Loading_
Loading_
A catalogue-driven employee portal where 82% of requests fulfil themselves without ever creating a ticket.
Measured outcomes
3.2 min
Median fulfilment time
−61%
Service desk volume
148
Catalogue items live
99.95%
Fulfilment success rate
Service desk volume was dominated by requests that had a deterministic answer: software installs, distribution list membership, VPN access, mailbox permissions. Each one still cost a human 12–20 minutes.
The portal turns each of those into a catalogue item with a defined approval chain and an automation behind it. The request is the fulfilment — there is no queue in between.
Headline result
0%
requests self-fulfilled
Tags
Five capabilities that define the system. Each one exists because something specific was broken.
Items render from a schema, so adding a request type is a config change rather than a release.
Approval chains resolve from cost, risk and the requester’s reporting line at submission time.
Requesters watch each automation step complete in real time instead of waiting on an email.
The catalogue only shows what the user is actually eligible for, computed from group membership and licence pool.
When an automation fails a precondition it opens a pre-populated ticket rather than dead-ending the user.
A schema-driven form engine in front of a durable workflow runtime, with entitlement resolved at render time.
3 components
One definition drives the form, the API contract and the audit record.
3 components
Durable execution survives restarts — a half-finished onboarding never gets lost.
4 components
Each connector is idempotent and safe to retry.
No mystery components. Everything below is either open source or a platform you already own.
Interactive mock-ups of the shipped interface. The live environment is available during a demo session.
Entitlement-filtered request tiles with search
The running environment is available during a booked session — including a sandbox tenant you can drive yourself.
The real sequence, in order. Steps with a command are copy-pasteable.
Container Apps environment plus a managed Temporal namespace.
$az deployment group create -f infra/main.bicepLoad starter catalogue definitions and map approval groups.
$npx aiinfraengine catalogue import ./catalogueGrant the app registration scoped Graph permissions and register the AD service account.
Enable for one business unit, measure fulfilment success, then widen.
Published rather than hidden behind a call. Volume and multi-year terms move these numbers.
Portal licence
$3.50per employee / month
Catalogue build
from $32kone-time
Need this scoped against your estate? We will size it properly, in writing, within a week.
Request a quoteWe will walk you through the architecture, the trade-offs we made, and what would change for your environment.