Start with ready-made AI agents with instructions on how to manage them on the marketplace. Browse the library
Back to blog
Back to blog

Westpac reduced IT incident response time from hours to seconds: how an AI agent added context to alerts

https://s3.ascn.ai/blog/b0533c3e-563f-4e20-a975-817738a33136.png
ASCN Team
30 July 2026
Build an AI agent for your task
It will handle requests, sort your inbox, compile reports, and follow up with clients. No coding or complex integrations required.
Try for free

At Westpac, a major player in the Australian financial market, the response time to critical IT incidents has been slashed from hours to mere seconds. Previously, a CPU or memory overload alert could sit in a queue for half an hour or an hour until the problem resolved itself or led to a failure. Now, the entire cycle from data collection to attaching context to a ticket takes moments. This was made possible by implementing an AI agent that automated event processing and added deep context to every ServiceNow ticket.

In a bank's IT infrastructure, incidents don't wait. Every minute of downtime means not only financial losses but also reputational risks that can be more costly than money. The traditional scheme, where an alert becomes a ticket and then waits for a human to investigate it, is too slow and inefficient. People spend hours on routine data collection that can be obtained automatically. This is not just inconvenient; it represents direct losses that can be avoided.

The Problem: Why IT Incidents Were Costly for the Bank

The IT infrastructure of a giant like Westpac is a complex system with thousands of interconnected components. Hundreds, if not thousands, of alerts about potential problems are generated daily: processor overload, insufficient RAM, service failures. Each such alert required an engineer's attention.

Without automation, the process looked like this: a monitoring system detects a problem and generates an alert. This alert becomes a ticket in the incident management system (ServiceNow). Then, a duty specialist (L1/L2 support) takes on this ticket. They manually begin to gather context: what exactly happened, which processes are consuming resources, are there errors in the logs, which services are affected. This consumed precious time—from half an hour to an hour, sometimes even more. During this time, the problem could worsen, lead to cascading failures, or, conversely, resolve itself, leaving the engineer with outdated information.

This approach led to several critical problems: high cost of incident response due to manual labor, delays in problem resolution, a high risk of human error, and, consequently, a reduction in the overall stability of IT systems.

The Path to the AI Agent: From Simple Automation to Context

Westpac had long used automation for IT infrastructure management. They had implemented an automation platform that allowed for the execution of predefined scripts and workflows. However, this automation was reactive and lacked sufficient intelligence.

The company understood that truly effective operations required moving from simple automation to event-driven automation and AI agents (AIOps). The idea was not just to react to events but to enrich them with context, analyze them, and make more informed decisions, doing so automatically and in real-time. Thus, the goal was not just to speed up task execution but to improve the quality and depth of incident analysis before a human got involved.

How the AI Agent for Incident Processing Was Designed

The AI agent was designed as an intermediary between monitoring tools (observability tooling) and the ServiceNow incident management system. Its main task is to receive alerts, enrich them with detailed information, and pass them to ServiceNow already with full context. The solution architecture included several key components:

  • Event-driven automation: The agent is configured to intercept alerts from monitoring systems. As soon as a new event arrives, it immediately enters the agent's workflow.
  • Detailed context collection: Upon receiving an alert (e.g., about high CPU usage), the agent immediately launches a script that performs a comprehensive health check on the endpoint. It collects data on processes using CPU and memory, checks storage load, and analyzes event logs. This stage takes seconds.
  • Integration with the AI platform: The collected data from the check is then sent to the bank's internal AI platform. Here, AI models analyze this data and generate recommendations or advice. It is important to note that the AI does not make final decisions but provides additional information and analytics.
  • Enriching the ServiceNow ticket: All collected information—results of the comprehensive check and AI recommendations—is automatically attached to a new ticket in ServiceNow. This allows L1/L2 support specialists to immediately get the full context of the problem without spending time on manual data collection.

Thus, the agent transformed into an intelligent assistant that not only records the fact of an incident but also provides a deep analysis of its causes and recommendations for resolution.

Implementation and a Cautious Approach to AI

The implementation proceeded in stages, starting with the most critical and frequent scenarios, such as CPU and memory load alerts. This allowed for quick demonstration of the solution's value and process refinement. Sean Dudding's team, responsible for automation, emphasized the importance of a cautious approach to using AI, especially in the banking sector.

They acknowledged that different AI models have "their own personality" and can "hallucinate." Therefore, a key principle was to use AI not for decision-making but for providing advice and context. Bank specialists carefully studied the models' behavior to ensure their reliability and minimize risks. A human remained in the loop as the ultimate arbiter, but their work became significantly more efficient thanks to complete and timely information from the AI agent.

An AI assistant for automation coding was also tested. The conclusion was clear: it doesn't allow everyone to write automation but makes experienced developers more efficient, enabling them to create complex scenarios faster within given guidelines.

Results

Metric Before AI Agent Implementation After AI Agent Implementation
IT alert response time 30-60 minutes seconds
L1/L2 support time spent on context gathering high virtually zero
Quality of information in ServiceNow tickets basic enhanced, with deep analysis and AI recommendations

The main result was a sharp reduction in IT incident response time. From an alert to a complete picture of the problem now takes seconds, not hours. This allows engineers to address failures faster, prevent their escalation, and significantly improve the stability of the entire IT infrastructure.

Furthermore, the collected artifacts—comprehensive reports with context and AI advice—are not only useful in the moment but also serve as a valuable data source for subsequent analysis. This enables the bank to identify the most problematic services, find new opportunities for automation, and continuously improve its operational efficiency.

How to Replicate This in Your Business

Westpac's case shows that AI agents can radically change the approach to IT infrastructure management, even in the most conservative industries. If your company has processes where manual data collection or slow response to events leads to losses, consider the following steps:

  • Identify routine data collection. Where do your specialists spend time searching for information that can be obtained automatically? This is an ideal candidate for AI agent implementation.
  • Start with context enrichment. Instead of immediately giving AI decision-making power, use it to collect and analyze data, providing recommendations. This will reduce risks and increase trust in the technology.
  • Integrate the agent into existing tools. Don't force people to learn new platforms. Embed the AI agent into the systems they already use (e.g., monitoring systems, ticketing systems).
  • Train and test AI models. Be cautious and methodical. Test model behavior, study their "personality," and avoid hallucinations. A human should remain in the loop as a controller.

If this case sounds like what's happening in your company, our manager can help: he'll analyze your business and niche for free and point out where an AI agent would bring a real result in your case. Message the manager

MainBlog
Westpac reduced IT incident response time from hours to seconds: how an AI agent added context to alerts
By continuing to use our site, you agree to the use of cookies.