

At Westpac, a major player in the Australian financial market, the response time to critical IT incidents has been slashed from hours to mere seconds. Previously, a CPU or memory overload alert could sit in a queue for half an hour or an hour until the problem resolved itself or led to a failure. Now, the entire cycle from data collection to attaching context to a ticket takes moments. This was made possible by implementing an AI agent that automated event processing and added deep context to every ServiceNow ticket.
In a bank's IT infrastructure, incidents don't wait. Every minute of downtime means not only financial losses but also reputational risks that can be more costly than money. The traditional scheme, where an alert becomes a ticket and then waits for a human to investigate it, is too slow and inefficient. People spend hours on routine data collection that can be obtained automatically. This is not just inconvenient; it represents direct losses that can be avoided.
The IT infrastructure of a giant like Westpac is a complex system with thousands of interconnected components. Hundreds, if not thousands, of alerts about potential problems are generated daily: processor overload, insufficient RAM, service failures. Each such alert required an engineer's attention.
Without automation, the process looked like this: a monitoring system detects a problem and generates an alert. This alert becomes a ticket in the incident management system (ServiceNow). Then, a duty specialist (L1/L2 support) takes on this ticket. They manually begin to gather context: what exactly happened, which processes are consuming resources, are there errors in the logs, which services are affected. This consumed precious time—from half an hour to an hour, sometimes even more. During this time, the problem could worsen, lead to cascading failures, or, conversely, resolve itself, leaving the engineer with outdated information.
This approach led to several critical problems: high cost of incident response due to manual labor, delays in problem resolution, a high risk of human error, and, consequently, a reduction in the overall stability of IT systems.
Westpac had long used automation for IT infrastructure management. They had implemented an automation platform that allowed for the execution of predefined scripts and workflows. However, this automation was reactive and lacked sufficient intelligence.
The company understood that truly effective operations required moving from simple automation to event-driven automation and AI agents (AIOps). The idea was not just to react to events but to enrich them with context, analyze them, and make more informed decisions, doing so automatically and in real-time. Thus, the goal was not just to speed up task execution but to improve the quality and depth of incident analysis before a human got involved.
The AI agent was designed as an intermediary between monitoring tools (observability tooling) and the ServiceNow incident management system. Its main task is to receive alerts, enrich them with detailed information, and pass them to ServiceNow already with full context. The solution architecture included several key components:
Thus, the agent transformed into an intelligent assistant that not only records the fact of an incident but also provides a deep analysis of its causes and recommendations for resolution.
The implementation proceeded in stages, starting with the most critical and frequent scenarios, such as CPU and memory load alerts. This allowed for quick demonstration of the solution's value and process refinement. Sean Dudding's team, responsible for automation, emphasized the importance of a cautious approach to using AI, especially in the banking sector.
They acknowledged that different AI models have "their own personality" and can "hallucinate." Therefore, a key principle was to use AI not for decision-making but for providing advice and context. Bank specialists carefully studied the models' behavior to ensure their reliability and minimize risks. A human remained in the loop as the ultimate arbiter, but their work became significantly more efficient thanks to complete and timely information from the AI agent.
An AI assistant for automation coding was also tested. The conclusion was clear: it doesn't allow everyone to write automation but makes experienced developers more efficient, enabling them to create complex scenarios faster within given guidelines.
| Metric | Before AI Agent Implementation | After AI Agent Implementation |
|---|---|---|
| IT alert response time | 30-60 minutes | seconds |
| L1/L2 support time spent on context gathering | high | virtually zero |
| Quality of information in ServiceNow tickets | basic | enhanced, with deep analysis and AI recommendations |
The main result was a sharp reduction in IT incident response time. From an alert to a complete picture of the problem now takes seconds, not hours. This allows engineers to address failures faster, prevent their escalation, and significantly improve the stability of the entire IT infrastructure.
Furthermore, the collected artifacts—comprehensive reports with context and AI advice—are not only useful in the moment but also serve as a valuable data source for subsequent analysis. This enables the bank to identify the most problematic services, find new opportunities for automation, and continuously improve its operational efficiency.
Westpac's case shows that AI agents can radically change the approach to IT infrastructure management, even in the most conservative industries. If your company has processes where manual data collection or slow response to events leads to losses, consider the following steps:
If this case sounds like what's happening in your company, our manager can help: he'll analyze your business and niche for free and point out where an AI agent would bring a real result in your case. Message the manager