Use case · AI ITSM Agent

App access requests, approved in Slack

An employee asks for an app in Slack. The AI ITSM Agent checks your written policy, asks the right approver, grants the access and takes it away again when the time is up.

Last updated 6 October 2026

The problem

Access requests are the most common IT ticket, and most of them follow the same few rules: who is allowed to ask, who has to approve, and for how long.

Done by hand, each one waits in a queue for someone to read the policy, chase the manager and click through the identity provider. Access that was meant to be temporary is often never removed.

How the AI ITSM Agent does it

  1. 01

    The employee asks in plain words

    "I need Figma for the design review." It recognises who is asking from your identity provider, so they don't fill in a form.

  2. 02

    Your policy decides, not the model

    It looks up the access policy for that app: who may ask, who approves and the longest access allowed. If the person may not ask, it says why.

  3. 03

    The approver answers in Slack

    The approver the policy names gets a card with who is asking, why, and the rule that asked them. They approve or deny with one tap.

  4. 04

    Access is granted and timed

    It assigns the app or group in Okta, replies in the thread and schedules removal for the end date.

  5. 05

    Everything is recorded

    Who asked, who approved, what changed and when it ends, ready for your next audit.

Example

“I need access to Figma for the design review.”
AI ITSM Agent
Figma Professional needs your manager's approval under the Design Tools policy. I've asked Jordan Park. Access ends on 5 November.
Example with fictional names.

Guardrails

  • Approvers come from your policy, never from the AI's judgement.
  • Nothing is approved automatically when an approver doesn't answer; it reminds them and escalates.
  • Temporary access is removed on the end date without anyone remembering to do it.

Works with

SlackOktaJira (hand-off to a person)

See the AI ITSM Agent do this with your own tools.

Book a demo

Questions

What if an app has no policy yet?

The request goes to your IT team with the person, the app and the reason already filled in. Writing a policy for that app lets the next request run on its own.

Can access be time-limited?

Yes. Each policy sets the longest access allowed, and access is removed automatically when it ends.

Which identity providers does it work with?

Okta. Book a demo to talk through your setup.

Hire your first AI employee

Tell us which team needs one, and we'll show you how it works with your tools.