Triage and routing
Classify each ServiceNow case, resolve ambiguity, and select the published runbook owned by the right domain specialist.
Lex IT case orchestrator
Classify ServiceNow cases, route them to specialist agents, advance governed runbooks, manage approvals and handoffs, and keep every case moving toward verified closure.
Entra evidence is attached to ServiceNow. The next privileged action is paused for an identity engineer.
Triage, route, govern. Lex is not one all-purpose IT engineer. It is the durable case orchestrator connecting ServiceNow to specialist agents and their published runbooks.
Classify each ServiceNow case, resolve ambiguity, and select the published runbook owned by the right domain specialist.
Track every node, action, handoff, requester wait, approval, human task, and verification step without replaying completed work.
Keep ServiceNow as the audit layer while specialists execute narrow actions and people retain control of privileged or exceptional work.
Triage
Lex reads the ServiceNow case, identifies the domain and intent, requests missing context when necessary, and selects only a published runbook that can safely own the work.
Use the ticket as the durable case record whether it came from Tron, an employee portal, an API, or an IT operator.
Send identity, endpoint, VPN, application, and future cases to agents with narrow missions and declared capabilities.
Ask for the missing user, device, app, or environment instead of letting a general-purpose model guess its way into a tool call.
Orchestrate
Lex advances the selected runbook while specialist agents gather evidence, invoke typed actions, hand off to another domain, and resume safely after external input.
Run explicit graphs of actions, decisions, approvals, requester waits, human tasks, handoffs, verification, resolution, and failure.
Specialists can request only declared, allowlisted reads and mutations backed by customer-specific connectors and permissions.
Carry evidence from one specialist to another in the same case, such as application diagnostics handing a healthy SAP case to VPN.
Govern
Lex manages the boundary between autonomous execution and human judgment. Every pause, decision, action result, approval, assignment, and resolution remains traceable to ServiceNow.
Pause before privileged changes, show the exact proposed action and target, and resume only after a recorded decision.
Route unsupported, destructive, physical, or policy-exception work to the correct team with completion criteria and a verification step.
Close the ticket only when the runbook's evidence, system checks, and requester or human confirmation requirements are satisfied.
Built from the runtime
“Lex owns the case, not every system. Specialists own the diagnosis and actions; Lex keeps their work coordinated, governed, and auditable through closure.”
How teams use Lex
Classify new RITMs, identify missing context, select a published specialist runbook, and preserve the routing decision on the case.
Move one case across application, VPN, identity, endpoint, or future specialists without losing evidence or starting a second workflow.
Pause a privileged runbook node, create the ServiceNow approval artifact, and resume from the exact next step after approval.
Ask the requester to test a fix or assign an exception to an engineer, then resume the same durable case from their response.
Require post-change evidence, write concise work notes and resolution details, close ServiceNow, and report the outcome back through Tron.
Bring Lex into the ServiceNow operating loop