Thread
Thread
Magic Library index for Thread native skills — covering triage, dispatch, QA, closure, and client comms with no connector required.
These run natively on Thread — no connector required. This is the baseline every partner can use out of the box.
1Password Business
Run 1Password Business admin work: vault and group structure, sharing discipline, the Emergency Kit, recovery groups, and suspend-then-recover offboarding.
Abnormal Security
Triage Abnormal Security email cases: read ATO and BEC behavioral signals, treat account takeover as an identity incident, finish auto-remediation gaps.
Access Request Handling
Work an access request for a folder, calendar, DL, or shared mailbox with approval checked, least privilege applied, and expiry on temporary grants.
Access Request Intent Design
Design an access-request intent for folders, distribution lists, and shared mailboxes — capture resource, justification, and approver on intake.
After-Hours Coverage Handoff
Build the end-of-business handoff to on-call or after-hours coverage — open urgent work, expected client callbacks, and site notes the night crew needs.
After-Hours Voicemail Digest
Build a morning digest of overnight voicemails and after-hours calls — urgent items first, callbacks owed with deadlines, and which tickets were created.
Aging, SLA & Follow-Up
Sweep open tickets for real staleness by last client-facing update, separate MSP stalls from legitimate waits, nudge techs, and drive clean closure.
Agreement Profitability
Compute the effective hourly rate on an all-you-can-eat fixed-fee agreement — agreement revenue divided by logged hours — or scan for loss-making clients.
Alert Storm Merge
Collapse a burst of identical alert tickets fired within a few hours into the earliest ticket as parent, so a flapping monitor does not flood the queue.
Alert Title Normalization
Classify a monitoring or security alert ticket and rewrite its title into the desk's standard format using a controlled vocabulary, with an internal note.
APC UPS Alerts
Work APC UPS alerts: on-battery events, low runtime, self-test failure, or replace-battery indicators. Separate utility issues from UPS hardware faults.
Apology With Remedy
Draft the message when the desk genuinely failed — specific acknowledgment, concrete remedy, and one prevention step, without groveling or overreach.
Approval Request Email
Draft an email to an approver requesting authorization for a password reset, install, purchase, or access change — what/why/risk/expiry in one read.
Approver Self-Skip
Before firing an approval, check if the ticket submitter is the client's designated approver — if so, skip send_approval and advance with an audit note.
Arctic Wolf MDR
Work Arctic Wolf MDR escalations: pick up where their SOC investigation ended and split response authority between Arctic Wolf and the MSP correctly.
Atera Workflow
Atera-synced desk playbook: ticket lifecycle, resolved-vs-closed nuance, contract types (retainer, block hours, monitoring, project), labor pricing.
Auto Priority Classification
Set a ticket's priority from its title and description against the partner's own priority definitions — built for alert boards and intake flows.
Automation Completion Auto-Close
When note evidence shows an intent or external automation finished the work, verify and auto-close the ticket — abort if any human message arrives after.
Automation Opportunity Finder
Mine recent tickets for repetitive manual work, estimate hours burned per pattern, and route each finding to a flow, intent, RMM policy, or training fix.
Automation ROI Report
Judge whether live automations earn their keep with tickets touched per flow, estimated time saved, noise created, and a keep, kill, or tune verdict each.
Autotask Contract Categories
Read Autotask contract type at triage (recurring, block, retainer, T&M, fixed) to label covered vs billable and add burn-down notes on hourly deals.
Autotask Contracts Blocks
Autotask contract mechanics: block-hour burn tracking, retainer-threshold alerts, and exclusions, overlapping contracts, and expired-contract edge cases.
Autotask Merge Simulation
Autotask has no merge API: dedupe tickets via a 5-step manual sequence — verify, pick survivor, cross-note, carry history, complete the source last.
Autotask Queue Management
Autotask queue model: queues are work pools, not workflow containers — route by moving tickets between queues with correct ownership semantics.
Autotask Service Call Scheduling
Autotask Service Calls: know when work is a scheduled visit object vs a plain ticket, and follow dispatch scheduling conventions so calendars stay right.
Autotask SLA Workflow
Autotask SLA event model — First Response, Resolution Plan, Resolved — with clock-pausing statuses and breach-risk assessment for synced desks.
Autotask Ticket Categories
Classify Autotask tickets with configured Issue Type + Sub-Issue Type pairs and ticket category/type — never invent classification values not in the board.
Auvik Network Monitoring
Triage Auvik network alerts: separate device-down, interface-down, and config-change events, and use the topology map to spot cascades early.
Bad Review Response Prep
After a poor CSAT score or negative review, prepare internal talking points plus an external response draft — facts only, zero defensiveness.
Billable Analysis
When someone asks how billable hours break down by technician, client, or period, or wants to see unbilled-work exposure from time entries.
Bitdefender GravityZone
Triage Bitdefender GravityZone alerts: identify the detection layer (AV, ATC, HyperDetect, EDR) and use Risk Analytics, quarantine, and rollback safely.
Bitwarden Business
Run Bitwarden Teams/Enterprise admin work: organization and collection structure, group-based sharing, account recovery, and offboarding vault handover.
Blackpoint SOC Response
Work Blackpoint MDR SOC calls: confirm what analysts contained (host isolation, account disable), finish the response, and merge companion ticket storms.
Board Routing Rules Engine
Route catch-all tickets to the right board (NOC, procurement, security, help desk) by walking a prioritized keyword-and-signal rule list to a result.
Breached Credential Response
Handle exposed user credentials: notify the user, drive password rotation across reused sites, and verify MFA is enabled before standing down.
Bulk Onboarding Coordinator
Coordinate a multi-hire onboarding wave with one parent ticket, child ticket per hire, and a consolidated status table kept current through cutover.
Bulk Ticket Operations
Safe procedure for bulk close, reassign, or update ticket operations: enumerate, eligibility check, chunked writes, audit notes, abort on anomaly.
Business Email Compromise Recovery
Recover from confirmed BEC: kill sessions and tokens, sweep mail rules and forwarding, notify downstream victims, and trace the fraudulent funds.
Business Value Summary
Summarize value delivered to a client this period in business terms — outcomes achieved, time saved, incidents prevented — as a client-facing story spine.
CAB Brief Builder
Build the weekly change advisory board pack: pending changes ranked by risk, collision flags, and last week's change outcomes for 20-minute CAB decisions.
Catchall Routing
Identify the correct client and contact for a ticket that landed in a catchall or no-company mailbox, including forwarded mail and vendor alert routing.
CEO Service Desk Brief
An owner or CEO asks for a review of the service desk — a business-level readout with trends, risks, and a decision to make, no ticket IDs.
Change Approval Sender
Flow that fires on Change Approval status: resolve the client's Change Approver and send_approval with the change summary — note-and-stop if unresolved.
Change Calendar Management
Check a proposed change window against freeze windows, client calendars, and other scheduled changes so collisions surface before the maintenance email.
Change Request Intake
Normalize a prose change request into a structured record (what, why, scope, when, rollback, risk) and route it to the right approval track before work.
Change Request Prerequisites
Validate a change request against the prerequisites template — justification, scope, rollback, window, approver — and bounce incomplete requests itemized.
Change Risk Assessment
Classify a change request as standard, normal, or emergency by scoring blast radius and rollback confidence so approval effort matches actual risk.
Chat-to-Ticket Conversion
Capture a live Messenger chat's context into a real ticket with title, description, contact, priority, and steps tried — no repeating for the user.
Churn Save Deep Dive
Analyze a client's churn intent using full ticket history to surface what went wrong, what worked, and honest talking points for win-back calls.
Client Health Report
Summarize a client's support health for a period — volume trend, recurring issues, noisy assets, SLA performance, and a few concrete recommendations.
Client RCA Summary
Draft a client-safe root-cause summary for a resolved issue — what happened, impact, cause, and prevention — written defensively for one ticket.
Client Reply
Draft an external client reply in your house voice and format — resolution updates, status notes, closing messages, or any client-facing email on a ticket.
Client Risk Scan
Scan the client portfolio for at-risk accounts using declining sentiment, aging tickets, recurring issues, and unresolved high-priority incidents; ranked.
Closure Note Completeness
Check a ticket's closure note against the house standard — issue, cause, actions, outcome, confirmation — and draft the compliant version when it's short.
Closure Recategorization
At resolution, re-read the thread and correct the ticket's type/subtype/item and category to match the actual work, using only configured board values.
Co-Managed Reference Exchange
Keep ticket references straight across a co-managed IT boundary — recognize the other side's number format, preserve foreign refs, and audit both-way links.
Compromised Account Containment
Rapid containment checklist for a compromised account: block sign-in, revoke sessions, reset password, sweep MFA and inbox rules, timestamp steps.
Conditional Access Exception
Exclude a user, app, or location from a conditional access policy with written risk note, approval, expiry date, and revert plan documented up front.
Connector Degradation
Base skill defining how a skill behaves when an integration it wants isn't connected — do the job with what's native, name the gap, never fake the missing source.
Contract Renewal Routing
Catch renewal and expiry notices in the service queue and route them to the right sales or account manager, retitled and moved with context attached.
COO Ops Review
An ops leader asks what the team is doing well and not so well — an honest, evidence-backed operations review of the service desk.
Cork Protection Posture
Handle Cork cyber-warranty posture signals: identify the required control that slipped and restore it to compliance before warranty coverage lapses.
Courtesy Reply Status Revert
When a thanks-only client reply flips a resolved ticket back to open, revert it to the correct status per a fixed per-board map — the only permitted write.
Cove Data Protection Alerts
Work N-able Cove Data Protection backup tickets: classify the failure family, verify recoverability, and keep archive and retention sessions straight.
Credential Stuffing Response
Investigate password spraying and credential stuffing patterns: scope the attack across tenants, lock down accounts, and rotate the ones that fell.
Cross-Client Outage Detector
Spot the same symptom appearing across multiple clients within a short window, flag a possible vendor or major incident, and propose a parent incident ticket.
CrowdStrike Falcon Alerts
Triage CrowdStrike Falcon detections: parse detection anatomy, decide when Network Contain is warranted, and spot mass endpoint failures as vendor-side.
CSAT Trends Report
Track CSAT scores over time by client, technician, or ticket category with honest treatment of response rates so a 3-response month isn't shown as 300.
CSM Weekly Ritual
A CSM or vCIO weekly account runbook: proactive outreach, sentiment-decline watch, meeting prep for the week's calls, and an expansion-scan skim.
Custom Time Entry Writer
Summarize thread activity within the active timer window using a recap template, preview the draft, then log the time entry on confirm.
CW Agreement-Aware Triage
ConnectWise Manage triage: read the client's CW agreement type at intake and route or label the work as covered vs billable before anyone touches it.
CW Project Tickets
Recognize ConnectWise Manage project tickets, understand the project → phase → ticket structure, and work within what Thread sees of the Projects module.
CW Service Board Conventions
ConnectWise Manage multi-board desks: pick which board work belongs on and execute cross-board moves without losing status, classification, or history.
CW Status Workflow Mapping
ConnectWise Manage status mapping: align Thread statuses with CW board statuses, take safe transitions, reconcile closed-in-CW-but-open-in-Thread drift.
CW Sync Lag Audit
Sweep Thread ↔ ConnectWise Manage divergence — status, owner, board mismatches — separate real drift from sync lag, and reconcile with CW as the master.
CW Time Entry Conventions
ConnectWise Manage time entries that survive sync: correct work role/type, deliberate billable flag, agreement application, and plain-text notes.
CW Type / Subtype / Item Classification
Classify ConnectWise Manage tickets with the three-level Type → Subtype → Item taxonomy using only values configured on the board — never invented ones.
Dagelijkse samenvatting (Dutch)
Dagelijkse samenvatting van openstaande tickets van een technicus: wat wacht op antwoord, wat is urgent, wat staat vandaag gepland, met 3-regelvariant.
Daglig oversikt (Norwegian)
Daglig oversikt over en teknikers åpne saker: hva som trenger svar, hva som haster, hva som er planlagt i dag, med ultrakort 3-linjers variant.
Daily Digest
Summarize a technician's open tickets in under a minute with what needs a reply, what's urgent, what's scheduled today, plus a 3-line ultra-short option.
Daily Leadership Digest
A service leader asks what needs their attention today — escalations, SLA breaches, at-risk clients, and staffing flags in one short daily view.
Dark Web Alert Lifecycle
Work dark-web and credential-exposure alerts: age stale exposures, document closure notes, and notify affected users with rotation guidance.
Day Planner
Plan a technician's day around calendar and queue, honoring shift end and timezone, producing a realistic time-blocked plan and not just priorities.
De-escalation Reply
Draft the response to an angry client message — acknowledge, own what's ours, commit to a concrete next step with a time, without matching their tone.
Dead-Air Call Filter
Detect and close voice sessions that were dead air, instant hangups, or robocalls so they don't pollute the queue — human speech means it isn't dead air.
Deep Recap
Build a full ticket recap covering messages, notes, time entries, related sibling tickets, timeline, and current blockers — beyond the default summary.
Default Contact Autofill
When a ticket arrives with no contact, look up the company's documented default contact, confirm with a search, and assign under a confidence gate.
Defender M365 Alerts
Triage Microsoft Defender and Entra alerts: Safe Links or Safe Attachments detonation, suspicious inbox rules, risky sign-in. Correlate to the incident.
Defender Quarantine Ops
Review Microsoft 365 Defender quarantine items and release requests using Defender portal paths, verdict types, and disciplined release mechanics.
Defensive Writing Standard
Language standard for security writing: use when drafting client notifications, incident updates, postmortems, and alert closures to avoid overstatement.
Delay Apology
Draft an honest acknowledgment that a ticket has taken too long or a commitment slipped — apology without excuses, new commitment only if confirmed.
Delegate Access Forensics
Investigate mailbox audit logs to identify Send As, Send on Behalf, and owner actions in delegation disputes and unauthorized-email claims.
Difficult News Delivery
Draft the message no one wants to send — data loss, unrecoverable state, security exposure — factual, empathetic, and pointed at the path forward.
Dispatch & Workload
Give a dispatcher the full queue picture: unassigned tickets by priority and age, open work per tech, lightest-load proposals, and a daily audit.
Dispatch Control Tower
The dispatcher's live picture in one view — unassigned queue, at-risk tickets, today's scheduled work, and which technicians are free to pick up right now.
Dispatcher Morning Ritual
A dispatcher's board-open runbook: morning dispatch report, clear unassigned via workload balancing, SLA-risk check, and yesterday's assignment audit.
Distribution List Management
Add or remove distribution list members with owner approval and a documented reason logged on the ticket, keeping email groups clean and auditable.
DLP Alert Triage
Triage a DLP alert: separate business-process false positives from real data exfiltration signals, investigating with respect for employee privacy.
DNS Filtering Alerts
Handle DNS-filter block events from Cisco Umbrella, DNSFilter, and similar tools: separate security blocks from category blocks, keep bypass discipline.
Duo MFA Anomalies
Work Duo MFA events: fraudulent pushes, push-fatigue patterns, device re-enrollment, bypass codes. Verify identity and time-box every bypass grant.
Duplicate Hunter
Check whether a ticket duplicates an existing open ticket for the same client, contact or asset, and symptom — and merge only on an exact reference match.
Easy Win Finder
Surface quick-win ticket candidates from the queue that match the requesting technician's skills, with a short reason each one is fast to close.
Email Baseline Standard
The base client-email standard other communication skills build on — structure, tone rules, and placeholder discipline for every outbound message.
Email Header Analysis
Parse raw email headers for a spoofing verdict: analyze authentication results, the received path, and spoof indicators with explicit confidence.
Emergency Change Handling
Run break-glass discipline for an emergency change: minimal in-flight record, act-then-document, then chase full retro documentation to done in 24 hours.
Employee Offboarding
Securely disable a departing employee in the right order: sign-in and sessions first, mailbox before licenses, then reclaim access, assets, and MFA.
End-of-Day Wrap-Up
End-of-day sweep for a technician: stale tickets over 24h, awaiting-client with no follow-up, status mismatches, and tomorrow's first moves lined up.
EOD Closed Ticket Audit
End-of-day quality sweep of every ticket closed today against the closure rubric: resolution, docs, classification, time, message, with pass/fail summary.
Escalation Advisor
Sweep active tickets against L2/L3, management, and project-conversion trigger lists and recommend which should escalate — before they age into problems.
Escalation Completeness Gate
Review tickets entering Escalation Requested status against the escalation checklist and bounce incomplete ones back to the tech with itemized feedback.
Escalation Prep
Build a complete escalation package so a senior engineer, TAM, or third party can pick the ticket up cold, or recommend whether a ticket should escalate at all.
Escalation Risk Radar
Scan open tickets for the early signs of a blow-up — negative sentiment, an SLA deadline closing in, and threads that have gone quiet — score and rank them, so a senior tech can step in before a client escalates.
ESET PROTECT
Triage ESET PROTECT detections by engine, interpret LiveGuard sandbox verdicts, and recognize when a protection-disabled alert is really a policy conflict.
ESL Drafting Assistant
Grammar and idiom cleanup for technicians writing in non-native English — "fix my English" or "mejorar ingles," technical content untouched.
Exec Weekly Ritual
An owner or exec's 20-minute weekly runbook: exec scorecard, resolve one decision ask, and review what has been escalated to me across the service desk.
Expansion Opportunity Scan
Mine a client's ticket history for expansion signals — recurring issues that justify a project or upsell, and training gaps that justify a service offering.
Expectation-Setting Acknowledgment
Draft the first-touch acknowledgment on a new ticket — what we understood, how seriously we're treating it, next steps, and when the client hears back.
Field Visit Scheduler
Schedule an onsite visit and make the trip count: sweep other open onsite-worthy tickets at the same site, group travel, book, confirm the client.
First Contact Resolution Report
Report the desk's FCR rate, the share of tickets resolved by first assignee with no handoffs, with the definition stated to prevent later disputes.
Flow Backup Export
Dump every flow definition to a JSON or markdown snapshot for archive and diffing — a read-only point-in-time backup of the desk's automation, no restore.
Flow Builder
Design an automation flow from a plain-English ask — trigger, filters, actions, notification channels — with a dry-run description before it is created.
Flow Bulk Editor
List the desk's flows, present the target set, then bulk enable, disable, or rename them in one confirmed pass — no editing each flow by hand.
Flow Debugger
Diagnose why a flow or intent didn't fire on a ticket — filters vs actual attributes, flow ordering, board scoping, and trigger-event mismatch.
Flow Note Personalizer
Replace a Flow's static "add note" text with an AI step that resolves the real owner and ticket context to compose a note with actual names and specifics.
Follow-up Chaser
Draft a polite, escalating follow-up when a client hasn't replied on a ticket — first nudge, second nudge, or final pre-closure attempt with tone.
Group Membership Request
Handle a security group membership change by stating what the group actually grants, getting the right approver, and setting a review date on the change.
Halo Actions & Workflows
HaloPSA actions and workflows beyond status changes: approval actions, multi-step workflows, and which action is valid at the ticket's current step.
Halo Agent Teams
HaloPSA team and section routing: team selects the pool, agent selects the person, and unassigned-within-team is a legitimate state — not an error.
Halo Recurring Tickets
HaloPSA recurring tickets and parent/child structures: work the generated instance, never the template, and respect parent/child closure rules on sync.
Halo SLA and Priorities
HaloPSA SLA and priority interplay: priority sets response and fix targets within the client's SLA, and configured hold statuses pause the clock.
Halo Status Actions
HaloPSA transitions run through configured Actions, not raw status edits — pick the action that fires the right status, note visibility, and notifications.
Halo Sync Audit
Sweep Thread ↔ HaloPSA divergence — especially the known pattern of statuses not carrying over — and reconcile toward Halo as the master system.
Health Score Reconciliation
Reconcile a client's own health or satisfaction scores against our ticket reality — where their perception and our data agree, and where they diverge and why.
How-Do-I Self-Help Router Intent Design
Design the catch-all "how do I" self-help router intent: classify the how-to, serve the matching end-user guide or KB article, escalate only if no match.
Huntress ITDR Alerts
Work Huntress ITDR identity reports: unwanted access, rogue apps, mail-rule anomalies. Verify with the user and drive the remediation-approval flow closed.
Inbox Rule Alert Runbook
An alert fired for a suspicious inbox rule created on a user's mailbox — judge legitimacy, inventory all rules, and remove plus rotate if malicious.
Incident Commander Brief
Assemble a handoff brief for an incoming incident commander: timeline, workstream states, comms state, and the next decision point in a single read.
Incident Comms Cadence
Draft internal and client updates on a fixed clock during a major incident from ticket evidence, tracking the next-due time so the cadence never lapses.
Intake Classification Tree
Walk a new ticket through the Incident, Request, or Problem decision tree and recommend a matching type, subtype, and item for consistent classification.
Intent Builder
Build or update a customer-facing intent — trigger phrases, arguments, replies, and per-client variations — with a test plan before anything goes live.
Intent Bulk Variation Update
Apply a shared argument or reply block across every client variation of an intent at once, with per-variation diff preview and explicit write confirmation.
Intent Mining
Analyze recent tickets to find top customer-facing intents worth building, ranked by volume and automatability, with draft trigger phrases for each pick.
Intent Setup Walkthrough
Walk through building a new Triage Agent intent from scratch — check it doesn't already exist, then set the name, description, trigger variations, replies, and any arguments — so a new automatic response is set up cleanly and without duplicates.
Invoice Dispute Investigation
When a client disputes an invoice line, reconstruct the work evidence from tickets and time entries, then draft a factual response backed by the record.
IRONSCALES Phishing
Work IRONSCALES phishing incidents and user banner reports: mailbox-level detection, automated remediation, and correct model-training feedback.
JSON API Response Pattern
Base skill for machine integrations: when an external system calls Super Magic and parses the reply, respond with only a raw JSON object matching schema.
Kaseya BMS Workflow
Kaseya BMS-synced desks: navigate the status/queue/location model, respect the service-desk vs projects split, and audit Thread ↔ BMS drift regularly.
Kaseya Dark Web Monitoring
Work Kaseya Dark Web ID compromise alerts: parse alert anatomy (source, date, data classes) and run the age-and-notify lifecycle with a no-crack policy.
Keeper Password Manager
Run Keeper Security admin work: vault and shared-folder structure, role-enforced sharing, break-glass access, and offboarding via Account Transfer.
Klantantwoord (Dutch)
Extern klantantwoord opstellen in de huisstijl: oplossingsupdates, statusberichten, afsluitende berichten of elke klantgerichte e-mail op een ticket.
KnowBe4 Awareness & PhishER
Run a KnowBe4 program: awareness training, phishing simulations, and triage user reports through PhishER and the Phish Alert Button without collisions.
Known Error Database
Maintain the KEDB with every known error in one findable symptom, cause, and workaround format — deduplicated on arrival and retired when the fix ships.
Kundenantwort (German)
Kundengerichtete Ticket-Antwort in der Hausstimme entwerfen: Statusupdates, Zwischenstand, Abschlussnachricht oder jede E-Mail an den Kunden.
Kundesvar (Norwegian)
Utkast til eksternt kundesvar i husets stemme og format: løsningsoppdateringer, statusmeldinger, avslutninger eller enhver kunderettet e-post på en sak.
Laptop Return Logistics
Get a company laptop back from a departing or remote user with prepaid return label, templated email, deadline tracking, wipe verification, and escalation.
LastPass Migration
Run a LastPass migration-away: export, import to a new vault, rotate every secret, decommission the account, and handle the breach-history talk with facts.
Lead Daily Ritual
A service manager's daily runbook: leadership digest, escalation queue pass, silent-ticket sweep, and one coaching observation captured for the team.
License Cost Optimization
When someone wants to find unused, duplicate, or oversized licenses for a client and get downgrade/reclaim recommendations with a savings estimate.
License Lifecycle
Assign or reclaim software licenses by checking for unused seats before buying and leaving a billing note on every change so client spend stays accurate.
Litigation Hold
Place or manage a legal hold on a user mailbox and data with scope confirmed by an authorized requester and no user notification unless counsel approves.
Live Call Transfer Brief
One-minute brief for transferring a live in-progress call to another technician — caller context, what's been tried, sentiment alert, and a verbal opener.
Live Chat Etiquette
House rules for working a live Messenger chat — response cadence, holding messages, handoff phrasing, and ending the chat cleanly for the desk playbook.
Lost or Stolen Device Response
Respond to a lost or stolen laptop or phone: decide lock or wipe, assess exposed data and access, and drive carrier or police steps with approval gates.
M365 SaaS Backup
Work M365 and Google Workspace SaaS backup tickets: point-in-time restores, license and seat reconciliation, and job failures with authorization checks.
Mail Flow Reports
Produce periodic Exchange Online mail flow health summaries: volume trends, spam/malware catch rates, top senders, connector health, forwarding.
Mail Forwarding Audit
Inventory every mail forwarding path in a tenant or mailbox: mailbox forwarding, inbox rules, and transport rules, treating external forwarding as risk.
Mail Trace Investigation
Run disciplined Exchange Online message traces with tight timeframes, sender/recipient pairs, verdict reading, and historical traces beyond 10 days.
Mailbox Permissions Audit
Inventory Exchange mailbox access grants: Full Access, Send As, Send on Behalf, and folder-level permissions, flagging unexpected delegations.
Maintenance Freeze Windows
Record and enforce client freeze calendars (tax season, go-lives, retail peak) so freezes block change scheduling unless a documented exception is signed.
Maintenance Window Notice
Draft a planned-work client notice — what's happening, when, expected impact, duration, and rollback promise — for patching, upgrades, or migrations.
Major Incident Declaration
Run the criteria check, declare or explicitly decline a major incident, assign incident roles, and start the comms clock from one declaration checklist.
Management Escalation Brief
When a client requests escalation to management, prep the leader taking the call with a timeline, an honest account of our misses, and a recovery plan.
Meeting Prep Brief
Rapid pre-meeting brief on a client — open items, recent wins and misses, sentiment, likely topics, and landmines — for meetings starting in 30 minutes.
Merge Duplicate Tickets
Find duplicate tickets — a client who wrote in twice, a re-forwarded alert, the same issue split across threads — confirm they're really the same, and merge them into one so the desk works a single thread.
Messenger Deployment Audit
Report which clients use Messenger versus which are entitled — deployed and active vs. silent — surfacing adoption gaps worth a rollout conversation.
Messenger Outage Banner
Draft, update, and retire the Messenger client-facing incident banner with factual wording, no cause speculation, and hard expiry for stale text.
MFA Fatigue Attack Response
Respond to MFA push bombing and fatigue attacks: treat the password as known, contain the account, and enforce number-matching so approval spam fails.
Mimecast Email Gateway
Work Mimecast gateway events: held-message release requests, URL Protect click alerts, and impersonation-protect hits. Treat allowed clicks as incidents.
Monitoring Companion Merge
Merge companion tickets that multiple monitoring tools opened for the same event on one device, folding them into a single parent within a time buffer.
Morning Briefing
A start-of-day briefing across your tiered support boards — every open human ticket grouped and flagged (unassigned, aging, SLA risk), with the alert/automation noise filtered out, a quick-stats table per board, and the day's key follow-up actions, all in one scannable report.
Morning Dispatch Report
The dispatcher's start-of-day briefing: overnight arrivals, P1/P2 status, unassigned aging, today's scheduled work, and a top-10 priority work list.
Morning Huddle Builder
Build the daily standup or morning huddle message — yesterday's P1s, overnight items, today's SLA risks, and shout-outs — ready to read out or paste.
MSA Change Management
Work through what an MSA change in tier, scope, seats, or sites means operationally: desk updates, notifications, and how effective dating is handled.
Multi-Issue Ticket Splitter
Detect when one ticket bundles two or more distinct problems and split it into cross-linked sibling tickets, one purpose each, with tech confirmation.
Multilingual Reply
Draft the client reply in the client's own language — detect it from their messages, write natively, and provide an English back-translation to verify.
My Queue Summary
Summarize a technician's assigned tickets showing what needs replies, what is urgent, and what to work next, with a clear next step attached to each item.
New Client 30-Day Review
Friction check on a new client's first 30 days — early recurring issues, expectation mismatches, and onboarding gaps — fixed while the relationship forms.
New Hire Intent Design
Design the new-hire onboarding intake intent: collect the full checklist up front so the ticket arrives complete and routes into the onboarding workflow.
New Hire Onboarding
Run a new-hire onboarding end to end with role-based accounts, licenses, groups, hardware, and MFA driven from the client's own onboarding checklist.
New Ticket Approval Gate
Configured clients require the designated approver to authorize work on every new ticket — fire send_approval on intake, hold, and record the outcome.
New Ticket First Touch
One-pass first touch on a new ticket: classify it, check duplicates, pull similar resolved tickets, and draft an acknowledgment for the tech to review.
New User Created Alert
Investigate an unexpected user or admin account creation in a client tenant: check for an authorizing ticket and contain if no one can claim it.
No-Response Closure Sequence
Close a ticket after a client goes silent following three documented contact attempts: send the templated final message, close with a reopen-invite note.
Noise Auto-Close
Close pure-noise tickets — bounce-backs, vendor auto-replies, thanks-only messages, reconnected offline alerts — behind independent stop conditions.
Note Format Standard
Base skill defining the house format, tone, and plain-text PSA-sync rules for internal ticket notes. Other documentation skills reference this standard.
OAuth Consent Grant Abuse
Remove a malicious or over-privileged OAuth consent grant from a client tenant: identify the grant, revoke it, and tighten tenant consent policy.
Offboarding Completeness Audit
Post-offboarding sweep for licenses still assigned, live delegations, unreturned devices, lingering MFA methods and sessions, and external share links.
Offboarding Intent Design
Design the employee-termination intake intent with an authorized-requester check and urgency handling built in from the start for offboarding tickets.
Onboarding Plan Builder
Draft a new tech's onboarding curriculum from the desk's own resolved tickets — the request types they'll actually face, in real volume order, with practice tickets per phase.
One-on-One Prep
A manager is preparing for a 1:1, 30-day check-in, or coaching conversation with a technician and wants a candid brief on their recent work.
One-Shot Ticket Workup
Get fully caught up on an in-flight ticket with a recap, suggested next step, drafted reply, and drafted time entry, previewed before anything is posted.
Out-of-Office on Behalf
Set automatic replies on an absent user's mailbox by request: manager or HR authorization verified, message kept minimal, and an end date set.
Out-of-Scope Billing Flag
Flag a ticket that looks like work outside the client's agreement — projects, installs, non-covered users — with a quote path, not silent free work.
Outage Notification
Draft a major-incident or mass-outage client notice — known impact, what we're doing, when the next update comes — without speculating on cause.
Password & MFA Recovery
Reset a password or recover MFA with an identity verification ladder, locked-versus-disabled account check, and secure delivery of the new credential.
Password Reset Intent Design
Design the password-reset intent — the top deflection target on most desks — with an SSPR-first reply path and a strict identity-verification handoff.
Phishing Simulation Program
Plan a client phishing-awareness simulation: scope, cadence, lure difficulty, a no-shame reporting culture, and desk triage that doesn't collide.
Phishing Triage
Triage a reported phishing email without touching the payload: check blast radius, contain if malicious, and reply to the reporter with a verdict.
Phishing-Triage (German)
Phishing-Triage einer verdächtigen E-Mail: Bewertung ohne Nutzlast, Streuradius prüfen, bei Böserkennung eindämmen, Melder mit Urteil antworten.
Phishing-triage (Norwegian)
Phishing-triage av en mistenkelig e-post: vurder uten å røre nyttelasten, sjekk spredningsradius, inneslutt hvis skadelig, svar melderen med konklusjon.
Phishingtriage (Dutch)
Phishingtriage van een verdachte e-mail: beoordelen zonder payload aan te raken, verspreiding controleren, isoleren bij kwaadaardigheid, oordeel geven.
Pod-Based Dispatch
Route a ticket to the least-loaded technician in the client's assigned service pod: read the pod from company record, load-balance, assign, and note it.
Post-Churn Autopsy
After a client terminates, reconstruct causes from ticket evidence, extract lessons, and identify early-warning signals so the next churn is caught early.
Post-Incident Action Tracking
Turn post-incident review action items into real tickets with owners and due dates, then run the follow-through audit that catches ones dying in backlog.
Post-Mortem & RCA Author
Write a structured post-mortem or root-cause analysis from an incident ticket — executive summary, event timeline, impact, root cause, and action items.
Premature Confirmation Detector
Catch tickets closed on assumption without customer confirmation — work summaries treated as sign-off, closes minutes after last change — then reopen.
Price Increase Letter
Draft the client notice for an agreement price change — value-first framing, effective date, honest rationale — gated behind account-manager approval.
Printer Issues Intent Design
Design the printer-problems intent: three top self-help fixes first, then an escalated ticket that already carries the diagnostics collected from the user.
Priority Downgrade Guard
On a priority change, if AI triage lowered a priority a human or client explicitly set higher, restore the higher priority — deterministic, restore only.
Problem Record Lifecycle
Drive a problem record through its states — opened from an incident cluster, investigating, known error, then fixed or accepted-risk closure.
Problem Ticket Creation
When an incident recurs past threshold, create a problem/RCA ticket linking the incidents and documenting the workaround so the pattern gets a real owner.
Procurement Quote Request
When a ticket needs hardware or software purchased and you want a structured quote-request note (specs, quantity, budget, needed-by) plus a vendor email draft.
Project Conversion Inbox Cleanup
When a ticket is converted to a project or moved to a project board, set the attribute that removes it from live inbox and queue views so dispatch is tidy.
Project Profitability
Check whether a fixed-fee project is on budget — logged hours versus budgeted hours, burn alerts at 70% and 90%, and documented evidence of scope creep.
Proofpoint Email Security
Work Proofpoint email security events: TAP click alerts, attachment-sandbox verdicts, quarantine-digest release requests, and VAP-driven priority triage.
PSA Billing Cycle Prep
Month-end PSA billing readiness sweep: find unposted time, done-but-open tickets, and agreement anomalies before finance runs invoices — clean handoff.
PSA Closed Status Taxonomy
PSA closed-status taxonomy (ConnectWise, Autotask, HaloPSA): find every closed-family status leaking into open searches and maintain the exclusion list.
PSA Field Mapping Doc
Build and maintain a Thread ↔ PSA field-mapping cheat sheet — statuses, boards, priorities, classification values — from observed tickets, not assumptions.
PSA Migration Hygiene
PSA migrations (ConnectWise, Autotask, HaloPSA): enforce dual-running discipline — one master per phase, no orphaned tickets, clean cutover evidence.
PSA New Board Setup
New PSA board or queue setup checklist: statuses, ticket types, SLA mapping, and Thread View plus Flow implications so it syncs cleanly from day one.
PSA Note Discipline
Base skill defining how a note or reply is written when it may sync to a PSA — plain text, internal vs client-visible, and what never goes in a permanent record.
PSA Note Visibility Rules
PSA internal-vs-external note semantics (ConnectWise, Autotask, HaloPSA) with a leak-prevention checklist — a wrong-visibility note goes to the client.
PSA Taxonomy Cleanup
Rationalize PSA ticket type/subtype/category sprawl: census real usage from tickets, propose merges and retirements, enforce migration discipline first.
PSA-Is-Master Reconciliation
Generic Thread ↔ PSA reconciliation pattern (ConnectWise, Autotask, HaloPSA): rule out sync lag first, then move Thread to match PSA, never the reverse.
Quarantine Release Request
Handle a quarantined email release request: verify the requester, assess why the filter caught it, and recommend release or refusal with reasoning.
Queue Hygiene Score
Scan a queue for hygiene defects — missing contacts, stale statuses, empty notes, unassigned owners, blank classifications — with score and fix list.
Queue Scoring Triage
Produce a ranked triage order for the queue using two-layer scoring — a per-queue baseline plus per-ticket modifiers — so techs work the right ticket next.
Quote Preparation
Prepare a client quote with structured options like 1-year vs 3-year or good, better, best tiers, plus explicit assumptions ready for the sales owner.
RE/FW Reopen Detection
When a new ticket subject starts with RE: or FW: on a recently closed subject, find the closed parent and flag it as a reopen instead of working new.
Reassign Contact Submitted On Behalf Of
Catch tickets one person opened for a colleague ("submitting this on behalf of Jane") and move the ticket's contact to the person the request is actually for — so it's attributed, notified, and reported against the right end user.
Recurring Issue Report
Someone asks which issues keep coming back — chronic problems hitting the same client or device repeatedly — and whether each has a root-cause fix underway.
Rehire Reactivation
Safely restore a disabled account for a returning employee with authorization verified, old group memberships reviewed, and credentials reset fresh.
Renewal Prep
Build a pre-renewal readout for a client — service record over the term, open risks, the value story, and prep for the pricing conversation.
Reopen Forensics
Analyze why tickets reopen: patterns by technician, client, and issue type over a window, distinguishing premature closure, recurrence, and client reopens.
Resolution Closing Email
Draft the closure email for a resolved ticket — what was wrong, what we did, how to reopen — built from the ticket's actual evidence, not memory.
Respuesta al cliente (Spanish)
Redactar una respuesta externa al cliente con voz y formato de la casa: actualizaciones, notas de estado, cierre o cualquier correo del ticket.
Resumen diario (Spanish)
Resumen diario de los tickets abiertos de un técnico: qué espera respuesta, qué es urgente, qué está agendado hoy, con variante ultracorta.
RFO Letter
Draft the reason-for-outage letter a client receives after a major incident (facts, impact, remediation, prevention) written defensively for legal review.
Round-Robin Assignment
Distribute incoming tickets fairly across a named technician roster in rotation, honoring exclusion rules — runnable unattended inside a Flow.
Réponse client (French)
Rédiger une réponse client dans la voix maison: point d'avancement, note de statut, message de clôture ou tout e-mail client sur un ticket.
SaaS Alerts MDR
Triage SaaS Alerts events in M365 and Google tenants: login anomalies, mail-rule creation, file-activity spikes, privilege changes as identity-plane EDR.
Scope Pushback
Draft the reply when a client requests something outside their agreement — a helpful no showing the path to yes (quote or agreement change) with AM loop.
ScreenConnect Access
Troubleshoot ScreenConnect / ConnectWise Control access: unattended-agent health, session connectivity, and console handoff for the technician on duty.
Screenshot OCR Translate
Extract the text from a pasted screenshot — an error dialog, email, or app screen — translate it to English if needed, and summarize what it actually says.
Security Incident Postmortem
Build a security incident postmortem: executive summary, timeline, impact, root cause, and action items drawn from ticket evidence in defensible language.
Security Noise Tuning
Reduce recurring false-positive security alerts: quantify the FP rate, build an evidence pack, and recommend a retune at the source tool.
Security Vendor Generic
Handle security alerts from any vendor without a dedicated runbook: extract alert anatomy, map severity to desk tiers, build a vendor escalation package.
Sentiment Closure Report
Bucket closed tickets by sentiment score per client, tech, or period, with driver messages cited so a low score is explainable, not just a number.
Sentiment Decline Watch
Find clients whose sentiment is trending down, show the evidence and the specific conversations driving it, and draft suggested outreach for each.
Sentiment Score Explainer
Explain why a ticket thread received its sentiment score by citing the exact messages that drove it — no hand-waving, no re-scoring.
Session Token Theft Response
Respond to stolen session cookies or tokens after MFA-passed account abuse: revoke sessions and tokens system-wide, not just the user's password.
Shared Mailbox Delegation
Set up or change shared mailbox access (Full Access, Send As, Send on Behalf) with owner approval and an audit note recorded on the delegation ticket.
Shift Handoff
Produce a skimmable end-of-shift or end-of-day one-pager of open work, grouped by status, for the next shift or a single named receiving technician.
Silent Ticket Detector
Find tickets where the client replied but no technician responded within threshold — surface each with wait time, @mention the tech, and draft a reply.
Single Ticket Handoff Card
Hand one ticket to another technician with a compact card — status table, watch points, overdue-task detection, and a one-sentence next action.
Site-Aware Approval Routing
Resolve a ticket's site, look up the per-site approver from a documented mapping, and send the approval request to that contact — not one hardcoded name.
Skill Authoring Coach
Help a member write a good Super Magic skill: sharpen the description into a real trigger, structure the workflow, and add the guardrails it needs.
Skill-Based Routing
Route a ticket to the technician with demonstrated expertise — who resolved similar issues for this client or this stack — not just whoever is free.
SLA Analytics
Someone asks how the desk is doing against SLA — first-response and resolution performance versus targets, and which tickets breached and why.
Smart Dispatch
Composite dispatcher skill: classify a new ticket, consult a routing matrix of tech specialties and client familiarity, then assign and schedule.
SOC Classification Tree
Classify a security ticket down the Incident, Request, and Problem tree and set type, subtype, and item consistently for reporting and routing.
SOC Client Email Pack
Pick the right client-outreach template for a security event (leaked credentials, BEC, inbox rule, lookalike domain) and draft with verified facts only.
SOC Shift Handoff
Hand off open security investigations at shift change: evidence state, containment progress, and watch items so the next shift can act immediately.
SOW Drafting
Draft a brief scope-of-work from ticket or project context with deliverables, assumptions, exclusions, and a T&M vs fixed pricing recommendation attached.
Spam Sender Triage
Close tickets from known-spam senders and patterns after verifying a human did not forward the message in for investigation or phishing analysis.
Staffing Model Analysis
Someone asks whether the desk is staffed right — ticket arrival patterns by hour and day versus coverage, and where the desk is under- or over-staffed.
Stakeholder Map
Map who matters at a client — contacts organized by role and influence as evidenced in ticket interactions — and where our relationship coverage has gaps.
Stale Ticket Follow-Up Cadence
Drive a configurable 24/48/72 follow-up cadence on tickets awaiting client reply: draft each friendly nudge, count attempts, skip legitimate waits.
Status Check Intent Design
Design the "any update on my ticket?" intent: answer from real ticket status and last client-visible update, escalating only when the trail has gone cold.
Status Nudger
Chase tickets stuck in a waiting status — re-send the pending approval or post the templated client nudge, never nudging twice inside one window.
Status Update Messenger
One command sets the ticket status and posts the matching templated client message from a per-status map, so status and note change together.
Super Magic Enablement
Prep a show-and-tell of the highest-value Super Magic use cases for a specific team, grounded in their own recent tickets so every example is recognizable.
Sweep Honesty
Base skill defining how a skill reports on a search or bulk sweep — result caps, what it could not see, and never presenting a partial pass as a complete one.
Syncro Workflow
Syncro PSA-RMM idioms: tenant-configured ticket statuses, worksheets as embedded checklists, ever-running timer culture, and RMM alerts inside the desk.
Synology NAS Alerts
Work Synology NAS alerts: degraded RAID or storage pool, disk-health warnings, full volumes, DSM updates. Treat a degraded array as near data loss.
Synthèse quotidienne (French)
Synthèse quotidienne des tickets ouverts d'un technicien: qui attend réponse, ce qui est urgent, ce qui est planifié aujourd'hui, variante 3 lignes.
Tagesübersicht (German)
Tagesübersicht offener Tickets eines Technikers: was auf Antwort wartet, was dringend ist, was heute geplant ist — inklusive 3-Zeilen-Variante.
TeamViewer Access
Troubleshoot TeamViewer remote access: host and agent health, unattended access, session connectivity, and the commercial-use-detected flag on handoff.
Tech End-of-Day Ritual
A technician's close-of-day runbook: EOD wrap-up, time-entry compliance self-check, and lining up tomorrow's first move before logging off for the day.
Tech Morning Ritual
A technician's 15-minute start-of-day runbook: digest, schedule check, easy-win pick, and a first-response sweep before diving into ticket work.
Tech Performance Review
A manager asks to evaluate a technician's performance over a period — closed, assigned, reopened, time logged, sentiment — with coaching angles, not a verdict.
Tech Utilization Report
Report billable utilization per technician — logged billable hours against capacity — with role-aware targets and framing as workload economics, not worth.
Technical to Plain English
Translate a technical resolution, diagnosis, or explanation into language a non-technical stakeholder can understand — "make this client-friendly."
Technician Availability Check
Answer who is the next available technician by combining today's schedules, priority-weighted open load, and shift or PTO context into a ranked answer.
ThreatDown Malwarebytes
Triage ThreatDown (Malwarebytes) detections by class — malware, PUP, PUM, exploit — and run the remediation-verification pass the remediated status skips.
ThreatLocker Allowlisting
Work ThreatLocker approval and elevation requests: triage daily allowlisting safely, keep Learning vs Secured mode straight, protect zero-trust posture.
Three Strikes Final Email
Draft the final "we're closing this ticket" email after three documented contact attempts with no client response — only when evidence exists.
Ticket Export for LLM
Produce a clean, sanitized, self-contained export of a ticket for pasting into another AI tool — credentials and PII stripped, context preserved.
Ticket Intake & Formatting
Build a clean ticket title and description from a raw report, voicemail, email, form submission, or rough technician notes, following the house intake standard.
Ticket QA Review
Grade a completed ticket against the closure rubric — resolution, classification, owner, time logged, title, client message — pass or bounce it back.
Ticket Review Training
Turn a real resolved ticket into a sanitized teaching case with what was done well, what could improve, and the transferable lesson for team review.
Ticket Summary & Closure Note
Produce a clean ticket summary as a resolution note, closure note, or templated P1/P2 handoff — in the requested format and point of view.
Ticket Triage
Classify a new or unassigned ticket, gauge severity, catch duplicates, and route it to the right board, status, and priority for the queue.
Tickets to Opportunities
Mine recent service tickets for expansion signals, surfacing work that became or should become a sales opportunity, in a per-client opportunity report.
Tier Dispatcher
Dispatch a new ticket by support tier: classify T1/T2/senior, check that tier's technicians against today's schedule, then assign and book the work around the customer's deadline.
Time Entry Cleanup
Turn raw, rough time notes into clean, standardized time entries with client-facing and internal versions, recording only work explicitly stated as done.
Time Entry Revenue Audit
When someone wants to find tickets that were worked with no time logged — revenue leakage by technician or period — and get the gaps fixed the right way.
Todyl Platform
Route Todyl alerts by plane: SASE network, endpoint EDR, or identity and SIEM detection. Each plane needs a different runbook from the same platform.
Tone Polish Rewrite
Rewrite rough technician text into a polished, client-ready version — "write this nicely," "clean this up" — preserving every fact exactly.
Travel Access Window
Open a temporary conditional access exception for a traveling user with automatic expiry and a tracked revert task so location policies stay in place.
Trend Micro Worry-Free
Triage Trend Micro Worry-Free alerts by engine (signature, ML, behavior, web reputation) and know when a client is on Apex Central or Vision One instead.
Trend Root-Cause Mining
Find what is driving ticket volume and making the desk busy by mining recent tickets for top recurring issues and root causes across a chosen period.
Triage Agent Tuning
Tune Triage Agent custom rules from observed misses — wrong boards, wrong priorities, tickets it should have left alone — plus bypass-word usage analysis.
Triage d'hameçonnage (French)
Triage d'hameçonnage d'un e-mail suspect: évaluer sans toucher la charge, mesurer le rayon d'exposition, contenir si malveillant, répondre au déclarant.
Triaje de phishing (Spanish)
Triaje de phishing de un correo sospechoso: evaluar sin tocar la carga, medir radio de impacto, contener si es malicioso y responder al reportante.
Unattended Output Discipline
Base skill defining the output contract for any prompt or skill that runs unattended inside a flow, where the agent's entire reply is posted verbatim.
Vacation Handoff Pack
Pre-PTO handoff prep listing which tickets need transferring, which need watching, and a per-ticket one-liner brief so cover techs can act fast.
Variation Author
Interview the admin on client-specific troubleshooting differences (printers, VPN, LOB apps), then encode them as intent variations with a test plan.
vCIO Weekly Proactive
Pick the three highest-leverage clients to proactively contact this week from live ticket signals, with a reason and a suggested opener for each outreach.
Vendor Fraud BEC Alert
Respond to a BEC or payment-fraud attempt (fake invoice, banking-change request, exec impersonation): freeze payments and run callback verification.
Vendor Outage Checker
Check vendor status pages and outage reports for M365, ISPs, and SaaS apps, then post sourced findings to the ticket to confirm is it down for everyone.
View Builder
Create or duplicate an inbox view from a plain-English spec — "open P1s", "the dispatch view filtered to a client" — saved filters and view variants.
VIP Priority Handling
Detect VIP contacts and VIP clients at ticket intake, apply the configured priority bump, and fire notify rules without letting VIP status skew triage.
Voice Call QA Review
Review AI-handled voice calls against a rubric — caller identified, issue captured, commitments accurate, clean handoff — with transcript evidence cited.
Voice Catchall Identification
Identify the client and contact behind an unknown caller on a voice ticket with only a phone number, using number, name, and company clues from transcript.
Voice Transcript Intake
Turn a pasted call transcript into ticket action — extract caller, client, issue, and commitments, then create or update the ticket with a time entry.
Voicemail to Ticket
Convert a voicemail transcription into a ticket with a callback commitment — urgency read from what the caller actually said, not from tone guesses.
VPN Issues Intent Design
Design the VPN connectivity intent: a short self-help ladder plus environment capture — client, location, error text — so escalations arrive diagnosable.
Waiting-on-Client Audit
Audit every ticket parked in a waiting status: how long, whether a follow-up was sent, and the correct next action — nudge, reschedule, unpark, close.
Weekly Ops Report
A service manager wants the weekly service-desk report — team volume, closures, sentiment, aging, and anything anomalous versus the prior week.
Wire Fraud Verification Protocol
Callback verification for any payment change request: banking updates, new wire instructions, or payroll redirects — verify out-of-band, no exceptions.
Workaround Documentation
Document a workaround in the standard format (steps, hold time, cost, expiry review) and label the ticket workaround-only so nobody mistakes it for a fix.
Workload-Balancing Assignment
Assign a ticket to the tech with the best availability score — base capacity minus open tickets minus scheduled blocks — with math shown, runs in Flows.
Write Guardrails
Base skill defining the gates that sit in front of any action that changes something — confidence bar, show-me-before-send, when-in-doubt-do-nothing, and never invent data.
XLA Breach Risk Tiering
Tier every open ticket by XLA exposure — Breached, Critical, High, Watch — from remaining time to target with escalation factors and a next move.
Zero-Touch Opportunity Mining
Someone asks where the biggest opportunities are to increase zero-touch resolution, or which ticket patterns should become intents or flows.
Was this page helpful?
⌘I