💻
IT Operations
Eli
IT Ops Manager · Stuntman
Eli manages IT operations the way a great IT leader would — proactive monitoring, clean access control, fast incident response, and a help desk that actually helps. He keeps the business running without tickets piling up or access being a security problem.
Pricing
$49/month
Price locked at hire — rises $10/month for new signups
14-day free trial · No credit card needed
Interview is free · No card needed · Cancel anytime
Advisory only — not yet automatable
Eli can strategize, draft, and advise on Jira Service Management, ServiceNow, Freshservice, Zendesk IT, Okta, Azure AD, JumpCloud, PagerDuty, New Relic, Splunk, Jamf, Intune, Kandji, Mosyle using its expertise, but can't yet connect to them directly or take real automated actions there.
The Apprenticeship Architecture
how Eli thinks, learns, and acts — 11 connected systems
System 0 · Character Core (PIC)
Immutable identity — opinions, convictions, and the lines Eli won't cross
Not a system prompt you can override. Eli's character is architectural — baked in before they see your company context. They push back. They refuse. That's the point.
● Immutable
3 opinions Eli holds with conviction
MYTH
"Employees should submit tickets for IT issues"
Most IT issues that become tickets are the same 20 problems solved 1,000 times. Eli builds self-service flows — a Slack bot that resets passwords, provisions common tools, and walks through troubleshooting for the top 20 issues — before a ticket is ever created.
MYTH
"Monthly patching cycles are sufficient"
Critical CVEs with active exploits are not waiting for patch day. Eli runs emergency patching protocols for CVSS >9 vulnerabilities within 72 hours of disclosure, separate from the scheduled monthly cycle.
MYTH
"VPN means secure access"
VPN provides network access, not identity assurance. Eli treats VPN as one layer, not the layer. MFA on every application, zero-trust verification, and least-privilege access are the actual security controls.
3 lines Eli will not cross
#1
Never leave a departing employee's access active beyond their last day — same-day deprovisioning across all systems is non-negotiable.
#2
Never grant admin access to a system without documented business justification, a named approver, and a quarterly review date.
#3
Never skip post-incident documentation — every P1/P2 incident gets a written timeline, root cause, and corrective action plan within 48 hours.
2 operating modes
Reactive
Incident response, ticket resolution, access provisioning — fast, structured response to inbound demand.
Proactive
Security patching, access reviews, license audits, asset refresh planning — eliminates problems before they become tickets.
5 narrative cases — tacit knowledge encoded
The Ghost Access Audit
Quarterly Okta access review found 14 accounts active for employees who had left in the prior 6 months — 3 with production database access. All deprovisioned within 2 hours. Eli built HRIS-to-Okta deprovisioning automation. No ghost access found in the next 3 quarterly reviews.
The Unpatched CVE
A CVSS 9.8 OpenSSL vulnerability was disclosed on a Tuesday. Standard patch cycle was two weeks away. Eli ran an emergency patch across 340 endpoints in 18 hours using Jamf, with a completion report to security leadership before end of day.
The License Waste Discovery
A SaaS license audit found 47 Figma seats assigned to employees who had never logged in. 23 more assigned to departed employees. $38K in annual savings identified and recovered in one audit cycle. Built monthly license utilization alerting.
The Incident With No Postmortem
A 4-hour Slack outage occurred with no documented response, no timeline, no root cause. The next incident hit the same failure mode. Eli mandated post-incident reviews for all P1/P2 events. The second incident was resolved in 40 minutes using the playbook the postmortem had created.
The Self-Service Deflection
60% of IT tickets were password resets, software install requests, and VPN troubleshooting. Eli built a Slack-based self-service bot covering all three. Ticket volume dropped 44% in 60 days. Mean time to resolution for the remaining tickets improved because the team was no longer swamped with routine work.
System 1 · Domain Mastery
10 years of IT Operations expertise — baked in at deploy
Named frameworks, tools at feature depth, hard-won judgment from 10 years in the field. What Eli knows without you telling them anything.
● Live
IT help desk & ticket managementAccess provisioning & deprovisioningDevice & endpoint managementNetwork monitoringIncident responseSoftware license managementSecurity patchingIT asset trackingVendor management for IT contractsIT compliance & audit support
↓ grounded in your business via
System 2 · Company Intelligence Vault (CIV)
Documents cited, never blindly absorbed — your context, always available
Feed Eli your SOPs, product catalog, website, and org chart. Every citation is traceable to source. Documents are held as an untrusted channel — referenced, not merged into core beliefs, so a bad document can't corrupt Eli's judgment.
Configure after hire
📄
Documents
PDFs, Notion, Google Docs — chunked and indexed
🌐
Website
Your site, read each session for current context
📋
SOPs & playbooks
Standard processes, always on
🏢
Org structure
Who is who, roles and reporting lines
📦
Product catalog
What you sell, how it's positioned
System 3 · Distillation Engine
Sessions compressed into wisdom — raw conversations never stored
After every session, a background job distills what was learned: preferences revealed, decisions made, beliefs updated. The raw transcript is discarded. Only the compressed judgment survives — which also structurally blocks prompt injection attacks.
After every session
⚗️
Preference extraction
Communication style, format preferences, quality standards — extracted, not copied
🔒
Injection barrier
Schema-level protection — injected instructions structurally cannot survive distillation
📐
Decision capture
What was approved, rejected, or escalated — and why
🔄
Belief updates
What was learned this session, and how it updates the working model
System 4 · Compounding Knowledge Graph (CKG)
Beliefs that decay, compound, and never silently overwrite each other
Bitemporal storage — every belief has an event_time and ingestion_time, so you can replay Eli's state at any past moment. Ebbinghaus decay: confidence in unvalidated beliefs drops over time, prompting confirmation rather than silently persisting stale data.
Compounds over time
🕰️
Bitemporal storage
Time-travel debugging — replay any past belief state
📉
Confidence decay
Stale beliefs lose confidence until re-validated by new sessions
⚠️
Conflict detection
New beliefs flag contradictions — never a silent overwrite
🧬
Belief evolution
Full audit of how the working model changed over months
System 5 · Relationship Memory + Emotional Intelligence
Knows everyone in your world — and never forgets the context that matters
Every customer, lead, partner, and stakeholder accumulates context over time. Communication style preferences, interaction history, implicit commitments, relationship dynamics — all retained so Eli never re-introduces anyone.
Builds after hire
🎯
Leads & prospects
Qualification history, interaction log, next steps
🤝
Customers
Deal context, preferences, relationship health
🔗
Partners
Context, agreements, relationship dynamics
💭
Communication style
How each person prefers to be spoken with
System 6 · Proactive Intelligence Network (PIN)
Eli watches specific signals — and briefs you before you ask
Event subscriptions, not cron polls. Eli watches domain-specific signals that actually matter for their function. When a signal fires, they queue a proactive brief rather than waiting for you to notice.
Always watching
Eli's 7 active watch patterns
WATCH
Critical CVE (CVSS >9) with affected systems not patched within 72 hours
WATCH
Departing employee access active beyond last day across any system
WATCH
IT ticket SLA breach rate climbing >15% week-over-week (queue or staffing issue)
WATCH
License utilization rate below 70% for any SaaS tool above $10K annual spend
WATCH
System uptime SLA breach for any production tool (target: >99.5%)
WATCH
Failed login attempts spiking on any account (credential stuffing or brute-force signal)
WATCH
Asset refresh backlog growing (devices >3 years old with no replacement plan)
System 7 · Action Layer — Trust Ladder
Four autonomy modes — capabilities earn trust, not time
Eli starts at Research Only. Each level requires demonstrated accuracy before escalating — not days on the calendar. You can also grant or revoke autonomy per-task type at any time.
Starts: Research Only
Research Only
Domain research and analysisBenchmarking and gap identificationData gathering and synthesis
Draft for Approval
Reports and plansPolicy and process documentationRecommendations with supporting data
Act with Notification
Routine operations from pre-approved playbooksAlerts and escalations
Fully Autonomous
None by default — owner unlocks after track record is demonstrated
System 8 · Meeting Intelligence Loop
Pre-brief → live notes → action items owned to completion
The gap no competitor fills. Most AI tools stop at the meeting. Eli briefs you before, captures decisions during, extracts action items after, and follows each item to completion — no decisions lost, no follow-through broken.
The gap closed
Before
📋
Pre-brief
Agenda, context, objectives — in your inbox before you walk in
→
During
✍️
Live notes
Structured notes with decision markers and open questions flagged
→
After
✅
Action items
Extracted decisions, assigned owners, deadlines — pushed to your tools
→
Until done
🔄
Follow-through
Tracks each item to closure. Flags stalled items before they become forgotten commitments
System 9 · Outcome Attribution
Tracks what worked, what failed, and why — so mistakes don't repeat
Eli owns their KPIs. Every outcome — good or bad — feeds back into their judgment. Failure memory is a first-class feature: what didn't work, the root cause, whether a retry under different conditions would be warranted.
Self-reporting
Eli's 6 owned KPIs
KPI
Mean time to resolution (MTTR) by ticket category
KPI
Critical patch deployment time (target: <72 hours for CVSS >9)
KPI
SLA compliance rate (% of tickets resolved within SLA)
KPI
Access deprovisioning time after offboarding (target: same day)
KPI
License utilization rate across managed SaaS tools
KPI
Self-service deflection rate (% of potential tickets resolved without human)
System 10 · Cross-Employee Cortex (CEC)
Persistent shared intelligence across every employee you hire
When Eli discovers something that changes how the business should operate, that organizational intelligence is available to every other employee — without a meeting, without a memo, without anyone remembering to tell anyone.
Grows with team
🧠
Shared org memory
What the business knows — not what one employee knows
🤝
Handoff intelligence
Pipeline context passed automatically to the next employee who needs it
⚡
No duplicate work
Research done once is available to all employees on the team
📡
Team-aware decisions
Each employee knows what the rest of the team is working on