| Request and ticket intake | Validate fields, match records, classify, enrich, route, and request missing evidence | Authenticated requester, stable IDs, eligible service, source evidence, policy, and owner | A message proves identity, urgency, entitlement, accuracy, or approval |
| Identity and access | Prepare or perform an expressly allowed entitlement action and verify the directory state | Authoritative identity, role policy, approver, separation of duties, minimum scope, and read-back | Employment, role, privilege, or prior access authorizes the requested access |
| Incident operations | Collect signals, correlate known records, retrieve runbooks, prepare updates, and execute bounded approved steps | Incident owner, severity rule, affected service, evidence, approved action, stop condition, and recovery path | Correlation proves root cause, a job response proves recovery, or closure ends the incident |
| Change and configuration | Validate a request, assemble evidence, schedule an approved change, execute a bounded action, and compare state | Named change authority, version, environment, window, test, backup, rollback, before-and-after proof, and sign-off | A generated plan or provider acceptance authorizes or completes a production change |
| Scheduled and batch operations | Start, monitor, retry, stop, and report allowlisted jobs under defined rules | Job identity, inputs, dependencies, limits, duplicate policy, completion criteria, affected-service check, and owner | A zero exit code proves the intended business or system result |
| Closeout and audit | Assemble records, unresolved items, notifications, retention, and reconciliation evidence | Accepted destination state, reviewer, remaining exceptions, incident linkage, retention rule, and sign-off | A closed ticket means every user, asset, service, or control reached the correct state |