DaemonLayer resolves common IT requests without engineer involvement. When it cannot complete a task, it exits cleanly and routes to your service desk with full context. No ticket ever falls through silently.
Coverage
DaemonLayer ships with automation across six domains that represent the majority of L1 volume for most MSPs. Each domain is opt-in: enable only what you are ready to automate.
Password resets with identity verification, account unlocks, and group membership changes executed directly against the user's Microsoft 365 tenant. No technician touches the admin centre.
Delegate access, forwarding rules, shared mailbox permissions, send-on-behalf rights, and out-of-office configuration, handled via natural language from the original ticket.
Display name, job title, department, phone number, and manager assignments updated directly in Microsoft 365 and written back to your PSA ticket as a structured note.
AI-generated first replies for common informational requests, informed by your historical ticket resolutions, your documentation, and the specific context of the requester.
"PDFs won't open" or a missing app on a new laptop, checked on the user's own Windows device through your RMM and fixed with a script you approved. The user confirms it works. Device Troubleshooting →
RMM alerts that stay open become PSA tickets, are investigated with history and read-only diagnostics, then fixed and verified, or escalated half-solved. RMM Alert Handling →
How It Works
Automation does not run on every ticket. It runs on tickets where DaemonLayer is confident enough to act. Everything else routes to your team with context already attached.
When a ticket arrives, the triage engine classifies the request and produces a confidence score. That score, not a rule you write, determines whether automation runs or the ticket goes to your team.
If the score meets your configured threshold and a matching workflow is enabled, it executes automatically. Below threshold, the ticket routes to your service desk already enriched with AI analysis.
Triage hands off to the correct workflow without any per-ticket configuration. A request that needs several actions gets a workflow plan and one reply. If a workflow encounters a problem it cannot resolve, it exits cleanly and routes to the service desk with a clear explanation of what was attempted.
Workflow Plans
"Change Diego's job title and give him access to the IT SharePoint site" is one request that needs two workflows. Ticket Triage builds a workflow plan: an ordered list of workflows, each owning one part of the request. They run one after another, each adds an internal note, and the last one sends the user a single reply and resolves the ticket. If even one action can't be automated, the whole ticket goes to your service desk.
The reporter gets a clarification question. After they reply, the plan continues where it left off.
The plan stops and the ticket goes to the service desk. The handoff note lists which parts are done (✔) and which still need handling (✘).
The Activity tab shows what's coming: Next: for the upcoming workflow and Then: for the ones after it.
Human-in-the-Loop
Any workflow can be configured to pause and wait for explicit approval before a sensitive action executes. HITL is not a workaround. It is how MSPs deploy automation at their own pace.
Gate any individual workflow. Before a sensitive action executes, an admin receives an approve/reject request with full context: requester, target, action, and risk level. You decide the granularity.
Approval requests surface directly inside your PSA panel, via email notification, or from the DaemonLayer dashboard. No context-switching. Approve or reject in one click.
Approvals time out after a configurable window (default 24 hours). If no response is received, the workflow exits and the ticket falls back to the service desk automatically. No ticket is ever left in limbo.
The Service Desk workflow cannot be disabled. Every failed automation, every approval timeout, and every ticket below the confidence threshold routes here automatically.
Deployment Model
Every workflow is opt-in per MSP. Start with the domains that carry the highest confidence and the lowest risk, then expand at your own pace. There is no requirement to automate everything on day one.
Confidence thresholds are configurable. If you want DaemonLayer to act only when it is 90% confident, set that threshold. Everything below routes to your team, already enriched and triaged.
Related
Connect your PSA, and DaemonLayer starts triaging, resolving, and routing, no scripting, no setup calls. Cancel anytime.
Prefer a walkthrough? Book a demo →