Flagship build

Zendesk AI Support Copilot + Jira on AWS

A human-reviewed support system combining cited AI assistance, explicit safety routing, a native Zendesk app, a verified Jira handoff, and controlled AWS commissioning.

View GitHub repository

Controlled AWS commissioning completed. The runtime was decommissioned after closeout, with an encrypted recovery snapshot retained.

Back to selected work

The safety model is part of the workflow.

CONTROLLED ROUTINGDraft, escalate, or block

Citations, confidence, sensitive-data checks, injection controls, and policy decide what reaches human review.

HUMAN AUTHORITYNo public-reply path

The native Zendesk app keeps every suggestion private and requires an explicit approval before provider writes.

ENGINEERING HANDOFFOne task, verified callback

Jira receives one approved task and returns its issue key without replay creating a second work item.

One controlled operating path.

The system keeps AI assistance private, makes approval explicit, and verifies the engineering outcome back against the originating case.

  1. 01 / INTAKEControlled Zendesk case

    Only the configured synthetic ticket can enter the commissioned provider-write path.

  2. 02 / ROUTECited AI decision

    Retrieval, confidence, safety signals, and policy produce a private draft, escalation, or block.

  3. 03 / REVIEWHuman authority

    The agent sees the sources and decision state before approving a bounded private action.

  4. 04 / HANDOFFVerified Jira return

    One Jira task is created and its issue key returns through a protected callback.

No autonomous public reply.

Every route records mandatory review. The Zendesk app can present a private suggestion or prepare an escalation, but cannot send a customer-facing message.

Retrieval and generation stay inspectable.

Approved sources, citations, model output, policy decisions, and safety signals remain separate so an operator can review why the route was chosen.

The Jira transition is replay-safe.

An atomic outbound claim and conditional callback transitions stop repeat approval or a fast callback from producing conflicting provider state.

The first provider run found a real defect.

The controlled escalation failed closed, the provider assumptions were repaired, and the same path completed without a duplicate note or task.

What failed.

Jira expected an existing issue in a webhook meant to create the first task. Zendesk tag timing also preceded exact CLI readback.

How it stayed bounded.

No public reply was available, no unbounded retry loop started, and no second Jira task was created.

How it was repaired.

The Jira rule accepted business data without a prior work item. The Zendesk fallback required the approved tag, a new private comment, and a changed provider timestamp.

Commissioned, verified, and closed out.

The fixed 40-case evaluation passed its defined thresholds. The provider path produced one approved private note, one Jira task, one verified callback, and zero public comments.

VALIDATION69 automated checks

64 backend tests, three operator tests, and two Zendesk app tests.

AWS AT CAPTUREHealthy and monitored

Two services, seven alarms in OK state, and no critical or high image findings.

CURRENT STATERuntime decommissioned

The former hostname is inactive. Historical logs and an encrypted recovery snapshot were retained.

Build AI support around human authority.

SM Systems can adapt the same retrieval, review, provider handoff, replay, and operating controls around an authorized Zendesk and Jira workflow.

Start a project