Demonstration using synthetic data
The 3 AM P1: an on-call ticket work-up from one question
A recorded demonstration: an on-call engineer asks one question, and an assistant pulls the ticket, the server record, the outage runbook, and credential ages from ConnectWise and IT Glue, then drafts a ticket note it does not post.
Demonstration using synthetic data.Every record, name, address, and log entry on this page is invented for the demonstration. No client, client system, or production record is involved.
- Author
- Tanner Rusher
- Published
- What this label means
- A scenario Natural State Logic built to show how a workflow behaves. The records, names, and log entries are invented, no client is involved, and no business result is claimed.
Demo environment. Synthetic data. The managed service provider, its client, the people, the ticket, the server, and the credentials are all invented. The ConnectWise and IT Glue shown are mock services that imitate the vendors’ APIs, not the vendors’ products or anyone’s real account. No client was involved and no business result is claimed.
The situation
It is 2:47 in the morning. Priya Raman is the on-call engineer at Cobalt Ridge IT, a fictional managed service provider with twelve clients. Her phone goes off: Redline Logistics cannot reach its file server, and the Redline depot starts loading trucks at five.
Working that page normally means four tabs. The ticket is in the PSA. The server’s record is in the documentation platform. The runbook is somewhere else in the documentation platform. The admin credential is in the password vault. She would open each one, half awake, and assemble the picture herself.
In this demonstration she types one sentence instead.
Who this demonstration is for
Service managers, on-call engineers, and owners at managed service providers, and at any IT team whose tickets live in one system and whose documentation lives in another. The vendor names differ between organizations. The shape of an after-hours page rarely does.
The question
The assistant is Claude, running in Claude Desktop with the provider’s on-call procedure loaded as standing instructions. Two connectors give it read access: one for ConnectWise and one for IT Glue. Priya asks:
I just got paged for 40217. Get me everything I need to start working it.
What it did
The ticket. It pulled ticket 40217 and its notes from ConnectWise. The ticket is a P1 on the Help Desk board, status New, with no owner. The only note is the after-hours call: the caller says nobody at the depot can reach the S: drive or the dispatch share, and the server does not answer ping. The ticket names the configuration, RL-FS01.
The server record. It found Redline in IT Glue, then the RL-FS01 configuration. The answer laid it out as a table: a Dell PowerEdge R750 running Windows Server 2022 Standard at 10.40.10.5, the primary file server and root of the shared-drive namespace, under warranty until December 2028.
The runbook. It looked up Redline’s runbook asset type and read the outage runbook for this server. The steps landed in the same answer, in order:
- Ping the server. If it does not answer, open the remote management controller (iDRAC).
- From a domain workstation, check that the shares path resolves.
- Check that the Server service and the DFS Namespace service are running.
- Check free space on the D: volume. The alert threshold is 10 percent.
- If the host is down, power cycle it from iDRAC. Boot takes about six minutes.
- If it is not back within 30 minutes, escalate to Priya Raman and notify the caller.
It also noticed that Redline’s two general IT Glue documents, the contacts-and-escalation page and the environment overview, contain only placeholder text. It said so: the runbook’s last step is the only escalation path on record.
The credentials. It listed the password records for Redline, names and ages only, without retrieving a single password value. The domain administrator account linked to RL-FS01 was last changed 411 days ago, and the answer marked it as needing rotation. It also pointed out that there is no iDRAC credential in IT Glue at all, so if step 5 comes to a power cycle, Priya will have to find that login some other way.
The moment
Ticket, server record, runbook, and a stale domain administrator credential, in one answer, before anyone logs in with that credential at three in the morning. None of it required intelligence beyond reading what was already documented. What changed is that Priya did not have to switch tabs to read it, and that the two gaps, the stale credential and the missing iDRAC login, were raised before she needed them rather than discovered in the middle of the outage.
What it handed back
It drafted an internal ticket note and did not post it. The note summarizes what was reported, which runbook is being worked, and when escalation happens. Below it, the assistant offered to post the note, assign the ticket to Priya, and move it to In Progress, and then waited. This flow is read-only by design: the assistant proposes, and the engineer reads, edits, and posts. It also listed follow-ups for after the outage: rotate the domain administrator password, add the iDRAC credential to IT Glue, and fill in the two empty Redline documents.
What this demonstration proves
- One plain request can gather a ticket, the configuration it names, the matching runbook, and related credential metadata across two systems in one pass.
- An assistant can report credential ages and gaps without ever retrieving a password value.
- Documentation problems, such as empty pages and a missing credential record, can surface as a side effect of ordinary work rather than waiting for an audit.
- A drafted change can stop at a proposal, with the write left to a person.
What this demonstration does not prove
- No business result. There is no measured response time, resolution rate, or saving here. A synthetic scenario cannot produce one, and this page claims none.
- It is only as good as the documentation. The runbook in this world is complete and current. Where a runbook is missing or wrong, the assistant reads back the same gap a person would find.
- Mock services are not the vendors’ products. The connectors are unmodified, but the APIs behind them are imitations serving a fixed dataset. Behavior against a live ConnectWise or IT Glue instance has to be verified in that environment.
- Access still has to be designed. What the assistant can read is whatever its connectors are allowed to read. Deciding that boundary, and keeping password values out of reach, is part of the engagement, not a property of the tool.
- The AI provider still processes the text. Ticket notes and documentation excerpts leave the organization’s boundary for processing. That trade-off is examined and disclosed per engagement.
Publication safety
Confirmed before publishing this page:
- Every company, person, ticket, server, address, and credential shown in the video and on this page is invented for the demo environment, and the video carries a persistent “Demo environment. Synthetic data.” label.
- No password value appears anywhere. The assistant listed credential names and ages only.
- The ConnectWise and IT Glue shown are mock services. Vendor names are used factually to describe compatibility, and no vendor has endorsed, sponsored, or reviewed this work.
Demo environment. Synthetic data. Cobalt Ridge IT and Redline Logistics are fictional.