Managing ITSM Tickets from the AI Agent
Use the AI Agent to look up, comment on, reassign, and close the ITSM tickets Axonius already knows about, without leaving the chat.
Prerequisites
- An adapter connection to a ticketing system, such as Jira or ServiceNow. The agent works only with tickets that have already been fetched into Axonius. These tickets are listed on the Tickets page. Tickets created between fetches appear after the adapter's next fetch.
- To look up tickets, your role needs the View tickets permission.
- To update tickets, your role needs the Action Center Add and import, and Run permissions.
- The agent can update tickets in Jira, Jira Software, ServiceNow, Zendesk, and Cherwell. Freshservice, BMC Helix, SysAid, and ManageEngine support ticket creation only.
Looking Up Tickets
Ask the agent about tickets by key or by asset, for example:
- "What is the status of PROJ-123?"
- "Did my ticket land?"
- "Which of these security findings already have a ticket?"
For each ticket, the agent shows the key, status, summary, assignee, a link to the ticket in the ticketing system, and the linked assets. One request covers up to 25 ticket keys or 100 assets.
When a key isn't in Axonius yet, the agent tells you the ticket hasn't been fetched, rather than reporting that the ticket doesn't exist. The ticket appears after the next fetch.
Changing Tickets
-
Tell the agent what to change: a new status, a comment, a new assignee, or any combination. Name the status as it appears in your ticketing system. For example, "Done", "Resolved", or "Closed". To list the statuses you can set, ask the agent.
- Jira lists the transitions the adapter saw during its last fetch.
- ServiceNow lists the incident State values.
- Zendesk and Cherwell accept new, open, pending, hold, solved, and closed.
-
Tell the agent which tickets to change:
- Specific tickets by key, up to 25 from one ticketing system per request.
- The tickets linked to devices, users, Security Findings, software, or cases from an earlier answer in the conversation, up to 100 assets. Choose all linked tickets or only the latest ticket per asset.
-
Review the preview. It lists every ticket with its summary and current status (or the exact asset scope), the new status, the assignee, and the comment word for word, with a warning that the change reaches real tickets in your ticketing system.
-
To apply the change, click Approve on the card or Cancel to discard it. The agent reports whether the run succeeded, failed, or is still running, and links to the one-time Quick Action enforcement set that carried the change.
The agent never changes a ticket as a side effect of answering a question, and never combines a ticket change with another write in the same turn.
Closing Tickets for Fixed Findings
Two new starting cards in the chat cover the most common flows:
- Ticket Status Check: which of your critical security findings already have a ticket, and each ticket's current status.
- Close Tickets for Fixed Findings: finds the tickets whose security findings are now Closed in Axonius, verifies the fix, and closes those tickets with the evidence as a comment, showing you every ticket first.
Before closing a ticket, the agent verifies the fix in Axonius: the finding's Axonius Status is Closed and the scanner still covers the asset. A ticket marked Done is never proof that a finding is fixed; when a ticket is Done, but its finding is still open, the agent offers to reopen the ticket with a comment instead.
The Remediation Tracking Virtual Employee can also close the tickets it flags as closable when an administrator enables that write action in the Virtual Workforce Control Panel; in Shadow mode, it runs previews of the change without applying it.
Controlling Ticket Changes for the Agent
The agent tool permissions gain two Action Center tools (what does "gain two action center tools" mean??): Get Tickets (read) and Update Ticket (write). By default, Update Ticket requires your approval on every change; administrators can change that default or block the tool.
"gain two Action Center tools (what does it mean??)" — from the reader's side: two tools appear under the Action Center category on the AI Agents tool-permissions page: Get Tickets (read) and Update Ticket (write). Update Ticket requires approval on every change by default; an administrator can change that default or block the tool.
Updated about 4 hours ago
