This session presents a lightweight AI assistant built to help a Security Assurance team review policy exception tickets more efficiently. The assistant summarizes tickets, generates follow-up questions, and maps requests to internal standards to support faster reviews.
The solution uses GitHub Workflows, a custom MCP server and client written in Go, ServiceNow integration, and Python-based evaluation. We used RAGAS to assess relevance and hallucination risk, and verified that the assistant retrieved internal standards through MCP calls.
We will share early results, including meaningful time savings in ticket review, as well as practical challenges such as stakeholder alignment, service account access, and the difficulty of evaluating correctness in security workflows. Attendees will leave with a practical blueprint for building a standards-grounded AI workflow for security review. In our implementation, the initial review step dropped from about 60 minutes of manual effort to about 50 seconds of automated generation plus validation, a time savings of roughly 98.6% per ticket.
___________________________
Presentation Language: English
Captioning will be available for attendees in 50+ languages through Wordly. See instructions in each room to utilize captioning.