Flagship build
Zendesk AI Support Copilot + Jira on AWS
A human-reviewed support system combining cited AI assistance, explicit safety routing, a native Zendesk app, a verified Jira handoff, and controlled AWS commissioning.
Controlled AWS commissioning completed. The runtime was decommissioned after closeout, with an encrypted recovery snapshot retained.
Back to selected workHuman control remains visible from review to callback.
The five frames follow the same controlled path across the native Zendesk app, Jira, the fixed evaluation, and the commissioned AWS runtime.
The safety model is part of the workflow.
Citations, confidence, sensitive-data checks, injection controls, and policy decide what reaches human review.
The native Zendesk app keeps every suggestion private and requires an explicit approval before provider writes.
Jira receives one approved task and returns its issue key without replay creating a second work item.
One controlled operating path.
The system keeps AI assistance private, makes approval explicit, and verifies the engineering outcome back against the originating case.
- 01 / INTAKEControlled Zendesk case
Only the configured synthetic ticket can enter the commissioned provider-write path.
- 02 / ROUTECited AI decision
Retrieval, confidence, safety signals, and policy produce a private draft, escalation, or block.
- 03 / REVIEWHuman authority
The agent sees the sources and decision state before approving a bounded private action.
- 04 / HANDOFFVerified Jira return
One Jira task is created and its issue key returns through a protected callback.
No autonomous public reply.
Every route records mandatory review. The Zendesk app can present a private suggestion or prepare an escalation, but cannot send a customer-facing message.
Retrieval and generation stay inspectable.
Approved sources, citations, model output, policy decisions, and safety signals remain separate so an operator can review why the route was chosen.
The Jira transition is replay-safe.
An atomic outbound claim and conditional callback transitions stop repeat approval or a fast callback from producing conflicting provider state.
The first provider run found a real defect.
The controlled escalation failed closed, the provider assumptions were repaired, and the same path completed without a duplicate note or task.
What failed.
Jira expected an existing issue in a webhook meant to create the first task. Zendesk tag timing also preceded exact CLI readback.
How it stayed bounded.
No public reply was available, no unbounded retry loop started, and no second Jira task was created.
How it was repaired.
The Jira rule accepted business data without a prior work item. The Zendesk fallback required the approved tag, a new private comment, and a changed provider timestamp.
Commissioned, verified, and closed out.
The fixed 40-case evaluation passed its defined thresholds. The provider path produced one approved private note, one Jira task, one verified callback, and zero public comments.
64 backend tests, three operator tests, and two Zendesk app tests.
Two services, seven alarms in OK state, and no critical or high image findings.
The former hostname is inactive. Historical logs and an encrypted recovery snapshot were retained.
Build AI support around human authority.
SM Systems can adapt the same retrieval, review, provider handoff, replay, and operating controls around an authorized Zendesk and Jira workflow.