Skip to content
Flexday AI Docs

Use cases › Service Desk Copilot

Solution design

Every resource in the Service Desk Copilot Solution, how each is configured, and why it is set up that way.

Written for
  • Technical

Last reviewed

The Service Desk Copilot is one Solution. Everything below lives inside it, so everything can reference everything else, and nothing outside it can reach in. This page lists each resource, how it is configured and why.

Four bands of resources: front doors (Bot, dashboard, two Flex Gateways), intelligence and automation (the Agent and four Flows), data and knowledge (Fact Base, Doc Base, optional Data Portrait), and credentials and settings (two Identities, a ServiceNow Connection and Variables)
Figure: inside the Service Desk Copilot Solution.

Note

Resource names follow the platform's convention of a short name and a type suffix. The Builder would name the Fact Base Service Desk DS and the app Service Desk APP; this page uses plain names for readability.

Data and knowledge

Service desk data (Fact Base)

Created by the Builder from a sample ServiceNow incident export (CSV).

TablePurpose
incidentsOne row per incident: ServiceNow record ID (the key), number, short description, priority, state, category, assignment group, site, opened and updated times
incident_eventsOne row per change pushed from ServiceNow: incident, state, priority, time
sitesHarbourline's sites, for grouping and the dashboard map
Saved queryKindUsed by
open_incidents_by_priorityReadDashboard
sla_at_risk (minutes from the SLA_WARNING_MINUTES Variable)ReadDashboard
incidents_by_siteReadDashboard map
incident_status (by number)ReadThe Agent: state, assignment group, last update and short description only
upsert_incidentWrite: insert, or update the row when the record ID already existsIngest incident, Nightly reconcile
add_incident_eventWriteIngest incident

The read queries run under the Fact Base's reader role. The write queries run under the writer role, and only the two Flows use them; no gateway endpoint exposes a write query directly.

IT knowledge (Doc Base)

SettingValue
ContentKnowledge articles exported from ServiceNow, plus IT runbooks
AudiencesKnowledge articles carry no tag (anyone who can search may see them). Runbooks carry the it-staff tag.
Linked File StoreA "Knowledge exports" store, linked with automatic indexing so a new export indexes itself
SearchHybrid, Balanced preset

Data Portrait (optional)

Harbourline profiles the incident data once it has a few weeks of history. The profile flags, for example, that most incidents arrive without a site, which led to the Agent asking for it.

Intelligence and automation

Service desk agent (Agent)

SettingValue
ModelThe workspace default (Claude)
GroundingAnswer only from connected knowledge on
GrantsDoc Base search on IT knowledge; Fact Base query on Service desk data (reader role, incident_status only in its instructions); run Flow: Raise incident
InstructionsTry documented fixes first and cite them; before raising a ticket, collect the work email, site, device and what was tried, then confirm; report status only by ticket number; never ask for a password
GuardrailsPersonal data masked (card numbers and similar); a blocked topic for requests to reset someone else's password or bypass security controls
FormsOff, because the Agent answers in Teams, which shows text only
EvaluationsA golden set of 20 questions and ticket requests, required to pass before publishing

Flows

FlowTriggerSteps
Ingest incidentManual (started through the intake gateway's flow endpoint)Check fields → Run query upsert_incident → Run query add_incident_event → Condition: priority 1 and state New → Subflow P1 alert → Respond
Nightly reconcileSchedule, 02:00 Europe/London; published and enabledIntegration: Find tickets (open only, assignment group from a Variable, up to 100) → Loop → Run query upsert_incident → Send email summary
Raise incidentManual (run by the Agent)Integration: Find user (by email) → Integration: Create ticket (caller, summary, description, category, assignment group) → Respond with number and link
P1 alertManual (run as a subflow)Loop over on-call conversations → Send channel message; HTTP request to the status page; Send email to P1 contacts; Respond

The ServiceNow Connection names a duplicate-prevention field, so an interrupted Create ticket can be checked rather than risk a duplicate.

Front doors

ResourceConfiguration
Service desk bot (Bot)Microsoft Teams, managed registration, bound to the Service desk agent; published to Harbourline's Teams catalogue
Service desk dashboard (LaunchPad)Widgets: open incidents by priority, SLA at risk, a site map, a table of recent changes, and a chat panel on the Service desk agent
Service desk gateway (Flex Gateway)Identity: Harbourline SSO. Endpoints: the three dashboard read queries, and an agent endpoint for the chat panel. All inherit, so all require sign-in.
ServiceNow intake gateway (Flex Gateway)Identity: ServiceNow push key. One flow endpoint that starts Ingest incident.

Two gateways keep two very different callers apart: people signing in through SAML, and one machine presenting an API key. Each gateway has exactly the endpoints its caller needs.

Credentials and settings

ResourceConfiguration
Harbourline SSO (Identity)SAML (federated) through an Amazon Cognito user pool; rule: email domain harbourline.example. See Authentication.
ServiceNow push key (Identity)API key. The key is shown once and stored in ServiceNow; it can be revoked at once.
ServiceNow (Connection)Kind Application, ServiceNow, OAuth client credentials; instance address; duplicate-prevention field
VariableTypePurpose
SERVICENOW_ASSIGNMENT_GROUPTextThe group new tickets go to, and the reconcile filter
SUPPORT_EMAILTextWhere the nightly summary goes
SLA_WARNING_MINUTESNumberHow close to breach counts as "at risk"
P1_NOTIFY_EMAILSJSONManagers to email about a P1
P1_ONCALL_CONVERSATIONSJSONTeams conversations of on-call engineers, copied from the Bot's Conversations view
STATUSPAGE_TOKENSecretThe status page API token, used only in the HTTP request's Authorization header

Why it is designed this way

DecisionReason
ServiceNow stays the system of recordAnalysts keep their tools; Flexday AI never becomes a second place to work tickets.
Writes only through FlowsEvery write to the Fact Base is visible in a graph with a step trail, under the writer role.
The Agent raises tickets through a FlowThe Agent cannot call ServiceNow directly; the Flow fixes the application, the credential and the fields.
Status by ticket number onlyTeams identifies people by their Microsoft account, not by email, so the Agent returns only fields any employee may see.
Runbooks tagged it-staffTeams users see public articles; IT staff see runbooks in the dashboard's chat, where their sign-in carries the tag.