Use case
Employee helpdesk
An internal assistant that answers staff questions about IT, facilities, expenses and policy, and can perform routine service actions such as resets and access requests. Same shape as customer support, different audience and different data.
- Source
- Editorial ontology entry — no fetched document behind this page
- Evidence
- none on this page — it links to the pages that hold it
- Category
- People
- Typical risk
- high
- Entry
- editorial · reviewed 25 Aug 2026
01What this is
An employee helpdesk retrieves from internal policy and IT documentation and integrates with the service desk to raise, update and resolve tickets. Value comes from resolving the repeated 60% of tickets and giving the rest to an agent with context attached.
A good deployment scopes what the assistant may do (reset a password, yes; change payroll details, no), respects the permissions of the asking employee, escalates to a named queue, and keeps ticket history under the HR and IT retention rules that already exist. Usage is reported without naming individuals.
Pitfalls: an assistant that surfaces policy applying to a different country's staff; helpdesk logs that quietly become an employee-monitoring dataset; and automated access grants without approval. Employee questions can reveal health, grievance or disciplinary context, so treat helpdesk transcripts as sensitive.
- Typical data
- employee data, support tickets, policies, internal documents
- Solution classes it admits
- Enterprise SaaS, Private cloud, Self-hosted
02Deployment options
- ASSESSMENT
On a neutral reading of this use case, Self-hosted is a strong alternative, Private cloud is a strong alternative and Enterprise SaaS is conditional.
- ASSESSMENT
Read as a generic reading of this page, not a recommendation: no organisation, size, jurisdiction, budget or technical capability has been supplied, so wherever an option depends on one of those, it says "unknown". Ask your own question to get a verdict that accounts for them.
Private cloud
STRONG ALTERNATIVEManaged model API or private model deployment in your cloud account
- ASSESSMENT
Two patterns fit inside one account in a region you name: call a managed foundation-model API such as Amazon Bedrock, Microsoft Foundry / Azure OpenAI, or Vertex AI; or deploy an open-weight model on GPU compute you control. Your application, retrieval layer, storage, identity and logs remain in your cloud boundary in both patterns.
- ASSESSMENT
The managed-API pattern can use closed-source frontier models without buying or operating GPUs. It is usually the fastest way to build a custom workflow, but prompts and retrieved context are processed by the managed service, so model availability, retention, abuse monitoring and regional routing must be checked for the exact feature and endpoint.
- ASSESSMENT
The private-model pattern gives more control over weights, serving and network paths, and can use managed endpoints or your own containers. It also makes your team responsible for capacity, patches, model upgrades, evaluation and failover.
- ASSESSMENT
The cloud provider becomes a data processor in either pattern: you need a DPA, a documented region, and an answer on cross-region routing and where support staff can access the environment from.
- RECOMMENDATION
Start with the managed-API pattern when the workflow is custom but model operations are not the source of competitive advantage; move to private model serving only if evaluation, volume, portability or the data boundary justifies the extra operations. Your stated technical capability is "unknown".
Self-hosted
STRONG ALTERNATIVEOpen-weight models on infrastructure you operate
- ASSESSMENT
Documents, queries and embeddings stay on machines you own, using an open-weight model whose licence you review. For a brief that involves confidential documents and personal data, that removes a model-API vendor from the data path rather than governing that transfer by contract.
- ASSESSMENT
It costs you the operational work instead: a GPU server, Docker, Linux, backups and a patching routine. Your stated technical capability is "unknown", which is the attribute this option most depends on.
- ASSESSMENT
No processor agreement, subprocessor list or cross-border transfer assessment is needed for the model itself, because no third party processes the content.
- RECOMMENDATION
Recommended where local processing is preferred (you did not say so) and the content is sensitive (confidential documents and personal data).
Enterprise SaaS
CONSIDER IFFinished closed-source cloud product with enterprise controls
- ASSESSMENT
This is a complete vendor application, not a model API: examples include an enterprise assistant, coding copilot or document product with the workflow, interface, connectors and administration already built. It can use closed-source cloud models while requiring no model hosting or application engineering from your team.
- RECOMMENDATION
Choose it when the product already performs the actual workflow and its controls meet your requirements. Do not choose it only because its underlying model is strong: a finished SaaS product is less flexible than building against a managed API when your process, integrations or review steps are organisation-specific.
- ASSESSMENT
Vendor commitments are treated as unverified until we have fetched the page that makes them. Until then this option carries questions to ask, not assurances: a signed data processing agreement covering the data you will actually put in; a documented data residency commitment naming the region, in the contract rather than a blog post; a written no-training commitment for your content, including uploads and connected sources; stated retention periods and a deletion path you can exercise; an administrative audit log you can export, and SSO with group-based access control.
- RECOMMENDATION
No jurisdiction was named, so this is the check rather than the conclusion: compare the vendor's stated processing locations and subprocessor list against the cross-border transfer rules wherever you operate before uploading anything.
03Deployment stacks
04Tools by hosting option
Self-hosted4
- HybridauthentikIdentity provider with OpenID Connect, SAML and proxy-based authentication, application-level policies and a forward-auth outpost for services that have no login of their own.
- Self-hostedKeycloakIdentity and access management server providing OpenID Connect and SAML single sign-on, user federation, groups and roles for self-hosted applications.
- Hybridn8nWorkflow automation tool with several hundred integrations, branching logic, code steps and AI nodes. Can be self-hosted, which is why it appears in on-premise automation stacks.
- HybridOnyxOpen-source enterprise search and chat over company systems, with connectors to common SaaS tools, permission-aware indexing and a self-hosted deployment path.
Private cloud5
- HybridauthentikIdentity provider with OpenID Connect, SAML and proxy-based authentication, application-level policies and a forward-auth outpost for services that have no login of their own.
- SaaSGleanEnterprise search and assistant across company SaaS systems, with permission-aware indexing, a knowledge graph of people and content, and an agent-building layer.
- Self-hostedKeycloakIdentity and access management server providing OpenID Connect and SAML single sign-on, user federation, groups and roles for self-hosted applications.
- Hybridn8nWorkflow automation tool with several hundred integrations, branching logic, code steps and AI nodes. Can be self-hosted, which is why it appears in on-premise automation stacks.
- HybridOnyxOpen-source enterprise search and chat over company systems, with connectors to common SaaS tools, permission-aware indexing and a self-hosted deployment path.
Vendor cloud7
- SaaSAtlassian RovoSearch, chat and agents across Atlassian products and connected third-party tools, using Atlassian’s cloud permissions model and admin controls.
- SaaSGleanEnterprise search and assistant across company SaaS systems, with permission-aware indexing, a knowledge graph of people and content, and an agent-building layer.
- SaaSIntercom FinAI support agent that answers customer questions from a company’s help content, takes defined actions and hands conversations to human agents inside Intercom’s inbox.
- SaaSMoveworksEmployee support platform that resolves IT, HR and facilities requests through chat, integrating with service-desk and identity systems to complete routine actions.
- Hybridn8nWorkflow automation tool with several hundred integrations, branching logic, code steps and AI nodes. Can be self-hosted, which is why it appears in on-premise automation stacks.
- HybridOnyxOpen-source enterprise search and chat over company systems, with connectors to common SaaS tools, permission-aware indexing and a self-hosted deployment path.
- SaaSZendesk AI agentsAI agents and agent-assist features inside the Zendesk service platform, answering from help centre content and routing or escalating tickets within existing workflows.
On-premise (enterprise plan)1
05Compliance hot spots
This use case usually raises personal data, sensitive data, confidentiality, retention, logging, human oversight, transparency, automated decision-making, prompt leakage, security.
- Sensitive data
- No published jurisdiction page names this topic yet
- Confidentiality
- No published jurisdiction page names this topic yet
- Retention
- Hong Kong
- Logging
- European Union
- Human oversight
- No published jurisdiction page names this topic yet
- Transparency
- United KingdomJapanSouth Korea
- Automated decision-making
- European UnionUnited KingdomSouth Korea
- Security
- China (mainland)
06Example questions
Each of these opens the question box with the text already in it. The answer is researched for your organisation, not for this page.
07Related use cases
- PeopleRecruitment screeningUsing AI in hiring — parsing CVs, matching candidates to requirements, ranking, structuring interview notes. Regulated as a high-risk application in the EU and constrained by anti-discrimination and automated-decision rules almost everywhere.
- PeopleHR knowledge assistantAnswering questions about leave, benefits, pay policy and procedure from the HR document set, with jurisdiction-correct answers for multi-country teams. Answers must match the employee handbook, not approximate it.
Improve this page
Sign in to contribute
From the field
0 deployments · 0 questions
Nobody has reported deploying this here yet, and no question has been opened against this page. Both appear once a reviewer accepts them.