ITAI

Automated IT troubleshooting for Windows fleets

ITAI: an extra pair of hands for every Windows ticket.

ITAI is a first-line tech for MSPs and IT teams. Describe a Windows problem in plain words and it does the legwork for your team: it reads logs, services and configuration, finds the cause, and writes up the fix with a rollback, usually in minutes. Your team reviews it, approves it, and moves on to the next ticket.

Root cause in plain English Every client's PCs in one place Fixes ready to approve From $1 per device
ACCT-12 · ticket "Finance share keeps dropping" · Local admin Awaiting review
PS> Test-Path \\FILESRV01\Finance
False
PS> Get-Service LanmanWorkstation | Select Status
Running: the client side is healthy
↪ the map says \\FILESRV01 serves this share, checking it
PS FILESRV01> Get-Service LanmanServer
Status StartType
Stopped Automatic
Finding. Nothing is wrong on ACCT-12. The Server service on FILESRV01 is stopped, so the Finance share is unreachable for everyone, not just this desk. ITAI knew FILESRV01 was the file server from the environment map and checked it directly.
Start-Service LanmanServer on FILESRV01 risk: low rollback: Stop-Service LanmanServer
A real-shaped ticket: the symptom is on one desk, the cause is on the file server. Press Approve step to run the fix. Until then, both machines have only been read.

How a ticket runs

How ITAI works, with a person holding the only key.

Every ticket follows the same six steps. The line between investigating and changing is enforced on the machine itself, not left to the AI.

Install once

Paste one line into an elevated PowerShell window, or run the installer package. ITAI runs as a Windows service and checks in with your dashboard.

Open a ticket

Pick the device, describe the problem in plain words, and choose the privilege level ITAI may investigate with.

ITAI investigates

It works through read-only commands: services, event logs, disk, network, configuration. If the answer lives on another machine, like a domain controller, it can check there too.

You get a finding

A plain-language cause, plus a remediation plan where every step carries a risk rating and a rollback command.

You approve

Open each step to review it, then approve all of the plan, some of it, or none. The approval is signed with your organization's key, and the device refuses any command it doesn't cover.

It's done, and on record

Approved steps run, and every command and its output lands in the ticket's permanent transcript.

See it work

One ticket, start to finish, in the ITAI dashboard.

The front desk printer queue is stuck. ITAI runs read-only checks on the PC, explains the cause in plain words and proposes three steps. The technician approves the two checked steps and leaves out the step ITAI could not double-check. Only the approved steps run, and the ticket's history keeps the record.

The real ITAI dashboard with sample data: the MSP, its clients, the devices and the command output are fictional. No sound.

Guardrails

Built so the AI can't act on its own.

Any AI can be wrong, and any AI can be tricked. So ITAI's limits don't depend on the AI behaving: they are enforced by the device, by signed approvals, and by a person approving every fix.

Diagnosis can't change anything, or phone home.

HowEvery investigation command is parsed on the device with PowerShell's own parser and checked against a read-only allow-list, and network checks can only reach your own network, hosts named on the ticket and a short list of known services. Anything else is refused before it starts.

No fix without a named person.

HowA technician has to open each step and review its exact command and rollback before it can be selected. Their name goes on the ticket.

Only what was approved can run.

HowApprovals are signed with a key unique to your organization, cover the approved commands byte for byte, can be used once and expire in five minutes.

Fixes are off until they're switched on.

HowEach new client starts diagnostics-only. Turning fixes on is a deliberate step for each client, and every change shows in Company settings with who made it and when.

A second AI checks the first.

HowA separate check, with none of the diagnosis in front of it, compares each step with its description, and always runs on our most injection-resistant model, whichever model you choose. A step it couldn't check needs an explicit acknowledgement.

A lost or hacked PC can be cut off on its own.

HowEach device has its own credential, so one machine can be locked out without touching the rest. Your PCs talk only to your dashboard, never to the AI directly.

Every command on the record.

HowEach command the AI ran, its full output, and who approved what are written to the ticket's transcript.

What ITAI will never do

  • Change anything on a machine while it is diagnosing.
  • Run a fix no one approved, or a command other than the one approved.
  • Use your tickets or device data to train AI models.
  • Start a diagnosis, or approve or send out a new fix, once a client has reached its monthly AI spend limit.
  • Keep your tickets forever: they are deleted 90 days after their last activity.

Also yours to control: a monthly AI spend limit per client, and a Data & privacy page where your admins export your data and your account owner can ask for it to be deleted. More detail under Security & privacy and in the security model.

Who it's for

IT support for MSPs, in-house IT teams and small businesses.

ITAI takes the first hour of investigation off a ticket. Every fix still needs a person to approve it.

Managed service providers

If you provide managed IT services, every client is its own organization in ITAI, with its own installer, key, devices and tickets, walled off from the others. Your technicians start each ticket from a finding instead of a blank remote session, and client organizations can share one billing account so the device tiers count your whole fleet.

In-house IT teams

Run a remote IT help desk without the first round of detective work. ITAI follows the evidence from the desk that reported the problem to the file server or domain controller where the cause actually is, and every command it ran is on the ticket for a senior tech to check. You can split your PCs into teams, such as Finance or HR, each with its own installer, devices and tickets.

Small businesses without IT staff

ITAI tells you in plain language what's wrong and what the fix would do, with a risk rating and a rollback for every step. Someone still opens the ticket and approves the fix, and installing needs admin rights on each PC. If you'd rather not do that yourself, an MSP can run ITAI for you.

Common problems

Windows IT support for the tickets that fill the queue.

Describe the symptom the way a user would. ITAI gathers the evidence with read-only commands, names the cause, and proposes a fix for you to approve. These are examples, not a fixed menu.

Printers offline or stuck

Reads the Print Spooler service, the queue, the printer's port and driver, and the print service event log. A typical plan restarts the spooler or clears a stuck job.

Network drives and file shares

Tests the path, the PC's Workstation service, DNS and the mapped drive. When the file server also runs ITAI, it checks the server side too, like the Finance share above.

Slow PCs

Looks at CPU, memory and disk use by process, free disk space, startup programs and recent errors in the event log, then says which one is the bottleneck.

Windows Update failures

Reads installed updates, the update services and the event log entries for failed installs, and reports the error code alongside what it points to.

Outlook and Office issues

Checks Office crashes and application errors in the event log, whether the mail server resolves and answers, and machine-level causes like a full disk. Settings inside a mailbox or a Microsoft 365 tenant are beyond what a PC can see.

VPN connections

Reads the VPN profile, network adapters, routes and DNS, and tests whether the gateway answers, to separate a local configuration problem from a network one.

Account lockouts

Reads sign-in and lockout events on the PC and, when your domain controller runs ITAI, the lockout records there, to find the machine a stale password keeps coming from.

What's in the box

Built for the people who get the call at 8:55.

Cross-device diagnosis

A login failure on a laptop is often a problem on the domain controller. ITAI follows the evidence to the machine where the cause actually is.

Learns your environment

ITAI builds a network map as devices enroll and report in: which machine is the domain controller, the DNS and DHCP servers, the file and print servers (with what they share), and the gateway. Every new diagnosis starts from that map, so it heads straight for the right machine instead of rediscovering the layout each time. Everyone in your organization can see the map. An admin can add entries by hand or delete them; an entry ITAI found on its own comes back while a device still reports it.

Privilege you choose

Investigate as the current user, a local admin, or SYSTEM. The highest level needs an explicit confirmation every time.

A full audit trail

Every command, its output, its exit code and its timing, recorded to the ticket. Nothing ITAI does is off the record.

Device inventory for free

Make, model, serial number, OS build, hardware and network identity are collected at install and kept current.

Made for MSPs

Separate organizations, each with its own installer and key. Rotate a key without breaking devices, and move a device between organizations with a full audit record.

A fleet that tidies itself

Devices that stop checking in are retired automatically after 30 days. You can change the window, and restore a retired device in one click for at least 90 days.

Security & privacy

An AI agent on your endpoints should be boring to audit.

ITAI's safety doesn't rest on the AI behaving well. The limits are enforced on the device, by code that sits between the AI and PowerShell.

Your PCs never talk to the AI

The dashboard makes every AI call. The service on each PC only runs the commands its policy allows and reports back, so no PC holds anything that can call the AI or run up your AI bill on its own.

Your data doesn't train anyone's model

Managed diagnostics run under our AI provider's commercial terms. Your tickets and device data are not used for model training.

Walled off from other customers

Every record belongs to one organization, and every request is scoped to it. Other customers never see your devices or tickets.

Bring your own key Coming soon

Connect your own AI provider account. Diagnoses run on your account and under your agreement with your provider, and you pay device pricing only.

1
Allow-listed commandsInvestigation may only run commands on a read-only allow-list. Anything else is refused before it starts.
2
Constrained PowerShellCommands run in PowerShell's Constrained Language mode, which blocks the techniques scripts use to break out.
3
Contained processesEach command runs inside a Windows job object, with limits on what it can spawn and how long it can run.
4
Signed approvalsChanges need an approval signed with your organization's own key, covering those exact commands, used once and expiring in five minutes. The device holds only the public key, so it can check a signature but never forge one.
5
Append-only transcriptEverything that ran is written to the ticket, where it can't be edited afterwards.

Compared

ITAI vs a traditional help desk or RMM.

A help desk is people working tickets by hand. An RMM tool monitors, patches and runs the scripts you give it. ITAI does the part in between: working out what's wrong, and proposing a fix you can check.

How ITAI compares with a traditional help desk and an RMM tool
QuestionTraditional help deskRMM toolITAI
Who investigates A technician, by hand, often over a remote session. Alerts point at a symptom; finding the cause is still manual, or a script someone wrote in advance. The AI, one read-only command at a time, and a technician reviews the finding.
What can run while investigating Whatever the technician types. Whatever the script does, with the rights it was given. Only commands on a read-only allow-list, enforced on the device.
How changes are made The technician makes them directly. Scripts and policies you deploy. A plan with a risk rating and rollback per step, run only after a named technician's signed approval, and only once fixes are turned on for that client.
The record The notes the technician writes up. The logs your tool keeps. Every command, its output and exit code, in an append-only ticket transcript.

ITAI works alongside the tools you already have. You can deploy the receiver with Group Policy, Intune or your RMM tool, and help desk integration is on the roadmap.

Pricing

A flat fee per machine, plus the AI you actually use.

Early-access pricing. Prices shown in USD or EUR.

Managed

$1per device / month
  • Drops to $0.90/device over 50 devices, $0.75 over 100
  • Plus metered AI usage, billed by the model you choose, from fast to most capable
  • $5 / month minimum
  • Retired devices stop counting
Coming soon

Bring your own key

$1per device / month
  • Same device tiers, no usage charge from us
  • Connect your own AI provider account
  • Runs under your own provider agreement

On the Managed plan you pay a per-device fee plus metered AI usage, billed by the model you choose, so no model (fast, capable, or in between) ever comes out of your margin. Bring-your-own-key customers pay the device fee only and run on their own account. Self-hosted and enterprise licensing: talk to us.

FAQ

Questions about ITAI.

What is ITAI?

ITAI is AI IT support for Windows PCs. It uses an AI model to do the investigative part of a technician's job: reading logs, services and settings to work out why something is broken. With ITAI, a technician opens a ticket for a Windows PC in the web dashboard, the AI diagnoses the problem by running read-only commands on that device, and it proposes a fix that a person approves before anything changes.

Is ITAI safe to use on business computers?

It depends on what the AI is allowed to do, and ITAI doesn't leave that to the AI. Investigation can only run commands on a read-only allow-list, checked on the device with PowerShell's own parser, in Constrained Language mode, inside a Windows job object. A change runs only after a named technician approves the exact command, and the device checks the approval's signature first. Fixes stay off for each new client until an admin turns them on, and every command and its output is recorded to the ticket.

Does ITAI fix problems automatically?

It diagnoses automatically, but it doesn't change anything on its own. ITAI proposes a remediation plan in which every step shows the exact command, a risk rating and a rollback command. Nothing runs until a technician opens the step, reviews it and approves it, and you can approve all of the plan, some of it, or none.

Can the AI change my machines without me?

No. While it diagnoses, the device only runs commands that pass a read-only allow-list, checked on the device itself. A fix runs only after a named person opens each step, reviews the exact command and approves it. That approval is signed with a key unique to your organization, covers only those commands, can be used once and expires after five minutes, and the device refuses anything it doesn't cover. For a new client, fixes are off entirely until an admin turns them on.

What if someone tries to trick the AI?

ITAI is built so that even a tricked AI can't change anything. The device enforces read-only diagnosis whatever the AI asks for, a separate AI check that sees none of the diagnosis compares each proposed step with its description and flags a mismatch, and nothing changes until a person approves the exact command. Text planted in a log, a file name or an event message may try to steer an AI, which is why these protections are built into the device and the approval, not left to the AI.

How much does IT support cost per device?

ITAI's Managed plan is $1 per device per month. Once a fleet passes 50 devices, every device drops to $0.90, and over 100 devices to $0.75. AI usage is billed on top of the device fee, by the model you choose, with a $5 monthly minimum. Retired devices stop counting. These are early-access prices in US dollars.

Can an MSP use ITAI for multiple clients?

Yes. Each client is a separate organization with its own installer, key, devices and tickets, and one client never sees another's. An MSP's client organizations can be grouped under one billing account, so the device tiers count the combined fleet rather than each client on its own.

Does ITAI work on Mac or Linux?

Not yet. ITAI supports Windows 10, Windows 11 and Windows Server today. macOS and Linux agents are on the roadmap.

Is our data used to train AI models?

No. Managed diagnostics run under our AI provider's commercial terms, and your tickets and device data are not used for model training. Every record is scoped to your organization, so other customers never see your devices or tickets.

What gets installed on each PC?

A small Windows service, the ITAI receiver. It makes only outbound HTTPS connections to your dashboard, so no inbound firewall ports are needed. It never contacts the AI itself: the dashboard does that, and the receiver only runs the commands its policy allows and reports back. It needs Python 3.10 or newer, which the installer can set up through winget.

Does ITAI replace our RMM or help desk software?

No. ITAI does the diagnosis and runs the fixes you approve. You can deploy it with Group Policy, Intune or your RMM tool, and integration with existing help desk systems is on the roadmap.

On the roadmap

Where ITAI is going next.

Help desk integration

Tickets that open themselves from your existing help desk.

Cross-platform support

macOS and Linux agents alongside Windows.

More AI providers

Support for additional AI providers, including ones you run yourself.

Self-hosted deployment

Run the whole dashboard inside your own network.

Put ITAI on a machine that's giving you trouble.

We're onboarding early customers one at a time. Tell us about your fleet.

Email support@itaibot.io

Documentation

Using ITAI

Everything you need to install ITAI, run your first diagnosis, and understand exactly what it can and can't do on your machines.

How ITAI fits together

ITAI has two parts. The dashboard is where your team opens tickets, reviews findings and approves fixes. The receiver is a small Windows service on each device: it checks in with the dashboard, runs the commands it's allowed to, and reports back.

A diagnosis is a conversation between the two. ITAI decides what to look at next, the receiver runs that one read-only command and returns the output, and this repeats until ITAI has a finding. Changes only happen after a person approves them.

Requirements

  • Windows 10 or 11, or Windows Server. macOS and Linux are on the roadmap.
  • Administrator rights on the device, to install the service.
  • Python 3.10 or newer, installed for all users. You don't need to install it first: if it's missing, the installer installs it (see below). It uses winget, or python.org's official installer where winget isn't available, such as on Windows Server 2019.
  • Outbound HTTPS from the device to your ITAI dashboard. The receiver only makes outbound connections, so no inbound firewall ports are needed.

Installing ITAI

Open Install in the dashboard. Every organization has its own installer, and a device joins the organization whose installer it ran.

Option 1: one line of PowerShell

Copy the command from the Install page and paste it into PowerShell opened with Run as administrator. It looks like this, with your organization's own values filled in:

powershell -ExecutionPolicy Bypass -Command "& { ... install.ps1 ... -ApiKey '<your org key>' -BackendUrl 'https://<your dashboard>' }"

Option 2: the installer package

Download the receiver package from the Install page, unzip it on the device, then right-click Install-ITAI.bat and choose Run as administrator. Use this where copying and pasting a command isn't practical.

Either way, the installer checks for Python, writes the device's configuration and starts the ITAIReceiver service. The device appears in your dashboard within a minute.

If Python is missing, the installer lists what it needs and asks before installing it (press Enter for Yes; no answer within a minute also means Yes). Pushed from an RMM tool or run as SYSTEM, where nobody can answer, it installs Python for all users without asking and says so in its output. Python comes from winget, or from python.org's official installer, checked before it runs. If you manage Python yourself, add -NoPrereqs to the command: the installer then never installs Python, and stops with instructions if it's missing. A progress bar, and a percentage on the output line for each step, show how far along it is.

Mass deployment: both options run unattended, so you can push them with Group Policy, Intune or your RMM tool.

Your first ticket

  1. Open the device from Devices.
  2. Choose Deploy agent. Describe the problem the way a user would report it, for example "Printer shows offline for everyone on the second floor".
  3. Pick a privilege level. Local admin is the default and right for most problems.
  4. Start the ticket. You can watch each command and its output arrive live.
  5. When ITAI finishes, read the finding and the proposed plan, then approve what you're comfortable with.

Privilege levels

This is the one decision ITAI asks you to make on every ticket. It sets the account ITAI investigates and fixes things with on that device.

LevelUse it forNotes
Current userProblems in one person's profile: an app setting, a mapped drive, a browser.Can't see system-wide settings or other users.
Local adminMost problems: services, drivers, updates, disk, network.The default.
Domain service accountProblems that need domain permissions.Not available yet.
SYSTEMDeep system problems that local admin can't reach.The highest privilege on the device. Needs an explicit confirmation each time.

The privilege level widens what ITAI can see, not what it can do unasked. Investigation stays read-only at every level.

Reviewing a plan

A plan is a list of steps. Each one shows the exact command, a risk rating, and a rollback command that undoes it.

  • Open a step to review it. Only a step you have opened can be ticked.
  • Approve selected steps runs only the steps you tick, in order.
  • Anything you don't approve never runs. You can close the ticket and fix it by hand instead.
  • Your approval is signed with your organization's key, covers only the commands you ticked, can be used once and expires after five minutes. The device checks the signature against its copy of your organization's public key, and refuses any step that doesn't match.
  • A step marked Not independently checked is one the second AI check couldn't assess. Read its command yourself: approving it records that you saw the warning.
  • If fixes are turned off for this client, the plan can be read but not approved. An admin turns fixes on in Company settings.
Read the plan before you approve it. ITAI explains its reasoning, but the approval is your decision and your record.

Ticket statuses

StatusMeaning
QueuedWaiting for the device to pick it up.
RunningITAI is investigating.
Awaiting reviewA finding and plan are ready for you.
ApprovedYour approved steps are running.
Resolved by ITAIThe approved fix worked.
Resolved manuallyA technician fixed it and closed the ticket.
Self-resolvedThe problem went away on its own.
No issues foundITAI looked and found nothing wrong.
UnreachableThe device didn't respond.
EscalatedNeeds a person: ITAI couldn't reach a safe conclusion.

Managing devices

Retiring and restoring

Retire a device you've replaced or decommissioned. It leaves the main list, stops counting toward per-device billing, and can't be targeted by tickets. Restore it at any time. Devices that stop checking in are retired automatically after 30 days; an admin can change that window.

Device profile

Each device reports its make, model, serial number, OS and build, hardware and network identity. It's refreshed on check-in and after every diagnosis, so the device page always shows the machine as it is now.

Organizations & keys

Each organization has its own installer key. Devices installed with it belong to that organization.

An MSP's dashboard calls its organizations Clients. A company's calls them Teams, such as Finance or HR. Either way they work the same.

  • Rotating a key issues a new one. The old key keeps working for a short overlap so devices can pick up the new one without an outage.
  • Unassigned devices land in a holding pool when they register with a key that isn't tied to one organization. An admin places them.
  • Moving a device between organizations is recorded with who moved it and why. ITAI flags a device whose domain or network looks like it belongs somewhere else.

Plans, models & caps

An admin sets these under Company settings.

SettingWhat it does
Device feeA monthly fee per active device: $1, dropping to $0.90 over 50 devices and $0.75 over 100, with a $5 monthly minimum per account.
AI usageOn the Managed plan, your diagnoses' AI usage is billed on top of the device fee. Bring your own AI key is coming soon.
AI modelThe model your organization's diagnoses run on. Lighter models are faster and cheaper; the most capable ones are best for hard problems. On the Managed plan, usage is billed by the model you pick, so any model is available.
Monthly spend limitThe monthly AI usage at which ITAI pauses for an organization. Every organization starts at $100; change or remove it in Company settings. A diagnosis already running when it is reached may finish its current work (up to 8 more AI calls each, billed as usual). Then no new diagnosis starts and no new fix is approved or sent to a PC until the limit is raised or the month turns. A fix already on a PC finishes, restart included. Device fees aren't affected.
Per-ticket capThe most AI usage a single ticket may consume. When a ticket reaches it, the diagnosis stops cleanly and tells you why.
CurrencyAmounts shown in US dollars or euros.

Security model

ITAI's safety doesn't depend on the AI making good choices. Five layers on the device stand between the AI and PowerShell:

  1. Allow-list. Investigation commands must match a read-only allow-list, or they're refused before they start.
  2. Constrained Language mode. Commands run in PowerShell's restricted language mode.
  3. Process containment. Each command runs in a Windows job object with limits on child processes and run time.
  4. Signed approvals. A change needs an approval signed by your dashboard. The device holds only the public key.
  5. Append-only transcript. Every command and its output is recorded to the ticket.

Around those layers:

  • Fixes off by default. A new organization is diagnostics-only until an admin turns fixes on. Every change is recorded and shown in Company settings.
  • A second check. A separate AI call, with none of the diagnosis in its context, compares each proposed step with its description. Mismatches are flagged, and a step it couldn't check needs an explicit acknowledgement to approve.
  • Devices never contact the AI. The dashboard makes every AI call. Each device authenticates with its own credential.
  • Retention. Tickets and transcripts are deleted 90 days after their last activity. Admins can export your data at any time, and the account owner can ask for it to be deleted.

Your data isn't used to train AI models. It's kept separate from other customers, with every record scoped to your organization.

Uninstalling

From the device page, choose Uninstall. For safety you type the device's hostname to confirm, and only admins can do it. The receiver stops, removes its service and install folder, and the device is marked uninstalled with an audit record.

Installing ITAI on the same PC again

After an uninstall from the dashboard, run the Install page's command on that PC at any time. The device comes back to your list by itself.

If ITAI was removed on the PC itself instead, for example its folder deleted by hand, the dashboard doesn't know it is gone and still holds that PC's credential. A new install under the same organization is then refused, so that no other machine can take the PC's place. Open the device's page, click Reset credential, then run the install command again.

FAQ

Can ITAI change something without asking?

No. Investigation is limited to read-only commands on the device itself. Changes run only from a plan a person approved, and the device checks the approval's signature first. For a new organization, fixes are off until an admin turns them on.

What happens if the AI suggests something harmful?

During investigation it can't run it: the command isn't on the allow-list. In a plan, you'll see the exact command, its risk rating and its rollback before deciding.

Does ITAI need inbound network access?

No. The receiver only makes outbound HTTPS connections to your dashboard.

Which AI models can we use?

You choose from the models your plan offers, from fast and economical to the most capable. Support for bringing your own AI provider account is coming.