Point of viewAI in capability centres

Stop reporting SLA breaches. Start predicting them

Service desks measure SLAs after the fact. The same ticket data, read by a handful of well-chosen models, tells a team lead which tickets will breach while there is still time to act.

5 min read By · Point of view
6
ML models in the ITSM intelligence platform we built on a real ticket estate1

Key takeaways

  • Ticket data already contains the signals of a coming breach: age, priority, comment activity, team load.
  • A small set of models — anomalies, forecasts, resolution time, breach risk, recurring issues, bottlenecks — covers most of what a desk needs.
  • A copilot over the same data turns 'why are we breaching?' from a spreadsheet exercise into a question with an evidenced answer.

Every service desk reports SLA attainment. Few can say, at nine in the morning, which open tickets will breach by the afternoon. The data to do so is not exotic: it is the ticket's age, its priority, how recently anyone commented, how loaded the assigned team is, and how similar tickets behaved before.

Six questions, six models

On a real ITSM estate — the IT function of a Gulf real-estate group — we built an intelligence layer around six models, each answering a question the desk already asks by hand.

Exhibit 1

Six models and the question each answers

From our GCC & IT services case study

ModelThe question it answers
Anomaly detection (isolation forest)Which tickets look unlike the rest?
Incident forecastingHow many incidents should we staff for next month?
Resolution-time predictionHow long will this ticket really take?
SLA-breach risk scoringWhich open tickets will breach?
Recurring-issue detectionWhich problems keep coming back?
Team bottleneck analysisWhere is work piling up?

Source: DaasLabs, “Delivered for IT operations, service management and audit: GCC & IT services case study” (2026)

From dashboard to conversation

Models are only useful if someone acts on them. A copilot over the same data lets a service-delivery manager ask 'why are we breaching SLAs?' or 'what should we fix first?' and get an answer with the tickets, the trend and a recommended action — which a person then decides to take.

Making it stick

  • Start with breach-risk scoring on one queue and measure attainment before and after
  • Turn recurring clusters into problem records with owners and dates
  • Feed runbooks and knowledge-base articles from resolved tickets
  • Review the models' misses every month with the desk
For executives

What this means for your bank

  1. Measure the share of breaches flagged in advance, not model accuracy alone.
  2. Keep the copilot's answers tied to the tickets behind them.
  3. Use recurring-issue analysis to remove work, not just route it faster.
Put it to work

How DaasLabs can help

Bring ITSM intelligence to your desk in our IT Service & Operations service.

Learn more

Meet the ITSM and AIOps agent squads.

Learn more

See the platform in our case study.

Learn more

Sources

  1. 1

Figures are drawn from the cited public sources. Opinions labelled “DaasLabs point of view” are our own.

Stay informed

Get new GCCs and IT services insights in your inbox

New perspectives on AI, data and transformation in GCCs and IT services — a few times a month. Browse all insights.