Energy
Triaging and resolving recurring network incidents in the NOC.
An AI-agent platform adopted by the network operations centre (NOC) teams: it triages the most frequent alerts and now autonomously resolves around half of recurring monitoring incidents, with a human in the loop on sensitive cases.
Alert triaged in under 30s vs. 10 to 15 min manually
Around half of recurring incidents resolved autonomously (target MTTR under 5 min)
On the order of 2.5 FTE of recurring workload absorbed, redirected to engineering
Context
The network operations centre (NOC) supervises the group's networks across several countries and handles dozens of WAN and fibre alerts every day. For each one, an engineer reads the alert, gathers context (site, related equipment, incident history) and writes a ticket: 10 to 15 minutes of manual work per alert, representing 80 to 90% of the team's recurring workload, with quality varying by operator and time of day. Beyond triage, resolving these otherwise repetitive incidents also remained largely manual.
The challenge
- Manual, repetitive, high-volume triage
- Ticket quality varying by operator (day, night, weekend)
- Long diagnosis on otherwise recurring incidents
- Resolution still manual, even on simple, reversible cases
What we delivered
- An AI assistant for each engineer (playground), connected to the entire NOC ecosystem, able to query, correlate and generate scripts, not just answer
- A multi-agent AI platform (Claude on Amazon Bedrock, data hosted in Europe)
- Around fifteen connectors: network monitoring, firewalls, SD-WAN, SASE, logs, ITSM, CMDB, topology graph, cloud and identity
- Enriched ticket triage: correlations, history, topology and recommendation
- Autonomous resolution of deterministic, reversible cases: checking and closing self-resolved alarms, restarting flows, clearing flapping alarms, remote actions after validation
- On more complex cases, multi-source diagnosis, coordination with third parties (entities, carriers), pre-drafted communications and supervised one-click actions
- A human in the loop: autonomy covers only deterministic, reversible cases validated by the team
- Full traceability and tracking of cost and energy footprint (FinOps)
- Compliance with the group's security requirements: private access, encryption, network segmentation
The result
The most frequent case is now triaged in under 30 seconds, and the agent autonomously resolves around half of recurring monitoring incidents (target MTTR under 5 minutes on those cases, halved on the cases that remain assisted). Adopted within weeks by dozens of engineers across several countries, the tool absorbs on the order of 2.5 FTE of recurring workload (roughly 4,000 hours a year), redirected to higher-value engineering work.
Our approach
This agent wasn't built in one go. Each use case first emerges in a playground, where engineers test the assistant on the live network, then moves to autonomy once five criteria are met:
- Recurrence: the case comes up often enough to justify automation
- Determinism: the procedure is clear and reproducible
- Reversibility: the action can be undone without risk
- Observability: every step is traced and verifiable
- Team consensus: engineers approve the move to autonomy
Rollout stays gradual: the agent first observes (shadow), then suggests, then acts automatically. This method, more than the agent itself, is the reusable asset from one use case to the next.
Why it matters: teams don't just save time on triage, they see recurring incidents get resolved, without ever losing control. Autonomy stays confined to deterministic, reversible cases validated by the team.
What it proves: Intelligence Partners can deliver AI services connected to existing environments that move from triage to resolution, with security, observability, governance and a path to scale.
Technical detail
Amazon Bedrock AgentCore · Claude (EU inference) · Around fifteen MCP connectors (monitoring, firewalls, SD-WAN, SASE, logs, ITSM, CMDB, topology, cloud, identity) · Read-only access by default with an allowlist · Versioned prompts and regression tests · Confidence threshold before action · Per-agent budget cap and task-based model selection · Full traceability and kill switch · Human in the loop
Mission led by
Dorian Richard
Founder · Intelligence Partners