What can AI agents take over in IT & Security?

tacitrun ships 4 IT & Security process blueprints — Access request & provisioning, Incident triage, Change management and Joiner-mover-leaver (JML) access provisioning — each stating its inputs, outputs, KPIs and the points where a person stays in the loop. They are the starting point: the domain agents themselves are built by reading your own procedure, and every write they make waits for your approval.

Cross-industry IT service + security processes.

IT Service Management

Access request & provisioning

Evaluate access requests against role/SoD policy, route approvals, and provision/deprovision.

Inputs
Access request · Role/SoD policy · Manager
Outputs
Granted/denied access · Audit record
KPIs it moves
Provisioning SLA · SoD-violation catch rate · Access-review findings
Systems it usually runs on
IAM · ITSM (ServiceNow)
Where a person stays in the loop
Privileged-access approval · SoD conflict

Incident triage

Classify, prioritize, and route inbound IT incidents; draft responses and suggest fixes.

Inputs
Incident ticket · CMDB · Runbooks
Outputs
Prioritized + routed ticket · Suggested resolution
KPIs it moves
MTTR · First-contact resolution · Reopen rate
Systems it usually runs on
ITSM · Monitoring · Slack/Teams
Where a person stays in the loop
Major-incident declaration

Change management

Assess change requests for risk, gather approvals (CAB), and schedule deployment windows.

Inputs
Change request · Risk assessment · Affected CIs
Outputs
Approved change · Deployment schedule
KPIs it moves
Change success rate · Emergency-change % · Failed-change rollback time
Systems it usually runs on
ITSM · CI/CD
Where a person stays in the loop
CAB approval for high-risk change

Identity & access

Joiner-mover-leaver (JML) access provisioning

Automate the identity lifecycle — provision access on join, adjust on role change, revoke on exit — with approvals and an audit trail.

Inputs
HR event (join/move/leave) · Role-to-access mapping · Approval policy
Outputs
Provisioned / revoked access · Approval record · Access audit log
KPIs it moves
Time-to-provision · Orphaned-account rate · Leaver-revoke SLA · Access-review pass rate
Systems it usually runs on
IdP (Okta / Entra) · HRIS · IGA / ITSM
Where a person stays in the loop
Privileged-access approval

What a blueprint is, and is not

A blueprint supplies the vocabulary, the typical steps, the KPIs and the approval points for a process. It is a starting point, not a pre-built agent: tacitrun builds the domain agents by reading your own procedure, tests them against cases derived from it, runs them in shadow beside your team, and holds every write for a person. Your IT connects the systems and approves before anything goes live.

Questions people ask

How do I give an agent a reference document (e.g. a sample template) to use at runtime?
Two places, both drag-and-drop: (1) for ONE agent, open it → Knowledge tab → drop the file on “Documents it can look up”; (2) for the WHOLE process (available to every agent in it), the process page has a “Documents for this process” card — drop it there. For example, drop a sample proposal template for a Proposal Generator. Whatever the format — PDF, Word, Excel, CSV, HTML, text, OR a screenshot/image (PNG, JPG, etc.) — we handle it: documents convert to clean markdown (tables and headings preserved, not a flattened blob), and images/screenshots are read by vision (Claude) which transcribes all the text and describes what’s in them (e.g. a screenshot of an invoice becomes a markdown table of its line items). Then we cap it to a sensible size for efficient token use, chunk and embed it so retrieval is sharp. It’s added immediately (no IT approval needed, nothing hardcoded) and shows in the document list. From then on the agent searches it live every run and uses it as a reference — e.g. it drafts new proposals in the shape of your template. To have it ALWAYS apply a rule instead of just look it up, use “Teach it” on the same tab (or the Rules tab for enforceable policies).
What is the Salesforce Data Hygiene blueprint, and how do I use it?
It’s a pre-built end-to-end process (a "crew" of 5 domain agents) that replaces the manual job of cleaning up messy CRM data and re-importing it. In the Catalog it shows as a Blueprint with the problem it solves, the outcomes it delivers, and the process mapped to each domain agent: (1) Data Quality Auditor profiles the object and reports duplicates/blanks/malformed/stale records; (2) Duplicate Finder & Merger proposes human-approved merges; (3) Field Standardizer normalizes phone/state/country/titles/casing; (4) Data Re-import Loader picks up a cleaned file (SFTP/SharePoint/Drive) and UPSERTS each row by external ID — so re-runs update the same record instead of creating duplicates; (5) Import Reconciliation Auditor verifies the load matched the source. Adopt each step from the blueprint; we build a private copy in your workspace that you can adapt, connected to your own Salesforce. Every write goes through human approval until you trust it.
What’s a Skill vs a Blueprint?
A Blueprint is a starter process template. A Skill is a reusable knowledge pack a domain agent loads on demand at runtime.
Do you have blueprints for private equity / deal teams?
Yes. Pick "Private equity" in Blueprints to get the full deal lifecycle (origination → diligence → execution & close with IC + signing gates → value creation → exit), plus the cross-portfolio value-creation playbook as standardized levers (working capital, FP&A, pricing/margin, spend analytics, JML access) that deploy identically across every portfolio company. Human-approval gates are built into the deal-close and IC steps. On Ingest, choosing "Private equity" also offers starter templates — Deal Sourcing & Screening, DD Red-Flag Log, IC Memo & Approval, and 100-Day & Value-Creation Plan.

Why offload this process to tacitrun’s AI operating layer

tacitrun is built for exactly this handoff: a business team describes the process it already runs, and the platform turns it into governed domain agents that work across the systems you have, under your IT’s approval, with every write waiting for a person.

Built from your procedure, not a vendor template
Describe the process in plain English or hand over the SOP. tacitrun compiles it into a process graph and composes one domain agent per step, so the agents carry your rules, your exceptions and your vocabulary.
Tested against the process before it can act
Evaluation cases are derived from the graph itself, so a passing agent is one that does what your process says. Then it runs in shadow beside your team on real work before anyone lets it act.
Every write stops for a person
The approval gate sits on the actual call to Salesforce, Shopify, SendGrid, SAP or any connected system. A person accepts, modifies or rejects; the corrected version is what executes; the trace keeps the record.
Runs across the systems you already have
Built-in connectors, your own REST APIs or MCP servers, and on the Enterprise plan your own cloud project and your own models. The systems of record stay where they are; the layer does the work between them.
IT approves, business leads
Business users build and prove; IT connects the credentials, binds the fields and approves before anything goes live. Neither side inherits the other’s risk.

Read next