IT playbook · AI Employee: Ivy

Proactive Device Health

Compliance drift < 3% workspace-wide

The problem

IT hears about a laptop problem the moment it becomes urgent — during a customer call, before a board meeting, at 4pm on a Friday. The signals were always there in the MDM console: failing SMART data, battery cycles past life expectancy, disk 98% full, macOS three major versions behind. Nobody looked. Reactive support means the fix is always at the worst possible time.

At a glance
Trigger
Cron (daily)
Approvals
None
What it does
Read-only
Systems
Jamf · Intune · Datadog
How it feels in production

An hour-by-hour walkthrough.

Every night, Ivy pulls device telemetry from Jamf / Intune / Kandji for every managed device. It scores each on a health matrix: - Disk health (SMART failures, wear leveling) - Battery health (cycle count, design capacity) - Disk fullness (root volume free space) - OS currency (versions behind supported baseline) - Encryption status (FileVault / BitLocker enabled + keys escrowed) - Security agent presence (EDR heartbeat, MDM check-in) - Uptime (weeks without a reboot — memory issues, pending patches) Priya's MacBook Pro scores yellow: disk 91% full, battery cycle count 1,120 (design life 1,000), OS one major version behind. None urgent. Ivy DMs Priya with a friendly heads-up: "Your laptop shows signs of aging. I've queued: (1) OS upgrade scheduled for tonight after 9pm (approve to run), (2) a disk cleanup that'll free ~40GB (approve), (3) I'll ship you a replacement battery service; let me know when's convenient." Priya approves the OS upgrade and cleanup. Ivy schedules both for after-hours. For the battery, Ivy files a ticket with the local IT ops team and books a swap slot from Priya's calendar. No emergencies, no lost work, no laptop dying in the middle of a customer demo.
How it works

Step by step.

  1. 01

    Pull nightly telemetry from every MDM

    Read device inventory + health telemetry from Jamf / Intune / Kandji / Workspace ONE / Fleet. Normalise to a common device record with health-score inputs.

    Jamf · Intune · Kandji · Workspace ONE · Fleet
  2. 02

    Score against health thresholds

    Compute a multi-factor score. Green: all normal. Yellow: one or more signals in caution range but not urgent. Red: signal past failure threshold or urgent security posture issue. Yellow triggers a friendly nudge; red triggers an urgent ticket.

    Health model · Threshold config
  3. 03

    DM the user with a plan + approvals

    User DM lists the signals, the plan Ivy has drafted, and the one-click approvals. Never runs disruptive actions without approval. Emergency-only exception: security posture failures (unencrypted disk on lost device) execute immediately with post-hoc notification.

    Slack · Teams · MDM · Approval flow
  4. 04

    Schedule the fixes off-hours

    OS upgrades, disk cleanups, cache flushes queue for the user's off-hours from their calendar. Hardware issues (battery, keyboard) route to IT ops for swap-slot booking with the user's availability.

    MDM · Google Calendar · IT ticketing
  5. 05

    Weekly IT-ops digest + fleet health rollup

    Weekly rollup: fleet health by device model, top failure modes, replacement pipeline forecast (batteries, laptops approaching end-of-life). Feeds hardware budgeting + refresh planning.

    Analytics · Slack digest · Asset lifecycle tool
Systems and wiring

What you connect to make this run.

Jamf · Intune · Kandji · Workspace ONE

read+write

Read: device inventory, hardware telemetry, OS version, security posture, encryption. Write: scheduled OS upgrades, remediation scripts, policy pushes. Nightly poll + on-demand for high-signal events.

CrowdStrike · SentinelOne · MDM security posture

read

Security agent heartbeat, encryption status, patch level, exploit protection. A missing EDR heartbeat is a red signal — the device is either lost, wiped, or the agent is broken.

Slack · Teams · Google Calendar

read+write

User DM with plan + approvals. Read calendar for off-hours scheduling. Never runs disruptive actions in-hours; user always sees the plan before execution.

Asset lifecycle · Hardware ordering

read+write

Replacement forecasting from health trends. Auto-open orders for batteries, laptops within refresh window. Feeds finance forecasting + inventory management.

What changes

Before and after, honestly.

Laptop failures caught before user impact
Before
20-40% (urgent tickets after failure)
After
85%+ (nightly telemetry catches early)
OS lag (devices behind current supported version)
Before
30-60% of fleet
After
Under 10%
Emergency laptop swaps per quarter
Before
5-15
After
0-2 (planned swaps replace emergencies)
Hardware budget accuracy (forecast vs. actual)
Before
40-70%
After
88-95% (fleet health data drives forecast)
Frequently asked

Answers about this playbook.

Won't nightly telemetry pulls affect battery life?

MDMs run continuous background telemetry regardless — Ivy just consumes what's already emitted. No additional agent overhead on the device.

What if users decline the recommended fixes?

Declined once = respected. Declined three times on the same signal = escalates to the user's manager as a coaching moment (usually the user needs a swap, not a fix). Security posture issues override user decline with policy-level enforcement.

How does it handle BYOD or unmanaged devices?

BYOD devices have limited telemetry; Ivy scores what MDM sees (email posture, VPN checks) and nothing more. Unmanaged devices don't get monitored — enrolling is the prerequisite.

Can we exclude specific device populations from proactive nudges?

Yes — device tag filters. Lab machines, kiosks, and shared devices typically excluded from user DMs but included in IT-ops digest. Executives can opt into higher-touch (dedicated IT ops rep instead of DM).

How is this different from what MDMs already do?

MDMs report; Ivy reasons + acts. MDM dashboard tells you 40% of the fleet is behind on OS; Ivy schedules the upgrades user-by-user off their calendars, chases the approvals, verifies success, and rolls up the fleet health for planning.

See it run on your data.

Free plan, no credit card. Connect the systems this playbook needs and run it against a past event first.