ITSM Automation: Where to start and what to skip
Learn which IT support workflows are worth automating first and what end-to-end automation looks like in practice. This guide also shows how to expand automation without replacing your existing ITSM.

So, you’ve got approval to automate more IT support workflows. But which ones should you automate first?
Starting with the most common type of request may seem like the best option. The problem is that high volume doesn’t always mean low risk. Some routine Tier-1 requests need very little oversight, while others involve approvals or actions that are harder to reverse.
Another common mistake is automating only the first part of the process. If an employee can request software access in Slack but IT still has to chase approval, grant access, and update the ticket, most of the work remains manual.
A better way to choose what to automate first is to weigh request volume against the potential impact of an incorrect automated action.
This guide shows you how to use your ticket data to prioritize workflows. We’ll also explain what you need to automate them safely, and walk through how common IT workflows can be automated from request through to resolution.
TL;DR
- Start with workflows that create a lot of manual work but carry relatively low risk. Higher-risk workflows can still be automated, but they need stronger approval and audit controls.
- The biggest gains come from automating the full workflow, including the action itself, rather than only automating intake or routing.
- Password and multi-factor authentication (MFA) resets are usually good early candidates because the process is clear and reversible. Access requests can also be valuable to automate when approval rules and audit requirements are built in.
- Some requests still need human judgment, while sensitive actions may only need a person to approve them before the system carries them out.
- Risotto can automate more IT work without replacing your current ITSM, so Jira, Freshservice, ServiceNow, or Zendesk can remain the system of record.
The key components of an ITSM automation stack
Before you decide which workflows to automate, first map out what needs to be in place for that automation to work end to end.
Most ITSM automation setups have six core components.
These components need to work together if the automation is going to resolve a request rather than simply route it somewhere else.
For example, an AI tool that identifies an access request and sends it to IT has automated intake. An agentic ITSM platform can continue through the configured workflow, apply the required approvals, take action in connected systems, and update the ticket once the work is complete. That’s what turns AI-assisted support into end-to-end automation in ITSM.
How to rank your workflows: volume against risk
As we mentioned above, the workflow with the most tickets isn’t automatically the best one to automate first. To choose where to start, compare how much manual work each workflow creates with the risk involved in automating it.
Export the last three months of tickets from your ITSM platform and group them by request type or workflow. For each group, record:
➡️Volume: How many tickets do you receive each month, and what share still needs manual work from IT?
➡️ Risk: How much damage could an incorrect action cause, and what controls would you need before automating it?
To assess risk, ask four questions:
- What would happen if the wrong action were carried out? The more serious the consequence, the higher the risk. For example, giving an employee incorrect troubleshooting guidance may waste time. Granting the wrong person access to a sensitive system could create a security or compliance issue.
- How easy would it be to undo the action? Workflows are safer to automate when mistakes can be corrected quickly. Temporary access can be revoked, for example, while wiping a device is much harder to recover from.
- Does someone need to approve it first? If so, that approval needs to be built into the workflow before the action can happen.
- Do you need a compliance record? Some actions need an audit trail showing who requested them, who approved them, and what happened.
Once you’ve assessed each workflow, place it in one of four quadrants:
This gives you a shortlist based on the work your team is actually handling.
A high-volume workflow that’s still mostly manual and easy to undo is a strong first candidate. Higher-risk workflows can still deliver a lot of value, especially when they’re common, but they need the right approvals and guardrails in place before you automate them.
Which workflows should you automate first?
Now that you’ve ranked your own workflows by volume and risk, let’s look at how that framework applies to common ITSM requests.
The examples below cover some of the most useful IT service desk automation ideas, and show which types of work are usually easier to automate first and which need stronger controls.
Here’s what that looks like in practice.
Password and MFA resets
Password resets and MFA re-enrollment are strong early candidates for automation because they follow a clear process and mistakes can usually be corrected quickly.
The process works as follows: an employee asks for help, their identity is verified through the identity provider (IdP), and the reset or re-enrollment is completed through a connected system such as Okta. If the workflow can’t be completed, the request is escalated to IT.
These requests typically don’t require an approval chain, which makes them easier to automate safely.
Thinkific shows the potential of automating this kind of Tier-1 work as part of a wider support queue. The company was handling close to 300 Tier-1 requests a month across access, password resets, and policy questions, and reached a 46% automation rate.
Software access requests, provisioning, and deprovisioning
According to our research, access requests account for roughly 17% of support tickets overall, and in some organizations they make up a much larger share of the queue.
Access requests carry more risk than password resets because an incorrect approval could give someone access to systems or data they shouldn’t have. The workflow therefore needs to check the company’s access rules and get approval where required before granting access.
A fully automated software access workflow looks like this:
- The employee submits an access request through the company’s support channel.
- The system identifies the application and checks the company’s access rules.
- It requests approval from the appropriate person or group where required.
- Once approved, access is provisioned in the relevant application.
- Any time limit is applied, and the actions are recorded against the ticket.
- When that access is no longer needed, it can be removed automatically based on the expiry date or another approved trigger.
The approval path can change depending on who is requesting access and which application they need.
Risotto, for example, can route approvals to the appropriate manager or group and apply time-based access with automatic expiry. The resulting actions are also captured for audit purposes.
Automation only works end to end if it can grant access in the applications employees use. Apps outside your single sign-on (SSO) setup may need a separate ITSM integration or workflow. Otherwise, IT still has to provision access manually.
When approvals and provisioning are connected, a large share of software access requests can be automated.
Ironclad reached a 91% auto-solve rate across software access spanning 40 to 50 applications. Trust & Will, meanwhile, automated provisioning across more than 30 applications with 24/7 coverage, with 35% of tickets automatically processed.
Onboarding and offboarding
Onboarding and offboarding are more complex to automate because each one connects several smaller workflows. A new hire might need an account created in the identity provider, access to the right applications, and hardware assigned. Information from the HR system can determine when the process starts and what access the employee needs.
A practical way to approach this is to automate the individual steps first. Once account creation, software provisioning, and other component workflows are working reliably, they can be connected into a wider onboarding process.
For example, a new-hire record in the human resources information system (HRIS) could trigger account creation and application access based on the employee’s role, while any hardware requirements move into the appropriate IT workflow.
Onboarding automation can also reduce the number of basic questions new hires send to IT. At Shakepay, for example, new hires use Risotto to get instant answers to common questions, which has accelerated onboarding, and reduced reliance on IT and security for troubleshooting.
Offboarding needs tighter controls. Access often has to be removed at a specific time, and some actions are difficult to reverse. The workflow therefore needs a reliable trigger and the right checks before sensitive actions are carried out.
Device requests and device actions
Device-related workflows vary significantly in risk, so the safest place to start is with routine requests where an incorrect action would have limited impact.
Equipment requests, for example, can be automated to collect the information IT needs and move the request into the appropriate fulfillment process.
Actions on an existing device need stronger controls. Take a FileVault recovery request on a Mac. The workflow should verify the employee’s identity before retrieving the recovery key from the mobile device management (MDM) platform and delivering it securely.
The same principle applies to other sensitive device actions. Remotely locking a managed Mac, for example, can log the employee out, restart the device, and prevent them from using it until the correct passcode is entered. Actions with that level of impact should require verification or approval before they run.
What you get back
Once the right workflows are automated, the benefits show up in four areas.
More support capacity without adding headcount
Automating routine Tier-1 requests means each increase in ticket volume creates less additional work for IT. With Risotto automating more routine support work, Gusto now supports twice the ticket volume with the same lean IT team.
Faster resolution
Routine requests often wait for an IT person to start working on them. Automation can begin the workflow as soon as the request comes in, which reduces the time it takes to reach resolution.
The difference can be substantial when those requests are handled automatically. At ThoughtSpot, tickets handled by Risotto averaged 6.5 hours to resolution, compared with 31 hours for tickets handled by human agents.
Support outside IT working hours
Automated workflows can continue resolving supported requests when IT teams aren’t available. That matters for distributed organizations where employees may need help across different time zones or outside the support team’s normal hours.
Hazel Health, for example, previously limited support to East Coast and Pacific business hours, meaning early morning and overnight requests could wait until the next day. With Risotto, Tier-1 requests can now be handled 24/7.
Stronger governance
Automation can reduce the manual work involved in access governance. Access requests and approvals are recorded as they happen. This gives IT an audit-ready record without having to compile the evidence later.
Platforms like Risotto can also run proactive access-review campaigns. This prompts the right people to review existing access, and record each decision and any resulting access change. That replaces spreadsheet-based reviews and manual follow-ups, while also creating a clear audit trail for compliance.
Pro tip: If you need to quantify these benefits, our guide to ITSM ROI shows you how to calculate the financial impact of automation and build a case your finance team can evaluate.
What IT requests should stay human-owned?
A good automation roadmap includes the work you deliberately choose not to automate. For example, in a typical Risotto deployment, around 30 to 40% of tickets still reach a person. These tend to be new, ambiguous, or more complicated issues where there isn’t a predefined resolution path.
There are two situations where humans still need to be involved:
- Requests that require judgment. An AI assistant can investigate the issue, gather context from logs and previous tickets, and propose a resolution plan. The specialist still decides what to do. For example, Risotto’s Tier 2 Assistant is designed to support that work rather than make the decision itself.
- Actions that are difficult to reverse. Removing critical access, wiping a device, or making a permission change with a large blast radius should require human approval. The system can still execute the action once approval is given and log what happened.
How Risotto automates IT work without replacing your ITSM
Automating more IT work doesn’t require replacing the ITSM software you already use. Risotto sits on top of your existing stack and handles automation while your current ticketing system stays in place.
Employees can ask for help in Slack or Microsoft Teams, while tickets stay synchronized with Jira, Freshservice, ServiceNow, or Zendesk. Your existing ticketing platform remains the system of record.
For common Tier-1 requests, Risotto can run the configured workflow, take approved action in connected systems, and update the ticket when the work is complete.
Risotto’s no-code runbooks also let IT build and adjust automations without relying on developer or vendor support. Teams can create workflows in the no-code editor or describe what they want to automate and have the Assistant generate the runbook.
Because Risotto works with your existing ITSM, getting started doesn’t require a full ITSM migration. Start with one of the workflows you ranked earlier, measure the result, then expand automation to the next priority.
Frequently asked questions
ITSM automation uses software to carry out IT service management work that would otherwise require manual effort from IT. It can range from routing a request to resolving an entire workflow, such as a password reset or approved software access request.
Common AI solutions for ITSM include ServiceNow, Jira Service Management, Freshservice, Zendesk, and Risotto. ServiceNow, Jira, Freshservice, and Zendesk offer automation within their own platforms, while Risotto can automate Tier-1 IT work while your existing ticketing system stays in place.
ITSM automation reduces response time by removing the wait time needed for an IT agent to pick up and work through routine requests. For supported workflows, the system can start troubleshooting or carry out the required steps as soon as the request comes in, which shortens both first response and resolution time.
On this page
See how Risotto automates IT support workflows end to end








%20(1).webp)


