Access, licences, and service requests executed across the systems your ITSM platform does not own. Not deflection. Governed execution. Live in 4 to 8 weeks.
WorkStreams
Each WorkStream runs on a deterministic, governed Playbook, not a chatbot answering tickets.
Access certification and entitlement review
A quarterly attestation cycle run end to end, with the audit pack assembled as a byproduct.
Agent Team
Veroli coordinates these agents autonomously, powered by VeroCortex, across identity, ITSM, SaaS, and cloud IAM. Ten core agents handle routine intake, policy, provisioning and fulfilment; nine advanced agents take on certification, segregation-of-duties, spend routing and licence recovery.
Request Capture & Identity Resolution
Captures access requests in natural language from Slack, Teams or the ITSM portal, resolves the requester, and separates a single sentence into distinct entitlement requests.
Risk, Cost & Regulated Screening
Checks entitlements already held, then evaluates risk tier, cost and regulated flags against the approval policy matrix to decide what needs a human and what does not.
Identity Provider & App Grants
Grants entitlements across the identity provider, directory and target application APIs. The same agent People Ops new hire onboarding runs.
Grant Confirmation
Re-queries every target system to confirm the grant actually took effect, retrying or escalating rather than reporting a grant that silently failed.
Seat Request Capture
Captures licence and seat requests across channels, resolves the application, edition and cost centre, and confirms the business justification before anything is bought.
Pre-Purchase Seat Lookup
Queries current entitlement pools before any purchase path opens, surfacing unassigned and reclaimable seats so requests are filled from what you already own.
Licence Grant
Assigns the seat through the SaaS vendor API, updates the licence system of record, and confirms the user can sign in to the application.
ITSM Channel Triage
Classifies inbound service requests from email, chat and the portal against the service taxonomy, sets urgency, and routes to the right resolution path before a ticket exists.
Self-Resolution
Searches the knowledge base and live system state, then attempts resolution directly so routine requests never reach a queue.
Cross-System Execution
Executes the fix in the owning system, whether that is identity, an endpoint tool, a SaaS admin console or a handoff into Procurement, and verifies the outcome.
Certification Population
Resolves the population for each certification cycle, excludes service accounts by policy, and flags scope changes against the prior cycle.
Evidence & Audit Pack
Gathers and normalises last-login, role history and prior attestations per entitlement, then assembles the final audit pack with Execution Ledger references.
Manager Campaigns
Builds per-manager review packets, tracks response state, chases non-responders in Slack at 48 hours and escalates on a configured ladder.
SoD & Privileged Outliers
Evaluates entitlement combinations against SoD conflict pairs, surfaces orphaned accounts and privileged outliers, and ranks every exception by risk.
Revoke & Confirm
Executes approved revocations across identity provider, directory and application APIs, re-queries the source to confirm, and retries or escalates on failure.
Governed Approval Paths
Routes only where policy requires it, auto-approves inside thresholds, and applies conditional logic with a chase at 4 hours and an escalation at 24.
Budget-Aware Licence Approval
Presents seat availability, annualised cost and budget position to the owning approver, and routes purchases into Procurement only when no seat can be reused.
Idle Seat Recovery
Tracks login activity on a rolling window, runs the grace period and owner notice, then reclaims idle seats back into inventory with the decision logged.
Human Handoff With Context
Diagnoses what could not be resolved autonomously, assembles the full attempt history and system state, and hands the exception to the right human owner.
The Transformation
IT carries the highest request volume of any function, and almost none of it lives in one system. A single access request spans the identity provider, the directory, the ITSM record, and three SaaS admin consoles. Certification cycles run on spreadsheets. Licences renew on seat counts nobody has verified in a year.
Managers chase evidence across systems, and the audit pack is assembled by hand after the fact.
Low-risk requests wait in the same queue as privileged ones because policy lives in someone's head.
Seats stay assigned long after the holder stopped logging in, and renewals price against the wrong number.
Deflection answers a question and leaves the work undone. VeroTX executes the work across the identity provider, directory, SaaS admin APIs, cloud IAM, and endpoint tooling, verifies it landed, and seals the trail. When a request needs a person, Veroli routes it with the decision already assembled.
VeroCortex
VeroCortex is part of the platform from day one, governed, multi-model, and audit-ready, so an access decision can be defended months later.
An engineer asks for two systems in one Slack sentence. One grant is inside policy and lands in 40 seconds with no human involved. The other is regulated and cost-bearing, so it routes to a manager and a budget owner who can see three seats are already paid for. Both grants are verified at source, both are sealed in the Execution Ledger, and both appear on the next certification cycle without anyone exporting a spreadsheet.
Agents share the identity roster and policy matrix instead of running siloed automations.
WorkStreams keep going when Okta, ServiceNow, or a SaaS admin API is slow or unavailable.
Every grant, revocation, and reclamation recorded in the Execution Ledger, ready for SOX and SOC 2.
Integrations & Connectivity
Plug into the systems your teams already run. Every connector is governed by role-based access, scoped credentials, and full execution ledger logging.
Every connector is callable by agents through native APIs or the Model Context Protocol.
OAuth, scoped tokens, secrets vault, and per-tenant isolation, with audit trails on every call.
Read and write across systems of record with retries, idempotency, and reconciliation.
Don't see a system? Custom connectors ship in days through the connectors studio, no platform change required.
See how orchestrated agents can be configured for your identity, ITSM, and SaaS estate in 4 to 8 weeks.