low-risk tickets like password resets, software installs, and software access requests.
The solution is an orchestration layer that works with native, custom, and other agents plus humans to bring agentic automation to existing systems and processes, and within the risk-based delegation framework.
ITSM’s blueprint for agentic automation
ITSM automation is easily split into reactive and proactive agents. Reactive agents gather incoming information, and then either point users to a solution, execute a known fix, or collaborate with a human to find a resolution. Proactive agents monitor systems 24/7 to heal and optimize them before issues occur, including escalating potential issues to humans or specialized agents.
These complementary tracks are governed by risk level using the three-tiered delegation framework:
- Human-owned processes involve high-risk, low-precedent, or irreversible decisions.
- Human-supervised processes delegate lower-stakes decisions to agents using approved rules and logging every action for human audits.
- Agent-owned processes assign agents low-risk, high-volume decisions.
At every level, trust is earned through performance. Actions in human-owned processes currently deemed too risky for agents are logged to identify patterns and train AI systems. Eventually, agents are trusted to take on those tasks under human supervision. Finally, with acceptable success, agents take ownership, with humans overseeing governing policies rather than each decision.
Think of common manually-processed software requests. Agents can begin evaluating requests against policy, and then draft recommendations for human review. As agents gain proficiency, low-cost, low-risk requests can be approved or denied instantly, with occasional human review. Eventually, agents can take on higher-stakes requests, with humans governing policy and auditing performance.
Instead of one human managing hundreds of requests daily, agents deflect incoming requests before ticket creation, resolve other tickets autonomously, and collaborate with humans to resolve remaining higher-risk tickets.
Benchmarking rollout success in ITSM automation
AI implementations have hit a wall, with only 40% of enterprises scaling agents in 2026, according to McKinsey. The lack of clear ROI must be a factor, especially since 90% of executives have yet to see AI productivity gains.
BDO Canada, however, reached 84% auto-resolution for projected savings of $1.9 million. Where overwhelming ticket volumes once created bottlenecks, agents now resolve common requests without human intervention. Users enterprise-wide get faster resolutions while IT professionals have more time for strategic efforts.
To get there, begin by benchmarking current performance, then calculate how gains similar to those above could impact ITSM. Cost savings, deflected tickets, user satisfaction—every critical metric is in play.
Don’t forget ITSM security and compliance
McKinsey expects cybersecurity budgets for agentic AI to triple within three years. This underscores why risk-based delegation is required: It costs too much to make a mistake, especially in ITSM.
Build security and compliance into ITSM automation, ensuring agents have least-privilege access, that data never leaves the enterprise, and that governance frameworks like ISO/IEC 42001 are deployed. Also, build security and compliance into the delegation framework’s risk assessments.
ITSM is only the first step in scaling agentic automation
IT ticketing and help desk processes are foundational to running a modern organization and mirror core processes across the enterprise. This same blueprint extends to HR, finance, operations, and beyond. Using the delegation framework mitigates risk, which secures organizational buy-in and ensures a methodical approach to scalable agentic automation.