IT Incident Responder Recommendation Engine
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Complex IT systems generate a flood of disparate event messages, overwhelming existing monitoring and management systems, which struggle to effectively process events, leading to prolonged mean-time-to-resolution (MTTR) and increased resource utilization due to manual and trial-and-error incident resolution methods.
Innovation Solution
A system and method using a machine-learning model recommendation engine to identify and recommend responders based on incident type, historical data, and responder skillsets or seniority levels, facilitating efficient incident resolution by associating the right responders with incidents.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual techniques and pre-programmed rules are used for incident resolution, then responders can address incidents with human judgment and adaptability, but the process becomes labor and computing intensive, increasing MTTR and resource utilization
Solution Approach 1:
The patent introduces an automated incident classification system and responder recommendation engine as an intermediary between incident detection and human responder action. This intermediary automatically analyzes incident data, classifies incidents by type and severity, and recommends appropriate responders based on historical data and skill matching, thereby reducing the manual effort and time required while maintaining effective resolution
Solution Approach 2:
The system performs preliminary actions by pre-classifying incidents and pre-identifying suitable responders before human intervention is needed. Historical data is analyzed in advance to build classification models and responder profiles, enabling rapid automated triage and recommendation generation when incidents occur, thus reducing MTTR without sacrificing resolution quality
2Productivity
If automated systems are used to process events in complex IT systems, then processing speed and scalability improve, but the systems struggle to effectively process events in complex and noisy environments, reducing accuracy
Solution Approach 1:
The system incorporates feedback mechanisms where incident classification results and responder recommendation outcomes are continuously analyzed to improve future classifications. Historical incident data and resolution outcomes feed back into the classification models, enabling the system to learn from past performance and improve accuracy over time while maintaining high processing speeds
Solution Approach 2:
The classification system is designed to be dynamic and adaptive, adjusting its parameters and models based on the complexity and noise characteristics of incoming event data. The system can dynamically switch between different classification strategies and adjust its sensitivity thresholds based on the current operational context, maintaining accuracy across varying system conditions
3Reliability
If more responders are retained to address incidents in networked systems, then incident coverage and response capability improve, but the complexity of managing and coordinating responders increases
Solution Approach 1:
The responder recommendation engine acts as an intermediary that manages the complexity of coordinating multiple responders. It automatically matches incidents with suitable responders based on skill sets, availability, and historical performance data, thereby maintaining comprehensive responder coverage while eliminating the need for complex manual coordination processes
Solution Approach 2:
The system creates virtual copies of responder profiles and incident characteristics to enable automated matching without requiring physical coordination of each responder-incident assignment. Digital representations of responder skills, availability, and incident requirements are processed algorithmically to generate recommendations, reducing management complexity while maintaining thorough coverage
Data Source
AI summary
An incident that requires a resolution responsive to an event detected in a managed information technology environment is triggered. An incident type is obtained for the incident, where the incident type is selected from a set that includes a rare type, a novel type, and a frequent type. Responsive to determining that the incident is of the rare type or the frequent type, a list of recommended responders to address the incident is generated using a machine-learning model. Responsive to determining that the incident is of the novel type, a list of recommended responders to address the incident is generated based on a seniority level of responders. A selection of one of the recommended responders is received. The one of the recommended responders is associated with the incident.


