Multi-tenant ITSM with governed AI triage, remote-support readiness, direct social authentication, and database-protected audit evidence — orchestrated from a single operator console.
Access decisions enforced at server and database layers
Purpose-built consoles · Requester · Tech · Manager
Audit evidence protected by database triggers
Operational records isolated with row-level security
§ 01 · Platform
Each role gets an interface shaped around their day — not a watered-down universal dashboard.
Guided intake, self-serve knowledge, and one-tap remote support readiness. Zero friction from problem to ticket.
Queues, SLA timers, remote-support readiness, resolution proposals, and mandatory EOD updates — all in one workspace.
Live ops KPIs, tenant + role administration, integration control, and an immutable audit trail for compliance.
§ 02 · Intelligence
Kavrynt's AI recommends category and priority with recorded confidence, model, prompt version, latency, and human override evidence. Core ticketing continues when the provider is unavailable.
Auditable triage
Category and priority recommendations carry confidence, provider, model, and prompt version.
Remote-ready checks
Wi-Fi, Ethernet, and TeamViewer readiness are recorded before remote work.
EOD enforcement
Stale work is frozen and rolled forward with an auditable operational trail.
SLA risk control
Scheduled sweeps record warnings, breaches, escalations, and notification attempts.
AI Triage
Governed recommendations
Remote Support
Provider-ready workflow
SLA Automation
Per-priority timers
Insert-only Audit
DB-level triggers
§ 03 · Security
Tenant-owned operational records are scoped by tenant and protected with database row-level security. Audit trails cannot be rewritten — not by a technician, not by an admin, not by us.
Row-level security
Tenant-owned operational reads are filtered by tenant_id at the database layer.
Insert-only audit
audit_events and ticket_status_history reject UPDATE and DELETE via triggers.
Role hierarchy
Requester, technician, administration, audit, security, and platform roles are enforced beyond the UI.
OAuth-ready
Direct Google and Microsoft sign-in through Supabase Auth, with no intermediary gateway.
§ 04 · Lifecycle
Every ticket flows through a deterministic lifecycle — logged, measured, and reviewable long after resolution.
Intake
A requester submits through the authenticated portal or a signed inbound-email workflow.
Triage
AI recommends category and priority, while confidence and fallback state remain visible.
Resolve
Technicians work with comments, readiness checks, SLA state, and mandatory EOD updates.
Approve
Junior and intern resolutions route through senior review before requester confirmation.
Review
Status history, audit evidence, AI decisions, and overrides remain available for review.
§ 05 · Integrations
Production service connections use server-only credentials, signed webhooks, explicit health checks, and honest degraded states.
Resend
Outbound + inbound email
Google Workspace
Direct OAuth
Microsoft Entra ID
Direct OAuth
TeamViewer
Readiness + API verification
§ 06 · Outcomes
Requesters see their own ticket history, public replies, status changes, and confirmation controls without internal notes.
Requester clarity
Junior and senior technician responsibilities remain distinct through assignment, approval, and resolution rules.
Technician governance
Privileged changes, automation runs, SLA actions, and AI overrides leave reviewable operational evidence.
Operator evidence
§ 07 · Questions
Every tenant-scoped table carries a tenant_id, and row-level security policies filter every read and write at the database — not the application layer.
No. audit_events and ticket_status_history are insert-only. Triggers reject UPDATE and DELETE regardless of role, including platform admins.
Kavrynt uses a configurable OpenAI-compatible provider, persists the model and prompt version for every recommendation, and falls back safely when the provider is unavailable.
Google and Microsoft authentication connect directly through Supabase OAuth. Email and password access remains invitation-only.
Kavrynt currently provides operational PDF reporting. Broader governed data portability is tracked explicitly in the release gate and is not represented as complete.
Application data is stored in the configured Supabase project region. The production region and retention controls are deployment decisions recorded in the runbook.
§ 05 · Request access
Every request lands in the Command Centre for triage. We reply within one business day.
§ 04 · Begin
Spin up your tenant in minutes. Bring your team. Let the assistant do the triage while you do the work that matters.