← Selected work
github.com/scadam/csm-aiteammate · Agent 365 · Customer success · Autonomous

A customer signal becomes governed work — without waiting for a prompt.

A Digital Customer Success Manager that starts when a product-usage signal, release event or renewal window lands. It resolves its own governed agent identity, builds customer context, applies auditable rules, drafts from approved content and either handles the routine work or stops at the point where its human CSM should exercise judgement.

7Stage autonomous journey
16Business MCP tools
3Supervision surfaces
0Human turns to start
Product signal received Event-triggered
Deterministic decision Routine work scales. Judgement stays human. Influence · sentiment · account strategy · topic complexity · prior acceptance
Manager cockpitOne CSM, one autopilot Sponsor controlFleet, cost and queues GovernanceIdentity and evidence

The transformation is the operating model

Traditional customer success is organised around people checking dashboards, finding the next account and assembling context before they can act. This design reverses that flow: events find the right digital teammate, routine work proceeds continuously, and humans receive only the work that benefits from relationship judgement.

Event landing

Work arrives; nobody has to ask

Usage thresholds, renewal windows and relevant product releases are the start of the process. The same engine can be invoked by an event hook, timer or programme sweep.

Named digital teammate

One governed agent per CSM

Each autopilot has an Agent 365 identity, a defined human manager, a scoped book of business and working memory. Autonomous work acts as the agent; access to a manager's Microsoft 365 data still requires delegated authority.

Deterministic judgement boundary

Rules decide where autonomy stops

Strategic accounts, frustrated or influential customers, complex recovery topics and first senior contacts route to review. Routine nudges and low-complexity tips can proceed automatically.

Management system

Autonomy remains supervised

The human CSM sees account work and review items; the programme sponsor sees fleet performance, queues, response time, inference cost and acceptance; the technical owner sees identity, access and evidence.

The seven-stage journey

Every run records the same ordered stages, tool calls, decisions, token usage, cost and outcome so the business process is explainable after the fact.

  1. 01
    Signal detected

    Select the highest-severity open signal for the assigned account.

    detect_signals
  2. 02
    Context built

    Combine customer-success context with recent Microsoft 365 relationship grounding.

    get_account_context + Work IQ
  3. 03
    Action decided

    Apply the signal-action map and auditable escalation rules.

    decide_next_best_action
  4. 04
    Content built

    Generate from approved content in the CSM's voice and screen the result.

    build_draft + Purview
  5. 05
    Prioritised

    Set priority and route judgement-sensitive work to the assigned CSM.

    create_review_task
  6. 06
    Delivered or gated

    Execute an allowed channel or retain the draft behind the human boundary.

    email · in-product · review
  7. 07
    System learns

    Record the outcome and update redacted working memory.

    write_outcome + remember

What makes the autonomy governable

The control system is not a wrapper around the demo. It is part of the design of the work.

Identity

Agent ID for autonomous work; OBO for human data

The agent can mint its own governed token without an incoming user turn. Reading or writing a manager's Microsoft 365 data remains an on-behalf-of operation and cannot silently fall through to the agent identity.

Data boundary

Cross-customer leakage is a hard stop

Grounding is screened for prompt injection, generated content is classified, and a cross-customer fence blocks a draft if another customer's confidential identifiers appear.

Evidence

Every journey can produce a forensic pack

The job ledger captures stages, tools, arguments, bounded results, acting identity, model turns, token cost, policy decisions and final outcome.

Access lifecycle

Governed access can expire

Agent instances, manager mapping and Entra ID Governance access-package state are visible to the technical owner instead of being hidden in deployment configuration.

Public portfolio boundary

The operational dashboards are deliberately not embedded here.

They contain manager-, customer- and identity-scoped information and include real mutation paths such as starting work, approving outreach and saving mailbox drafts. The public lab is therefore a deterministic, synthetic, side-effect-free replay of the repository's stages and rules. It makes no calls to the control plane and does not claim to be a live customer-success run.