A user requests a password or access credential to be reset, after it has been established that the requester really is who they say they are. This occurs with service desk staff and IT administrators, usually within an identity management system or service desk system. It is one of the most common requests within IT support, and precisely because of that a good example to show when AI can and cannot take over a task.
Three axes determine the judgment here: volume, structuredness and compliance.
Volume (5). Password resets occur extremely frequently. Virtually every organization with a service desk processes dozens to hundreds of them daily. High volume with a repetitive pattern is exactly the kind of work where automation pays off fastest: every automated handling directly saves time, because the task repeats continuously.
Structuredness (5). The process has fixed steps: establish identity, check authorization, issue a new password or token, send confirmation. Little interpretation is needed — the input (a request) and the output (a reset) are clearly defined. That makes it technically easy to capture in an automated flow or chatbot agent.
Compliance (3). This is where the tension lies. A reset is only safe if the identity check is correct. Anyone who wrongfully gains access through weak or bypassable verification can reach sensitive systems. That is not a matter of convenience, but of security: the reliability of the verification step determines whether automation is responsible, not the reset action itself.
Discretion (2) and creativity (1) are low: there is hardly any weighing to be done, it is execution according to protocol. Customer contact (4) is relevant because the user is often frustrated (locked out of a system), but that does not require tailored empathy — a clear, fast handling is usually sufficient. Physical (5) plays no role; everything happens digitally. Cost of error (3) is moderate: a wrongly issued access credential can cause damage, but can usually be quickly remedied by blocking it again.
The combination of high volume, high structuredness and a compliance risk that mainly sits in the verification step leads to the judgment: an AI agent can take over this task today, provided identity verification is reliably set up and a self-service portal is available where the user can go themselves. Without those two preconditions, the task automatically shifts to category two: AI can prepare or execute it, but a human must approve the identity check before the reset actually takes place.
An example to illustrate. At an organization with multi-factor authentication, a linked employee register and a portal where employees can identify themselves with a second verification factor, a reset is a matter of seconds — fully automatic, without service desk involvement. At an organization where identity is only established by phone ("what is your date of birth and employee number"), it is different: that verification is easy to bypass and does not lend itself to full automation without additional controls. Same task, different judgment — precisely because the compliance axis turns out differently per organization.
At organizations with heightened security requirements — for example access to financial systems, medical records or critical infrastructure — the compliance axis can weigh much more heavily than described here. There it is common that a reset request for certain systems is always assessed by a human, even if the identity check is in order, simply because the cost of error of an incorrect reset is unacceptably high. Also, when access management is part of a broader authorization process — comparable to what you see with screening customers and partners against sanctions lists — the emphasis shifts from speed to diligence, and thereby from category one to category two.
These kinds of shifts are precisely why a task can never be judged by the name of the function, but on the basis of the eight axes such as structuredness, volume and compliance. The same logic applies, for example, to access and authorization tasks within what work can AI take over in procurement, where supplier accounts and payment rights call for similar trade-offs between speed and control.
This judgment says nothing about the question of whether a service desk can become smaller or what role an employee retains within it. It concerns the task, not the person who currently performs it. Decisions about staffing and job design have their own legal requirements and fall outside the scope of this page.
Would you like to know how password and access resets relate to the rest of your service desk or IT task portfolio, and which part of it already qualifies for automation today? The free quickscan from ftetoai consists of twelve questions, requires no account, and gives an indication of what portion of the hours in your profile can already be taken over by AI today. The full work scan, which goes deeper into specific systems and processes, is still under construction — so we don't yet offer that here, but the quickscan already provides a first, well-founded direction.
Vraag maar. Ik ken de kennisbank van deze site; wat ik niet weet, zeg ik erbij.
Answers come from this site’s knowledge base. Not tailored advice, and not a scan of your company.