You set what Theo touches, per ticket category and per client. Anything irreversible stops for an approval. Every action is logged against the ticket with a named approver. Nothing goes autonomous until you have watched it work.
Nobody running a service desk is afraid of an agent being slow. The fear is opening the queue at 8am to find fourteen tickets touched overnight, half of them wrong, and spending the morning working out which half — while the actual queue keeps filling.
That fear is correct, and it is the reason most AI pilots on a service desk quietly stop. An agent that resolves quickly and reports badly transfers work to you instead of taking it away.
So the question isn't how fast Theo is. It's whether you can tell, at a glance, exactly what it did and why.
Everything on this page is about that. Speed is a side effect.
Tickets land between 6pm and 7am and the backlog is fixed before anyone logs in. Your SLAs slip on volume, not on difficulty.
A log of API calls is not a handover. If a technician has to reconstruct what happened, the ticket was not really closed.
An offboarding request from a manager reads exactly like an offboarding request from someone who isn't authorised to make it.
The team's trust in an agent is set by its worst outcome, not its average. So the worst outcome has to be bounded by design.
Theo does the work and stages the action. A technician approves before anything executes. Pick a ticket and step through it.
Every cell is a ticket category for a specific client, and every cell has one of three settings: off, supervised, or autonomous. There is no global switch, because a global switch is the thing that would frighten you.
Changing a cell takes effect on the next ticket. You can dial any category back to supervised for one client or all of them without touching the rest of the configuration, and without raising a support request.
| Ticket category | Acme Dental | Northwind | Redwood Fin. |
|---|---|---|---|
| Password reset | Autonomous | Autonomous | Supervised |
| Account unlock | Autonomous | Autonomous | Autonomous |
| Licence assignment | Autonomous | Supervised | Supervised |
| Mailbox permissions | Supervised | Supervised | Supervised |
| MFA reset | Supervised | Supervised | Supervised |
| Offboarding | Supervised | Supervised | Off |
MFA and offboarding stay supervised everywhere — that is the default we ship, and most service desk managers never change it.
Granting autonomy on a category does not hand over the actions inside it that can't be undone. Those keep their gate regardless of the category setting.
Offboarding and account deletion, MFA method changes, shared mailbox and delegate permissions, licence changes that would trigger a true-up, and anything that removes a person's access to their own work.
The action, the exact arguments, the target identity, why Theo chose it, and what the evidence was. Not a request to confirm — a decision you can actually make in ten seconds.
Nothing executes. The ticket holds with the investigation and the recommendation written into it, so whoever picks it up starts from a worked ticket rather than a cold one.
The failure mode that hurts a service desk isn't an agent that can't do the work. It's an agent that does irreversible work on an assumption.
A ticket arrives: "Sam has left, please close the account." The requester is a real identity in the tenant. The account exists. The action is technically simple, and it is not reversible.
This behaviour is not configurable off. Where an action is irreversible and consent was only implied, Theo holds and escalates — including in categories you have set to autonomous.
Not an approximation of the answer. The tool call, the arguments, the target, the result, the timestamp, and the name of whoever approved it. 100% of actions are logged, and the log is exportable.
This is the part that decides whether your team keeps using it. A service desk manager who can reconstruct any ticket in one click will grant autonomy on a second category. One who can't, won't — and shouldn't.
| Logged on every action | Example |
|---|---|
| Timestamp | 2026-03-14 02:14:39 UTC |
| Ticket | #48327 · Northwind |
| Action | reset_password |
| Target | j.marsh@northwind.example |
| Autonomy state | Supervised |
| Approver | D. Okafor |
| Result | Success |
| Export | CSV, per client or per date range |
Read-only investigation steps are logged the same way, so you can see what Theo looked at before it decided — not only what it changed.
Your team lives in the PSA, so that is where the handover has to be. Theo writes for the next human on the ticket: what was wrong, what it did, what it deliberately did not do, and what somebody should watch for.
Plain language, in the ticket, with the time entry attached. If a technician has to open a second system to understand a closed ticket, the note failed.
Kenji asked for more mailbox space, but 21.4 GB of the 48.7 GB was Recoverable Items inflated by a legacy rule copying every sent message — raising the quota would have hidden that and recurred within weeks.
Enabled the auto-expanding archive, applied a 2-year archive policy (11.2 GB queued to move), and removed the duplicating rule. Sending works now; the mailbox will drop below 30 GB after the next assistant pass.
No quota change needed, no extra licence cost.
Most SLA breaches on an L1 queue are not hard tickets. They are ordinary tickets that sat for eleven hours because they arrived at 7pm.
Work type, priority and SLA target set the moment the ticket lands, not when someone opens it. Runs on 100% of tickets.
Categories you have granted are resolved. Categories you haven't are investigated and staged for approval.
<5 min medianWhat is left is either genuinely for a human or waiting on one approval, with the work already done and written up.
When Theo is not confident, or consent was implied on something irreversible, it holds. A held ticket is visible; a wrong action is not.
That gap is where the SLA protection comes from. It is not that Theo works faster than your technicians on a hard ticket — it is that ordinary tickets never wait for a shift to start.
You control what Theo does autonomously and where it requires approval. Every action is logged with a full audit trail. Start fully supervised and expand autonomy as you build confidence.
Two things matter more than the error rate. First, the categories where Theo acts alone are ones you have already watched it work. Second, the actions that are hard to undo stay gated even in an otherwise autonomous category.
In week one, yes — that is the point of supervised mode, and it is a few seconds per action rather than a re-investigation, because the evidence is in front of them at the gate.
After that you grant autonomy on the categories where checking stopped telling you anything new. Most desks start with password resets and account unlocks.
Yes. Autonomy is configured per client as well as per ticket category, so you can run Theo autonomous for one client and fully supervised for another, with different category sets for each. A change takes effect on the next ticket.
They escalate with the work done up to that point written into the ticket: the identity resolved, the documentation checked, the evidence gathered, and a clear statement of what stopped it.
An escalated ticket does not count toward the resolution rate we publish. Only tickets resolved end-to-end with zero human touch do.
As itself. Notes, time entries and status changes are attributable to Theo, and where an approval was involved the approver is named on the action. You should never have to work out whether a person or an agent closed a ticket.
No. Theo routes into the queues and boards you already run and maps to the ticket types you already use. We do the mapping during the first week; you don't reorganise the PSA to accommodate it.
Your client data is not used to train models. Full stop.
SOC 2 Type II — Trust Center. Data residency, retention window and the subprocessor list are published in the trust pack we send before any pilot.
Theo acts through the same delegated permissions your technicians use, scoped per client, and every call is recorded against the ticket. You can revoke access from your side at any time.
Book 30 minutes. We'll go through your queue, the categories worth starting on, and exactly what your technicians see at an approval gate.