Enterprise Service Management (ESM)

Prev Next

Enterprise Service Management (ESM) extends proven IT service management practices to the entire organization. Instead of each department running its own disconnected tools and processes, ESM provides a shared foundation for managing requests, workflows, and services across teams on a single unified platform.

With ESM, departments like HR, Facilities, Finance, Legal, and others can deliver services to employees using familiar, structured workflows, while maintaining the flexibility each team needs.

IT typically owns the core infrastructure, security standards, and operational reliability of the organization. In ESM, IT acts as the backbone that enables other departments to scale safely and efficiently.

By placing IT at the center:

  • Infrastructure, integrations, and automation remain consistent

  • Security and compliance standards are enforced across all spaces

  • Other teams can innovate and move faster without compromising stability

ESM allows IT to empower the organization, not bottleneck it. At the same time, ESM respects boundaries. Each team operates in its own dedicated space, with its own data, workflows, and permissions.

How it works

In SysAid Spaces ESM, each department operates within its own space. A space represents a self-contained service environment with its own configuration, workflows, and data.

Creating a new space means:

  • Defining a dedicated service area for a specific team

  • Configuring workflows, forms, automations, and roles

  • Controlling exactly who can see and manage data within that space

These spaces are independent, but not isolated.

Each space comes with:

  • Its own service workflows and request types

  • A dedicated work area for team members (Agents) to manage requests and tasks

  • Department-specific settings and automations

  • An AI agent chatbot that guides team members through their workload, fully equipped with AI agents to help get work done faster

  • An AI employee chatbot that helps your employees get answers faster and solve their issues without needing to wait for help

This structure ensures teams can work efficiently without interfering with one another.

Roles in ESM

ESM introduces a clear role model that balances control with autonomy:

  • Global Admin: Oversees the ESM structure by creating and managing spaces and managing user repositories across all spaces. When ESM is enabled on your account, SysAid Admins automatically get this permission, and it can only be changed in the primary space. A Global Admin who creates a new space automatically becomes the Space Admin of that space, which grants them access to set up and configure it. Global Admins don't have access to all spaces automatically, but only to those to which they have been actively added as admins.

    Please note:

    By default, Global Admins have access to the service records inside the spaces they administer, including the sensitive data within them. You can change this at any time by removing the relevant permissions from their profile in that space.

  • Space Admin: Manage configuration within a specific space, including workflows, settings, and team members. Space Admin is a permission available under Permissions in every space other than the primary space. A user with it:

    • Has access to all of that space’s Settings.

    • Can see every service record in the space’s queue, whether or not the record is assigned to a group, and whether or not they belong to that group.

    • Has the AI Admin permission enabled.

    Please note:

    In non-primary spaces, Space Admin takes the place of the SysAid Administrator permission, which appears in the primary space only. The two work the same way, with one difference: the additional permissions Space Admin enables are selected by default, and you can still change or remove each of them individually.

  • Team members with Service Desk access: Work on requests and tasks within a space. They only see data relevant to the spaces they belong to. This means an IT agent cannot see sensitive data available in the HR space.

  • End User: Submits requests and interacts with services through the organization’s unified self-service experience. End Users are the employees in your organization.

How spaces work together

While spaces maintain clear boundaries, they can still interact through cross-space workflows.

Examples include:

  • Employee onboarding that starts in HR and automatically triggers IT flows.

  • Offboarding processes that span multiple departments.

  • Shared approval or notification steps across teams.

These workflows allow organizations to operate as a connected system rather than a collection of silos.

Data segregation and sensitive data

Data segregation is a core principle of ESM.

  • Each space controls access to its own data

  • Sensitive data is visible only to authorized roles within the relevant space and group

  • Global Admins can view the service records in the spaces they administer by default, including the sensitive data within them, and you can remove that access at any time

This ensures privacy, compliance, and trust between departments and between the organization and its employees, while still enabling centralized governance.

The Self-Service Portal (End User experience)

The Self-Service Portal is how End Users discover and access services across departments in ESM. It is designed to remove friction, so they don’t need to remember multiple URLs and log in to multiple areas.

End Users experience either the chatbot or the Self-Service Portal homepage, depending on the Self-Service Portal settings configured in the Primary space. From there, they can easily move to other departments such as HR or Facilities.

Navigation between spaces is seamless:

  • Via the chatbot: End Users can switch between departments in the same chatbot window. When switching, the chatbot resets its context and updates its branding to match the selected space, ensuring full data separation.

  • Via the Self-Service Portal: End Users select a department, then are redirected to that department’s services, catalog, and knowledge base.

Please note:

Currently, it’s only possible to have one chatbot when using Microsoft Teams. This means that multiple chatbots can only be used via the SysAid Self-Service Portal, while the primary space chatbot remains available through Teams as well.

To learn more, see AI Chatbot via Microsoft Teams.

This approach balances ease of access with strict data segregation, while laying the groundwork for deeper unification in future phases.

Next steps

Create a new space for any department in your organization. To learn more, including how to move a team that already works in SysAid into its own space, see Creating a New Space in SysAid.