Theo The frontier AI for IT work
Home/Products/AI Triager

The AI Triager.

Every ticket classified, routed and prioritised the moment it lands. Before a technician opens it, the ticket already carries its work type, its queue, its priority, its requester identity and the context needed to work it.

Where to start

Triage runs on every ticket. Even the ones Theo will never resolve.

Resolution autonomy is something you grant one ticket category at a time. Triage isn't. It reads and labels, it doesn't change anything in a tenant, and it runs on 100% of inbound volume from the first day — including categories where you have set resolution to off.

That makes triage the safest place for a sceptical MSP to start.

You get a full month of classified, routed, correctly prioritised tickets before you decide whether to let Theo execute anything. The classification data is also what tells you which categories to grant autonomy on first.

01

Nothing is written to a tenant

Triage reads the ticket and writes back to the PSA record. It does not touch identity, mail, licensing or devices.

02

No category has to be enabled

Firewall migrations, project work, billing queries — all classified and routed, none of them candidates for resolution.

03

Your existing boards stay where they are

Theo routes into the queues and boards you already run. It doesn't ask you to restructure the PSA first.

04

Every classification is reversible and logged

A technician can reclassify in one click. The correction is recorded, and it is visible in the audit trail alongside every other action.

Classification

Against a real taxonomy, not a keyword list.

Theo classifies against 17 domains and 142 work types — the published taxonomy of what MSPs actually do. "Email issue" is not a class. "Mailbox quota exceeded" is.

Domain and work type

Each ticket lands in one of 17 domains and one of 142 work types. The taxonomy has explicit rules for the boundary cases, so a mailbox permission request doesn't drift between identity and email depending on how it was worded.

The class survives contact with the queue

Classification is stable across channel and phrasing. The same underlying problem reported by phone, by email and through a portal form gets the same work type, which is what makes category-level reporting mean anything.

You can read the mix

Once volume is classified consistently you can see what your desk actually spends its week on, per client and per work type. That is the input to every autonomy decision that follows.

The taxonomy is published. Read A Taxonomy for MSP IT Work for the full domain and work-type catalogue and the classification rules.

The triage pass

Six decisions, made before a human opens the ticket.

Each one runs on every ticket, in the same order, in seconds.

01

Classify the work

Domain and work type from the 17/142 taxonomy, plus a confidence level. Low-confidence tickets are flagged for a human rather than guessed at.

02

Resolve the requester to an identity

A display name in a ticket body is not an identity. Theo matches the requester to a real user in the client's tenant and to a contact on the account, and flags the ticket when it can't.

03

Route to the right queue or board

Into the boards you already run, using your own routing rules per client. Project work goes to project, security goes to security, L1 volume goes to L1.

04

Set priority and the SLA clock

Priority from the work type, the client's contract and the actual business impact described in the ticket — not from whichever radio button the requester happened to pick.

05

Detect duplicates and related tickets

Four tickets about the same outage get linked instead of worked four times. Recurrence against the same user or device in the last 30 days is surfaced on the ticket.

06

Decide whether it is a resolution candidate

Theo marks the ticket as something the AI Technician can take end-to-end, something that needs supervised execution, or something that belongs to a human from the start. Your autonomy grid decides what happens next.

Enrichment

What is on the ticket before a technician opens it.

The point of triage is that the first thirty seconds of a technician's work is already done. This is what is attached to the PSA record.

Classification

Domain, work type, confidence level, and the reason the class was chosen when the ticket was ambiguous.

  • domain
  • work_type
  • confidence

Requester identity

Resolved user principal name, client account, department and manager, plus whether the requester is authorised to ask for what they asked for.

  • resolve_identity
  • get_manager
  • verify_contact

Routing and priority

Target queue or board, assigned priority, SLA target and the contract terms that produced it.

  • route_ticket
  • set_priority
  • apply_sla

Duplicates and history

Links to open tickets covering the same incident, and to the same problem resolved for this user or device before.

  • find_duplicates
  • search_past_tickets

Documentation context

The relevant IT Glue or Hudu article for this client and this work type, with the client-specific exceptions called out rather than left to be found.

  • search_documents

Device and tenant state

Where relevant: the requester's device, its compliance and patch state from Datto RMM or NinjaOne, and licence headroom on the client's tenant.

  • get_device_health
  • get_license_availability

A resolution candidate flag, and nothing more.

Triage decides whether a ticket is a candidate for the AI Technician. It does not decide whether Theo is allowed to act on it — that is your autonomy grid, per ticket category and per client.

See the autonomy grid
Straight answers

What the AI Triager is, and what it isn't.

What it does
  • Runs on 100% of inbound tickets from day one, in every category.
  • Classifies against a published taxonomy of 17 domains and 142 work types.
  • Routes and prioritises using your boards and your contract terms.
  • Attaches identity, history and documentation to the record before anyone opens it.
  • Flags what it isn't sure about rather than guessing a class.
What it isn't
  • Not a resolution engine. Triage labels and routes. The AI Technician does the work.
  • Not a PSA replacement. It writes into the boards and fields you already use.
  • Not a chatbot for end users. There is no new front door for your clients to learn.
  • Not a licence to act. A resolution-candidate flag is not an approval to execute.
  • Not a reason to rebuild your taxonomy. We map to what you run today.

Start with triage. Grant autonomy later.

Book 30 minutes. We'll look at your actual ticket mix, show you how it classifies against the taxonomy, and tell you which categories are worth granting autonomy on first.