Evidence-led decisions.
Governed execution.
AI understands the ticket, retrieves precedent, plans the action and proposes the correct autonomy level. Governance decides. The platform executes, verifies, records and learns.
Automation and SLA risk
Ticket volume by tower
Evidence confidence trend
Live Operations Console
Follow every in-flight ticket from intake to verified closure. All records below are synthetic and generated for the demonstration.
| Ticket | Tower | Current Agent | Mode | Current Step | SLA | Status |
|---|
No active run
Execution connectors
Ticket Explorer
Inspect ticket context, classification, historical evidence and the executable plan in one traceable view.
Agent Orchestrator
Specialist agents operate under one durable state machine. The orchestrator controls sequence, dependency, pause, retry, rollback and hand-off.
Approval & Guardrails
Evidence informs the decision. Configurable Kyndryl policy determines the permitted level of autonomy.
Block high-risk geo-origin traffic
Security Operations requested a geo-IP block after correlated access attempts were identified. The plan affects perimeter firewall, WAF and SIEM watchlists.
AI proposed execution plan
- Perimeter controlsApply the approved geo-origin deny rule to the firewall policy.
- Application controlsSynchronise the equivalent WAF policy and validate propagation.
- Monitoring controlsAdd the indicator to SIEM watchlists, verify events and update ServiceNow.
set rulebase security rules "GEO-RISK-2026-08" source-region ["RU","KP"] action deny log-end yesDecision gate
Automation Maturity
Autonomy is earned from evidence. Categories progress from Shadow to Assisted to Automatic, and can be demoted if precision deteriorates.
| Category | Current Mode | Precision | Approval Rate | Drift | Status | Next Gate |
|---|
Work distribution by automation stage
Human effort required — Current vs AI Ops
Feedback becomes governed evidence
Security & Governance
Separation of decision and execution, short-lived privilege and immutable evidence keep every action controlled and reviewable.
Integration Landscape
Approximately 24 connector patterns across the Kyndryl estate. Demo connectors simulate vendor-native calls; production integrations require validated access and testing.
Business Value & ROI
Every assumption remains editable during the discussion. Outputs are illustrative and subject to due diligence against Kyndryl data.
Ticket volumes
Automation & effort
Cost, deployment & currency
AUTO / APPROVE / HUMAN
Capacity released over 36 months
36-month cumulative value
Cost composition
Delivery Roadmap
Due diligence locks scope, evidence, infrastructure and acceptance gates before three four-week delivery milestones.
Due Diligence & Execution Planning
Validate ticket baseline, task groups, connector scope, ownership, infrastructure and UAT gates.
Scope and execution plan lockedFoundation & Core Automation
Ingestion, evidence, single-system planning, core guardrails, approvals, audit and Tier A activation.
Indicative backlog: 44 capabilitiesAssisted Execution & Governance
Multi-system plans, blast radius, rollback, drift monitoring, extended connectors and Tier B activation.
Indicative backlog: 39 capabilitiesAdvanced Operations & Autonomy
Multi-agent orchestration, proactive remediation, controlled promotion and advanced operating insights.
Indicative backlog: 17 capabilitiesThirdEye Data responsibilities
- Platform design, development and customisation
- Model training and precedent configuration
- Connector implementation and validation
- Deployment, UAT support and knowledge transfer
Kyndryl responsibilities
- Infrastructure, access and platform owners
- Historical ticket and action data under NDA
- Approval policy and named decision owners
- UAT participation and milestone acceptance


Kyndryl — Agentic AI Automation for ITSM & Security Operations
Proposed by ThirdEye Data
A system of action alongside the system of record
AI Ops reads incoming work, grounds decisions in Kyndryl’s resolution history, creates an executable plan and operates within configurable risk policy. ServiceNow remains authoritative; AI Ops performs governed action and writes every outcome back.
The current model does not compound
Seven layers with explicit separation of duties
Governance determines autonomy for each action
Coverage organised by operating domain
Deployed in a Kyndryl-controlled environment
Ticket data, models, action traces and audit history remain within the controlled environment. Hosted reasoning may use minimised and redacted context where permitted; self-hosted alternatives can be used where policy requires.
Due diligence, then three governed milestones
The 100-feature capability backlog is an indicative planning basis. Final committed scope and sequence will be validated during due diligence.
Complete 35-page proposal — source of truth
The interactive sections above provide the presentation story. The embedded document below is the complete approved Word proposal converted to PDF without replacing its wording, section order, tables or diagrams.
Baseline first. Lock the plan on evidence.
Governed Agentic Operations