Resolving help desk requests with enterprise-safe Jamf automations
A preview of Serval's sponsor session at JNUC 2026.
Many IT teams have tried an AI assistant on their help desk, mostly for answering questions, but rarely letting it take action on production systems.
The same flexibility that lets an AI agent understand "my laptop is ancient, and I can't unlock my disk" is what makes its behavior unpredictable from run to run. It’s a good fit for vague requests, but risky for holding admin credentials to your MDM.
Fernando Pereira, IT Fellow at Serval and former Head of IT at Coinbase, talks through the architecture Serval built to resolve that tension, and demo the Jamf automations it produces.
Serval separates understanding from action
Serval uses two agents with a strict boundary between them.
The help desk agent:
- Talks to employees
- Reads requests from:
- Slack
- Teams
- Service tickets
It determines what the person needs and gathers context – it does not act on production systems.
The automation agent builds the workflows. Each workflow is explicit, versioned and deterministic code that calls Jamf ‘s API. A person reviews and tests the workflow before publishing it, which allows the help desk agent to call it when needed.
Every workflow run follows the same steps and is fully auditable.
Three demo automations that IT teams can leverage
1. FileVault key recovery
The workflow verifies the employee's identity and device assignment in Jamf. It then retrieves the key and delivers it through an approved channel and records the disclosure.
2. Hardware refresh approvals
The workflow pulls the purchase date, model and warranty status from Jamf. It then applies the organization's refresh policy. Requests that meet the policy are approved automatically while the rest go to a human with the data attached.
3. Ticket triage with device history
The workflow attaches the device's recent check-ins, OS version, disk encryption state and patch status. The technician's first response can use those facts instead of asking for more information.
Note: No automation requires the LLM to hold Jamf credentials or to improvise an API call at runtime.
Questions to ask before an AI tool gets production access
The second half of the session gives a framework for evaluating any AI tool before it touches production. Fernando covers:
- What the agent can do directly, and what it can only propose
- Can a human review every action before it runs, and reconstruct it afterward?
- Who approved each automation, and can you see what changed?
- What happens when the help desk agent can’t figure something out?
Join Serval at JNUC 2026
Session: How AI Agents Are Building Their Own Automations with Serval
Speaker: Fernando Pereira, IT Fellow, Serval
When: Thursday, September 24th from 1:45 PM - 2:30 PM | Where: Room 2504A
Don’t miss this presentation at JNUC 2026!