How it works

Four steps. No phone calls.

AlwaysOnIT replaces the helpdesk layer of a traditional MSP with a single autonomous AI agent. Here is what happens from the moment you sign up to the moment a ticket closes.

01

Secure sign-up

Create an account with your work email and a passkey. Your tenant is provisioned in a UK region with per-organisation encryption keys before you ever raise a ticket.

02

Identity verification

Each user verifies through your existing identity provider — Microsoft Entra, Google Workspace, or Okta. Device posture is checked on every session, so the AI always knows it's talking to the right person on a trusted endpoint.

03

Live AI support via chat

Open a chat from the web app, Slack or Teams. The AI replies in seconds, holds full context across your devices and prior tickets, and stays available 24/7 — including weekends and the small hours.

04

Automated fixes and guidance

For approved task types the AI acts directly: rotates tokens, resets MFA, restarts services, applies group policy, runs scripted fixes. Where action isn't appropriate, it walks you through the steps with clear, copy-pasteable instructions.

05

Clear boundaries on unsupported issues

If a request falls outside our scope — anything physical, regulated workloads, custom development — the AI says so plainly, points to the page that lists it, and suggests a sensible alternative. No vague promises, no quiet drop-offs.

Under the hood

A single model, scoped tools, narrow blast radius.

Reasoning

A frontier LLM held to a strict IT-support system prompt. Hallucinated fixes are blocked by tool-level validators before they reach a device.

Tools

A curated set of typed actions: M365 admin, Intune/Jamf MDM, Okta/Entra, Google Workspace, common SaaS APIs. Anything outside the set is refused.

Approvals

Destructive actions (mailbox deletion, mass policy changes, off-boarding) require an in-band approval from a named admin on your side.

Decision framework

How support decisions are made.

AlwaysOnIT is autonomous. There are no technicians sitting behind the chat — the AI agent decides what to do with each request by running it through five fixed checks. The same checks apply at 03:00 as at 15:00, to every customer, on every ticket.

01

Identity & subscription verification

Every request is tied to a verified user on an active subscription. Unverified sessions get nothing account-specific.

02

Physical access requirement

If a fix would require touching hardware, cabling, or being in a building, the request is out of scope by definition.

03

Platform support

The request must concern a platform on the supported list — Microsoft 365, Google Workspace, Entra, Okta, Intune, Jamf, common SaaS. Other platforms are declined.

04

Risk level

Low-risk reversible actions are executed directly. Destructive or wide-blast-radius actions require an in-band approval from a named admin.

05

Certainty of outcome

If the agent cannot reach a high-confidence answer with the data available, it says so plainly rather than guess.

Issues we handle automatically

Inside the framework

These pass all five checks: verified user, no physical access needed, supported platform, acceptable risk, high certainty of outcome. The agent acts or guides directly, in chat, in seconds.

  • Password resets and MFA re-enrolment on verified accounts
  • Microsoft 365 and Google Workspace mailbox, calendar and sharing issues
  • Email delivery diagnostics — SPF, DKIM, DMARC, quarantine review
  • Conditional access, sign-in failures, token and session troubleshooting
  • Device posture checks and guided fixes on Windows, macOS and mobile
  • SaaS account provisioning and de-provisioning through supported APIs
  • Security hygiene guidance and read-only backup recovery walkthroughs

Issues we don't handle (and why)

Declined, with the reason stated

When a request fails one of the checks, the agent says so plainly and explains which check it failed. No vague holding replies, no quiet drop-offs.

  • Physical hardware repair

    Requires being on site. The agent operates entirely online.

  • On-site networking, cabling or electrical work

    Outside the scope of a remote-only service.

  • Emergency incidents requiring physical access

    A locked server room or a dead switch needs hands, not chat.

  • Regulated workloads (FCA-supervised, NHS clinical systems)

    These require named accountable engineers under specific certifications we do not hold.

  • Bespoke software development and custom integrations

    Out of scope for a support service. We diagnose and configure, we do not build.

  • Anything unsafe, unlawful, or beyond a verified user's authority

    Refused on principle, regardless of how the request is phrased.

Frequently asked questions

How AI-run IT support works, answered

The questions people most often ask before they trust an AI agent with their Microsoft 365 tenant.

What happens when I raise a ticket?

You open the chat and describe the problem in your own words — there is no form, category picker or priority field to complete. The AI agent reads the description, asks any clarifying questions it needs, and begins diagnosis immediately. For guided issues it gives you numbered steps tailored to your operating system and Microsoft 365 configuration. For actions that touch your tenant, it verifies your identity first, performs the change, and then confirms exactly what was done. The conversation stays open until you say the issue is resolved. There is no ticket reference to chase and nothing sits in a queue overnight waiting for someone's shift to begin.

How does the AI verify who I am before changing anything?

Identity verification runs before any account-affecting action, including password resets, MFA re-enrolment, mailbox permission changes and off-boarding. Verification uses signals tied to your account rather than to the chat conversation — your authenticated session, your verified work email address and, where enabled, your second factor. This matters because the most common attack against a helpdesk is social engineering: someone convincing an agent to reset a password for an account they do not own. Because the AI will not act on persuasion alone, that route is closed. Read-only guidance and diagnostics are given freely; privileged changes always require the verification step to complete first.

How long does a typical issue take to resolve?

First response is typically under thirty seconds, at any hour. Straightforward requests such as a password reset, an MFA re-enrolment, a distribution list change or a licence assignment are usually complete within a few minutes of the conversation starting. Diagnostic work — an Outlook profile that will not sync, a Teams call quality problem, a device that boots slowly — depends on how quickly you can run the checks the AI suggests, but is normally resolved inside a single conversation. Because there is no queue and no escalation tier, there is no waiting between steps. Issues outside our published scope are identified in the first reply rather than after a delay.

Do I need to install any software or agents?

No. AlwaysOnIT is delivered entirely through the browser-based chat, so there is nothing to deploy, no endpoint agent to roll out and no management console to learn. That keeps onboarding to minutes rather than weeks and means the service adds no software to your device estate for you to patch or trust. Device diagnostics for Windows and macOS are handled by the AI walking you through the built-in tools already on the machine and interpreting what you report back. If your policy forbids third-party agents on endpoints, this model is a good fit precisely because there are none.

What happens if the AI cannot fix my problem?

It tells you straight away, explains why, and points you at the right route. There is no human escalation tier — that is a deliberate design decision, not a gap we are hiding. If the issue needs physical presence, involves on-premise server or network hardware, or falls into a regulated workload we do not cover, the AI says so in its first or second reply rather than keeping a ticket open. Where it can still help indirectly, it will: writing up a clear technical summary you can hand to a hardware engineer, or explaining precisely what to ask a vendor. Our published scope pages set the boundary out in advance.

Is the AI available outside UK business hours?

Yes. The service runs 24 hours a day, seven days a week, including weekends and public holidays, with no out-of-hours premium and no on-call rota. This is one of the clearest structural advantages of an AI-run helpdesk: capacity does not vary by time of day, so a Sunday-evening lockout gets the same sub-thirty-second first response as a Tuesday morning. For distributed teams working across UK, Irish and European time zones, that means nobody is stranded because their working day sits outside a support window. There is no queue that builds up overnight and gets triaged in the morning.

How does this compare with a traditional MSP helpdesk?

A traditional MSP helpdesk routes your ticket to whichever technician is free, works to an SLA measured in hours, operates mainly in business hours, and typically costs £30 to £80 per user per month. AlwaysOnIT answers in seconds, works around the clock, costs £4 per user per month and handles every conversation with the same agent and the same context. The honest trade-off is that an MSP can send someone to your office, manage physical infrastructure and take on regulated environments. AlwaysOnIT does none of those. For cloud-first SMEs whose tickets are overwhelmingly accounts, email, licensing and devices, the AI model wins on speed and cost.

Get started

Open a chat. The AI picks up before the second ring — every time.

No onboarding calls. No sales process. Connect your devices and start raising tickets in under ten minutes.