Stop Sending Employees to IT. Send Service to Them.

Episode Summary

IT service management was built around a constraint: a small IT team cannot serve ten thousand employees, so the employees are told to come to IT. Lenin Gali, chief business officer and a founding team member at Atomicwork, argues that agents remove the constraint and the whole model should invert. Instead of an employee leaving what they were doing to open a ticket in a portal and wait, the service arrives where they already are, in Slack or Teams, and answers in seconds. His framing is that the employee is the recipient of the service, so the employee should be the focal point, not the process that brings them to the queue. That reframe drags the measurement with it. Mean time to resolution stops being the number that matters once resolution is real time, and deflection, quality and productivity returned take its place. The back half of the conversation is about what has to be true before any of it is safe: trust, security, governance and compliance as four separate tests, an identity for every agent, and a support hierarchy for agents that mirrors the human one rather than a single agent doing everything.

Key takeaways

  • Invert the service model. The old design tells employees to come to a centralized portal because IT is small. Agents remove that constraint, so the service should travel to the employee in Slack, Teams, email or whatever application they are already in

  • Real-time response changes the unit of measurement. Ask a question in Teams and an agent answers immediately, which moves resolution from hours or days to seconds

  • Ticket deflection replaces ticket volume. Once agents open and close tickets behind the scenes, counting tickets measures nothing. The measures that survive are whether the employee got the outcome, the quality of the fix, and whether it created a new problem

  • ROI needs a baseline before it needs a story. Nobody gets ROI by asserting that AI works magically. Record what a thing costs and how long it takes today, then measure against that

  • Four separate tests for an AI vendor, not one: trust, meaning transparency and logs; security; governance, meaning guardrails and an off switch; and compliance

  • Give agents the same support hierarchy people have. A level one agent triages and resolves, then hands off to a Salesforce, SAP or Workday agent. One super agent doing everything is a single point of failure

  • Every agent needs an identity. Identity governance is already the foundation for granting a person access to an application, and an agent is the workforce equivalent. A hundred agents running with nobody able to say which one did what is the failure mode

About Guest1

Guest Linkedin Profile is VP of AI and Data at Envorso and a founder of the AI GovOps Foundation, a nonprofit practitioner community advancing AI Governance as Code. He spent 25 years at Microsoft and then led a Ford subsidiary serving 20 million connected vehicles, with senior roles spanning AI, data, cloud platform, telematics, and digital transformation. His book The Lean AI Handbook is due from Pearson in summer 2026. He is known for helping enterprises embed governance controls into AI systems through engineering rigor, automation, and operational feedback loops rather than policy documents alone.

 

In this episode

00:00 Welcome and guest introductions
01:45 Ken: GDPR, privacy, and the road to AI governance
03:32 Bob: when the models changed and the controls did not fire
04:50 What governance as code actually looks like
05:54 Where the policy code lives
07:06 Why gates also have to run at runtime
08:21 Will the CI/CD vendors build this?
09:20 Why the tooling is open source
11:07 Agent swarms, or viruses with credit cards
11:52 Ford: the puddle that flipped the car
14:10 GM: governance treated as a safety system
15:14 Over-the-air updates and automated targeting
16:07 Governance After Hours in San Francisco
16:42 The biggest misconception: governance as a brake
17:34 Unsafe at any speed
18:00 How much testing is enough
18:24 Red teaming and adversarial testing
19:14 The security analogy: shift left
19:53 Getting past the maybe gate
20:33 How many models do you test against
21:05 Inside Beacon
22:19 Umbrella, Lantern, and the audit layer
23:14 The Lean AI Handbook and the learning loop
24:47 Blast radius control and rollbacks
25:27 Data as the new oil, refined
26:54 Bob on where to start
28:23 Ken on his free e-book
29:26 Executive clarity and prototype theater
30:33 The one thing to remember
31:26 Wrap-up

In Lenin’s words

“The inconvenience for employees is I am running for service rather than the service coming to me.”

— Lenin Gali   (06:46)

“Literally, you ask a question in Teams or Slack, now you’re not waiting because the agent is really immediately responding.”

— Lenin Gali   (17:43)

“It’s not about volume of tickets. It’s about the outcome. Is the employee happy? Are they getting the service done? Is the quality of service correct?”

— Lenin Gali   (19:37)

“You’re not gonna get an ROI unless you justify in steps. You can’t just say you just use AI and it’ll work magically.”

— Lenin Gali   (22:18)

“There is no one way to solve any one problem. With AI, you’re actually getting that super intelligence capability.”

— Lenin Gali   (42:34)

“You can’t have 100 agents running wild and nobody knows what they’re doing.”

— Lenin Gali   (36:23)

“They need to also have a piloting system that knows, like a command and control, like air traffic control, just like that.”

— Lenin Gali   (37:45)

 

Resources

Lenin Gali and Atomicwork

Ideas and frameworks discussed

  • Employee service management: His reframe of IT service management. The employee is the recipient of the service, so the employee is the focal point and the service travels to them

  • Ticket deflection: The metric that replaces ticket volume once agents resolve and close issues without a human. Paired with quality of resolution and productivity time returned

  • Trust, security, governance, compliance: The four separate tests he says an enterprise AI vendor has to pass. Trust is transparency and logs, governance is guardrails and an off switch, compliance is the standards and procedures

  • Level one, two and three agents: Agents arranged in the same escalation hierarchy as human support, triaging first and handing off to a system-specific agent, rather than one super agent doing everything

  • Agent identity and IGA: Identity governance and administration as the foundation. Every agent gets an identity so that any action can be traced to the agent that took it

  • Air traffic control for agents: His image for an agent control system: a registry where a deployed agent has a role and an entry, so nobody is running agents nobody can account for

Named on air

  • Global CIO Circle: The CIO community he runs, which he describes as moving what one CIO has actually deployed into the hands of the others

  • NANDA, MIT: The open source project defining standards and protocols for the agentic internet, led by Ramesh Raskar. He was present when it was introduced at an MIT innovation forum

  • MCP and A2A: The agent registration approaches he names when describing how an agent gets tracked once deployed

  • Okta: His example of the single sign-on layer that already governs who gets access to an application and for how long

Related AI Realized episodes and events

 

Frequently Asked Questions

 
 
 
 
 
 
 
 
 
 
 
Previous
Previous

Threat Intelligence Is a Board Question, Not an IT One

Next
Next

Never Surrender Agency to the Agent