VivoLearn

Information Systems & IT

Business IT is a factory that produces trust artifacts: tickets resolved, access granted and revoked, alerts dispositioned, integrations that move data correctly, contracts renewed on defensible terms. Almost every process runs on structured, logged, high-volume work — ideal AI terrain — but the artifacts that matter most (an access grant, a production change, a containment action) are exactly the ones where a wrong move is expensive or irreversible.

The thesis · automate the reading and the drafting aggressively, keep humans on the writes to production and identity — and remember that AI agents are now themselves IT assets that need accounts, permissions, and offboarding like any employee.

Filter stages:

IT Service Desk (ITSM)

continuous / per-ticket

ticket → triage record → resolution (or escalation) → knowledge base article → problem/trend report

  • Automate
    Intake & self-service deflectionconversational agent resolves password resets, how-tos, and known issues directly against the KB and identity system · huge volume, low stakes, and success is verifiable — the user confirms it worked or the ticket reopens
  • Automate
    Triage & routingclassify category, urgency, and assignment group from free-text tickets · repetitive and cheap to correct; a misroute costs minutes, not money
  • Draft
    Diagnosis & resolution draftingAI surfaces similar past tickets and drafts fix steps for the technician · context is rich in ticket history, but executing changes on someone's machine needs an accountable human
  • Assist
    Identity-sensitive requests (credential resets on privileged accounts, MFA re-enrollment)AI assembles verification context only; a human verifies the caller · helpdesk impersonation is now a top intrusion vector, and a fraudulent reset is close to irreversible
  • Draft
    KB article generationturn resolved tickets into draft articles automatically · verifiable by the resolving tech, and unpublished bad drafts cost nothing; unreviewed published ones poison future deflection
  • Draft
    Problem management & trend reportingcluster recurring tickets into problem candidates with evidence · pattern-finding at volume is AI's strength; deciding what's worth a root-cause project is a resourcing call
Tools (2026)
ServiceNow Now Assist, Jira Service Management (Rovo), Freshservice Freddy AI, Moveworks, Glean
Failure mode
The bot closes tickets with plausible KB answers that don't actually fix the issue, users quietly give up on reporting, and the deflection metric improves while the real problem count goes dark.
Try it
Take 50 sample help-desk tickets (provided), build a triage prompt that outputs category/urgency/assignment, run it, and score its accuracy against the real routing — then rewrite the prompt to fix its worst error class.

Identity & Access Management

per-request, plus quarterly access certifications

access request → risk/policy assessment → approval decision → provisioning change → certification record → audit evidence

  • Draft
    Request interpretation & policy lookuptranslate "I need what Maria has" into specific entitlements, check role fit and segregation-of-duties conflicts · rules-heavy and checkable against the role model, but the output shapes a consequential decision
  • Automate
    Birthright & low-risk provisioningauto-grant standard packages on HR joiner/mover events · pure rules, fully logged, and revocable in seconds
  • Assist
    Privileged and sensitive grantsAI compiles a risk brief (who, what, precedent, SoD flags); a named human approves · high stakes plus regulatory exposure — SOX and auditors want a human name on the grant, and over-provisioning is how breaches escalate
  • Draft
    Access certification campaignspre-flag dormant accounts, outlier entitlements, and peer-group anomalies so reviewers judge exceptions instead of rubber-stamping lists · turns an unverifiable checkbox ritual into reviewable claims; humans still sign the certification
  • Automate
    Offboarding deprovisioningtrigger and verify revocation across all systems on termination · the risk runs the other way: the irreversible harm is the account you *don't* kill, and completeness is machine-checkable
  • Assist
    Non-human identity governanceinventory service accounts, API keys, and AI-agent credentials; flag over-scoped or orphaned ones · the fastest-growing identity population is agents, context on "what does this agent actually need" is scattered, and revoking blind breaks production
Tools (2026)
Okta Identity Governance, Microsoft Entra ID Governance, SailPoint Identity Security Cloud, CyberArk, Astrix Security
Failure mode
Approval drift — AI risk summaries are so consistently reasonable that approvers stop reading them, and the human gate on privileged access becomes ceremonial exactly where it matters most.
Try it
Given a spreadsheet of 200 user-entitlement pairs with roles and last-used dates, have AI flag revocation candidates with reasons, then run a mock certification meeting where students must defend or overturn ten of its calls.

Security Operations

continuous

alert → enriched investigation → incident record → containment action → post-incident report → detection rule update

  • Automate
    Alert triage & enrichmentauto-correlate alerts, pull asset/user context, reputation lookups, and prior-incident history; close known benign patterns · thousands of alerts a day, enrichment is verifiable lookup work, and a wrong close is recoverable while the log trail exists
  • Draft
    Investigation narrativeassemble a timeline across endpoint, identity, and network logs in plain English · AI reads logs faster than any analyst, but the narrative frames every downstream decision, so an analyst owns it
  • Assist
    Containment execution (isolate host, disable account, block domain)AI stages the action with blast-radius analysis; a human fires it · technically reversible but business-disruptive — isolating the wrong server or CEO's account mid-quarter is a stakes problem, not a capability problem
  • Automate
    Phishing responseverdict reported emails, purge confirmed campaigns from all mailboxes, notify targets · high volume, narrow well-understood action, easily undone
  • Draft
    Detection engineeringdraft new detection rules (KQL/Sigma) from incident findings and threat intel · rules are testable against historical data before deploy, which makes the AI output cheap to verify
  • Draft
    Post-incident reportinggenerate the incident report and regulator/customer notification drafts from the case record · regulatory exposure means counsel and the CISO own the wording; AI just eliminates the blank page
Tools (2026)
Microsoft Sentinel + Security Copilot, CrowdStrike Falcon (Charlotte AI), SentinelOne Purple AI, Tines, Abnormal Security
Failure mode
Attacker-shaped inputs — log noise, decoy activity, or outright prompt injection in telemetry — steer the triage agent to auto-close true positives, industrializing the very alert-fatigue blindness it was bought to fix.
Try it
Give students 20 mixed alerts (5 real attacks, 15 benign), have AI produce a triage verdict and one-paragraph justification for each, and grade the AI — arguing every disagreement against the answer key.

SaaS Portfolio & Vendor Management

continuous discovery; renewal-driven negotiation cycles

usage & spend data → application inventory → rationalization recommendation → renewal brief → contract/DPA → sanctioned-tool policy

  • Automate
    Shadow IT & shadow AI discoveryreconcile SSO logs, expense lines, and network telemetry into a live app inventory, flagging unsanctioned AI tools where employees may be pasting company data · pure cross-referencing at volume, and every finding is verifiable against source records
  • Automate
    License utilization analysismap paid seats to actual usage per app · mechanical, high-volume, and wrong answers surface immediately when checked
  • Draft
    Rationalization recommendationspropose consolidations and cuts with overlap analysis and switching-cost estimates · the data work is AI-shaped, but usage counts miss load-bearing niche apps, so an owner validates before anything dies
  • Draft
    Vendor security & AI-clause reviewextract SOC 2 findings, data-processing terms, and model-training/data-retention clauses from vendor paperwork into a comparison grid · extraction is checkable against the document; judging acceptable risk is legal's and security's call
  • Assist
    Renewal negotiationAI builds the leverage brief (usage, benchmarks, alternatives, contract asymmetries); humans negotiate · negotiation is a relationship game with a counterparty, the classic rules-vs-relationships boundary
  • Assist
    Sanctioning decisions & AI-use policydecide what's approved, tolerated, or blocked, including which AI agents may touch which data · low volume, high organizational stakes, and it's a governance judgment the CIO must own
Tools (2026)
Zylo, Zluri, Productiv, Vertice, Netskope (shadow-AI discovery)
Failure mode
AI recommends killing an app with near-zero logins that turns out to run one critical quarterly process, and the "savings" costs a week of finance-close firefighting.
Try it
Hand students an anonymized SSO-plus-expense export, have them use AI to build an app inventory with overlap clusters and a one-page kill/keep/consolidate recommendation, and present the three most defensible cuts.

Systems Integration & Workflow Automation

per-project builds; continuous maintenance

process map → integration spec (field mappings, triggers, exceptions) → workflow build → test evidence → production cutover → runbook

  • Draft
    Process discovery & mappinginterview notes and screen recordings become a documented as-is flow with systems and handoffs · AI structures messy input fast, but only the process owner knows which undocumented exception is the real process
  • Draft
    Field mapping & transformation specpropose source-to-target mappings with sample-data validation · directly verifiable against real records, which makes AI's speed nearly free to check
  • Draft
    Workflow buildgenerate the iPaaS recipe or automation from the spec in a sandbox · low-code platforms make the output inspectable and testable by a non-engineer before it touches anything real
  • Automate
    Test-case generation & sandbox executionenumerate edge cases (nulls, duplicates, malformed dates, retries) and run them against sample payloads · testing is the definition of verifiable work, and sandbox failures cost nothing
  • Avoid
    Production cutoverenabling live writes to systems of record · bad writes to the ERP or CRM propagate downstream and are painful to unwind — a human flips the switch after reviewing test evidence, ideally with a human-approval step left inside the workflow
  • Assist
    Exception handling & maintenanceAI drafts diagnosis when a workflow errors; a human applies the fix · each failure is novel and low-volume, and the fix is itself a production change
Tools (2026)
Workato, Microsoft Power Automate, Zapier (incl. Zapier Agents), Make, n8n
Failure mode
A workflow that passed every happy-path test silently corrupts records at machine speed when real-world edge-case data arrives — automation doesn't make mistakes occasionally, it makes them at scale.
Try it
Build a working two-system automation (form submission → AI-enriched record → spreadsheet/CRM) in Zapier or n8n with an explicit human-approval step before the write, and deliberately feed it three malformed inputs to see what breaks.

Infrastructure Monitoring & Incident Response

continuous monitoring; incidents ad hoc

telemetry → correlated alert → incident channel & timeline → remediation change → status communications → postmortem

  • Automate
    Anomaly detection & alert correlationcollapse alert storms into one probable incident with affected services · this is statistics over high-volume telemetry, and a bad correlation is instantly visible to responders
  • Draft
    Incident summarization & commsmaintain a live timeline and draft status-page/stakeholder updates during the incident · AI keeps up with a fast channel better than any scribe, but a wrong public statement is a trust event, so a human posts
  • Draft
    Root-cause hypothesiscorrelate the incident with recent deploys, config changes, and dependency status to rank likely causes · genuinely strong AI territory because the change log is machine-readable, but hypotheses must be labeled as hypotheses
  • Automate
    Runbook remediationexecute pre-approved actions: restart the service, roll back the flagged deploy, scale out · bounded, rehearsed, reversible actions with humans spot-checking — this is what runbooks were always for
  • Avoid
    Novel production changes under pressureuntested fixes outside the runbook during an active incident · lowest-context, highest-stakes moment in all of IT; an AI-suggested "fix" applied at 2 a.m. is how outages become data-loss events
  • Draft
    Postmortem authoringassemble the blameless postmortem from the channel, timeline, and change records · the evidence-gathering is mechanical; the lessons and action items need the humans who were there
Tools (2026)
Datadog (Bits AI), PagerDuty AIOps, incident.io, Grafana Cloud, New Relic
Failure mode
A fluent, confident, wrong AI root-cause narrative anchors the whole response team on the wrong system for an hour — the cost isn't the bad guess, it's the borrowed credibility.
Try it
Give students a synthetic incident packet (alert stream, chat log, deploy history), have AI produce a timeline, root-cause hypothesis, and postmortem draft, then compare against the ground-truth cause and mark exactly where the AI's narrative went beyond its evidence.

Source: Directing Intelligence course field guide, 2026. Tool lists are dated on purpose — they churn; the stage verdicts and their blockers are the durable part. Spot something the frontier has dissolved? Contribution is coming; for now, open an issue or PR on GitHub.