Automation you can read.
AI that earns its place.

Flows runs the routine work across your whole desk. AI drafts each flow from plain words, writes and decides inside its guard rails, and acts on its own only once your people have agreed with it.

From a sentence to a flow your team trusts.

Skip to the details

Start with a sentence.

Say what should happen, the way you would tell a colleague. Plugboard drafts the flow from your own tickets, repairs and settings, and asks a question first when it needs one.

A draft changes nothing. Publishing needs someone who holds every permission the flow uses.

See it with your team
A flow, draftedExample
You wrote

“When a staff member joins, set up their account, licences and groups.”

WhenA staff member joinsTrigger
Only ifStart date and manager knownWaits
ThenOne go-ahead, with step-upPerson
ThenAccount, sync, licences, groups6 steps
Drafted from your school’s own setup.
Illustrative draft. Nothing runs until it is published.

Try it before it touches anything.

Run the draft against a real past ticket or person and read what it would do, step by step. Backtest it over recent records, then publish it in Watching mode to record what it would have done.

Dry runs, backtests and Watching change nothing.

See it with your team
A dry runExample
Dry run · Priya SharmaNothing changed
Would ask for one go-ahead with step-up, covering the next 6 steps.
Would build Priya Sharma’s account from the Staff template.
Would add her to the staff groups in Active Directory.
Would start a directory sync and wait for her cloud account.
Thomas Walsh: would wait for a start date and manager
Read it, change it, try again.
Illustrative dry run on sample people.

Decisions that earn their automation.

A Decide step asks one typed question, such as which kind of request this is, and follows the lane for the answer. Every answer starts as a suggestion a person confirms. Only once people have agreed with that question often enough can it act on its own, and corrections send it back.

Unsure, unanswered or below your threshold, the run asks a person.

How decisions learn
A typed decisionExample
Decide

Is the requester asking for access for someone else?

AnswerYesSuggested
ConfidenceAbove your thresholdChecked
Track recordPeople confirm each answerSuggest
Confirm the answer

Only a person’s choice teaches the record.

Illustrative decision. Automatic outcomes never count toward its record.

Guard rails on every step.

Changes to Plugboard’s own records run on their own, and messages go to people found from your records. Changes in other systems wait for a person’s go-ahead, and accounts, devices and admin roles need step-up too. Every run keeps a timeline, and a failed step pauses with Retry, Skip and Undo.

Nothing is deleted, and a run never acts with more access than a person.

What needs a person
A run’s timelineExample
Go-ahead given, with step-up

It covers the account steps that follow.

Create accountActive DirectoryDone
Directory syncEntra Connect SyncDone
LicencesMicrosoft 365Waiting
Undo turns an account off. It never deletes.
Illustrative run on sample records.
Scroll to follow the flow, or choose a stage above.01 / 04

The detail, when you need it.

What flows can reach, the AI built into the desk, what stays under your control, and where your data goes.

What a flow can do

One builder for automation across the whole desk: tickets, repairs, loans, stock, visitors, kiosks, devices, knowledge and people, and the systems you connect.

  • When. A ticket or repair arrives or changes, a person joins, moves or leaves, someone asks for access, a schedule comes round, another app calls in, or a connected system raises an event such as a security alert.
  • Then. Change records, send messages, ask for approval, hand a task to a technician, wait, branch, decide, write with AI, repeat for each item, or call another flow.
  • People flows. Joiners and leavers built from your account templates: Active Directory, a directory sync, licences and groups, with one go-ahead and step-up, and an undo that turns accounts off and never deletes them.
  • Privileged access. Entra PIM roles activated by the person themselves, and just-in-time admin inside Plugboard that someone else approves and that ends on time.
  • Approvals anywhere. Put an approval in front of any action. A flow can also offer itself on a ticket, repair or person, as a card a technician runs, sends for approval or dismisses.
  • Other platforms. Hand a step to Power Automate, Zapier, Make or n8n through a signed connection, and start a flow from another app through its own hook.
How decisions earn their automation

A decision is a typed question with a closed set of answers: yes or no, one of a list, or a score. The answer chooses a lane in the flow. It never chooses who or what a step changes.

  • Suggest first. Each answer is shown to a person, who confirms it or picks another. Only those human answers count toward the question’s record.
  • Earned, per question and per model. A question acts on its own only after your people have agreed with enough of its answers, and only if your school allows it. A few corrections send it back to suggest.
  • A fallback that always works. A condition written in words also has a keyword or field rule. With AI off, or no answer, the rule decides or a person does.
  • Your choice of model. Decisions come from your AI provider, or from a dedicated decision model: Laya on a self-hosted server, or TypeSafe Jev on your own TypeSafe account. Decision text is always pseudonymised.
The AI built into the desk, as flows you can open

Sorting incoming tickets, sending them to the right queue, resolving on the spot, suggesting a device fix and spotting access requests run as system flows. Open one to see what it does, narrow it to one desk, or turn it off.

  • Each keeps its own mode, threshold and track record, inside your daily limit on background AI calls.
  • Routing and access requests learn from the answers your team corrected, inside your school only.
  • Each week Plugboard points out work your team keeps doing by hand that could be a flow, from your records alone and with no AI calls.
Raising a ticket in one sentence

Type what happened. The ticket and repair composers fill in the person, how it came in, the desk, the category, the priority and the device, and mark every field they filled so you can change it or undo it. They never write over a field you set.

  • Resolved on the spot. When the words say the job is done, the ticket is raised already resolved, with the fix kept as a note.
  • Polished wording. Turn quick notes into a clear description, and keep your own words if you prefer them.
  • @-mentions. Mention a person, device, ticket or repair to link it. Mention a colleague in an internal note and they are told, if they can see the ticket.
Briefing, related reports and page-aware answers

One page for what needs you, what the AI changed on its own overnight and what it spotted: a cluster of reports, a device that keeps coming back, a loan pool about to run short.

  • Every overnight change is listed with its reason and an Undo, or says why it cannot be undone.
  • Frustrated requesters and anything past its service target come first.
  • “What the assistant saved you” is an estimate from words read and written, and the card says so.

Ask “what does this person have on loan?” on a student’s page and the answer is about that student. Questions about their loans, devices, repairs and tickets are answered straight from the records, and the matching rows light up on the page with their reasons and dates.

A person who reports the same thing twice gets one ticket: a same-person duplicate within 48 hours can merge on its own, with a one-click unmerge.

When several people at one site report the same outage, Plugboard proposes one incident with the evidence. Accept it and the reports are grouped, a known issue is posted, and each requester is told once.

Repair outcomes and approved routine actions
  • Access requests arrive as a card that already knows the groups, the licences, the free seats and who approves.
  • Joiners, movers and leavers run as people flows from the student system: accounts, licences, groups, mailbox delegation, and device and loan recovery. Each step is previewed, waits for a go-ahead with step-up, and can be undone. Nothing is deleted.
  • Device fixes for staff devices come from a catalogue. The AI suggests one, a person approves it, and your MDM runs it.

At lodgement, a likely-outcome card shows the probable result, days and cost range, drawn from your own repair history.

  • Cover agreements. A repair covered by the school’s insurance with its vendor never asks a family to approve or pay.
  • Replace device. Take the new device from stock or the loan already out, or record one on its way, and say what happens to the old one. The repair, both devices and the person’s history record it.
Tone, urgency and student safeguards

Each requester message is read for tone and urgency. The queue has a Tone column and a Frustrated requesters filter, and Briefing lists them. With no AI, a rules pass on chases, reopens and waiting time still gives a coarse read, labelled as rules.

Staff get an experience score: a 90-day summary of waits, reopens and satisfaction on the tickets they raised. It is a conversation starter for a manager, not a performance measure.

No profiles of students or parents

No per-person score is calculated or stored for a student or a parent. Their tickets carry a tone like anyone’s, because a frustrated ticket needs answering, and their experience appears only in school totals. Tone never changes a person’s account, access or charges. In auto mode it can raise a ticket’s priority one step, never to the top, and that can be undone.

Routing, intake and resolution review

AI works across intake, routing, repair classification and resolution review.

Each one runs when you turn on the AI features you want.

Route to the right desk
Suggest the department and queue from the request, within the school’s access and routing rules.
Understand incoming work
Read email and Teams intake, suggest repair types and apply your school’s configured decision criteria.
Spot when the fix worked
Recognise a requester’s confirmation that the issue is resolved and prepare a review. A technician confirms the resolution; AI does not silently close the ticket.
Keep the queue focused
Distinguish acknowledgements and automatic replies from messages that need attention, and find related reports for review.
What runs automatically, and what needs approval?

The AI proposes. People and your records decide.

Labelled

Every AI value is marked

Anything the AI wrote or changed carries an AI mark and its reason. Undo is one click, and where something cannot be taken back, such as a device restart, it says so.

Modes

Off, shadow, suggest, auto

Set per feature, and per question inside a flow. Shadow compares proposals with what staff actually did. Auto unlocks only after people have agreed with it often enough.

Identity

Never automatic

Accounts, devices and admin roles always wait for a person’s go-ahead with step-up, inside a flow or anywhere else.

API and MCP

Writes wait for a person

A write requested through an API key or MCP is held until someone with the right permissions approves it.

Activity log

Every call on record

Admin, AI activity lists every model call and suggestion, searchable and exportable. Calls are logged as counts, not prompt text.

Students and parents

No generated text reaches them

Students and parents get help articles found by search and translations a person has approved. Safeguarding words show the school’s own contact.

Where does AI run, and what leaves our school?

Your hosting region and your AI processing are separate answers. Here are both.

Managed AI

Open models that DigitalOcean serves itself: gpt-oss-120b, NVIDIA Nemotron 3 Ultra and BGE-M3. Processing is in the United States, whatever your hosting region. Names, emails, phone numbers and IDs are pseudonymised before every call, and DigitalOcean stores no inputs or outputs.

Self-hosted, local model

The bundled local model runs on your own server. The text stays on your network, and there is no AI sub-processor to disclose.

No AI

Switch AI off for the school, or run without an AI connector, and nothing is sent. The desk works as it did before, with rules-based triage.

You can also connect your own OpenAI, Anthropic or compatible account. That provider works under your contract, and pseudonymisation stays on by default.

For typed decisions, a self-hosted school can run Laya on its own server, and any school can add TypeSafe Jev on its own TypeSafe account, which is hosted in the United States. Decision text is pseudonymised for both.

What pseudonymisation does not catch: a description that identifies a student without naming them, such as “the kid in 9B with the red case”, or a name that is not on your roster. The data-processing page lists these gaps and the sub-processors.

Pricing and other questions
Is this a chatbot?

No. You can ask it questions, but most of the work is prepared in the background and shown where you already work: on the ticket, in the queue and in Briefing.

Does it act on its own?

Only where you set a feature or a question to auto, and auto unlocks only after people have agreed with it often enough. Accounts, devices and admin roles never change without a person’s go-ahead, no reply goes to a requester without a person, and undo is offered where supported.

Do we need AI to use Flows?

No. Flows run on their rules and their people. With AI off, conditions written in words use their keyword rules, Decide steps ask a person, and you build each flow step by step instead of from a sentence.

Do students or parents talk to the AI?

No. No generated text reaches a student or parent. They get help articles found by search, known issues and translations a person has approved.

What does it cost?

The plan includes 5,000 hosted AI calls a month. Above that, hosted calls are A$25 per 1,000. A local model or your own key costs nothing from us. See pricing.

What if we don’t want AI?

Turn it off for the school, or per feature. With no AI, the desk works as it did before, and nothing is sent anywhere.

See it on your own tickets.

Fifteen minutes on your queue, your student system and the work you would hand to the assistant first, with a 30-day trial to follow.