Radar / Ideas / DeskZero: the on-device IT agent with…

DeskZero: the on-device IT agent with a judgment layer, sold through MSPs

daily ideamoderateJEV confidence 0.492026-10-07
Outcome80% of tier-1 employee IT tickets resolved on the employee's own device in under 5 minutes, with zero data egress and a full audit trail.

The problem

A manually-handled IT ticket costs about $22 and the average internal team fields 492 tickets a month, with nearly 70% of the service-desk budget going to staffing. Mid-market companies are priced out of Moveworks-class tooling (median deals around $130k/year, quote-gated), and every cloud IT copilot ships employee device data off the laptop, which is a non-starter for regulated SMBs.

The idea

An on-device agent that resolves the most common tier-1 IT fixes (VPN reconnect, disk cleanup, app reinstall, password reset, printer queue) directly on the employee's laptop, inside existing role-based permissions. Every autonomous action passes through a local typed decision gate: a small decision model answers 'safe to run / escalate to human' in milliseconds, and each fix lands in a JSON audit log. It ships white-labeled through managed service providers who already bill per device, so the MSP cuts tier-1 labor cost while selling a compliance story no cloud chatbot can tell.

Why now

The decision-model wave of the last two weeks changed the economics: ARC-1 (1.7B, ~16-25ms per judgment, fully offline), Respan Span-01 (single-forward-pass behavior scoring at $0.02/M tokens), and this week's TokenAI Neo (41M parameters, a choice plus a calibrated score in one pass) make per-action judgments cost milliseconds and effectively $0. Earlier autonomous-fix attempts died on the cloud LLM bill per ticket; now every fix can carry a calibrated 'safe to proceed' verdict plus a behavior audit without one. Yellow.ai's Nexus EDGE proved the on-device agentic resolution pattern works inside existing permissions.

What it combines

Three radar capabilities combine: (1) on-device agentic resolution (Yellow.ai Nexus EDGE) as the engine that runs fixes inside role-based permissions; (2) local typed decision models (ARC-1 1.7B, JEV-27B) as the per-action judgment layer — 'is this fix safe to run autonomously?'; (3) single-pass behavior scoring (Respan Span-01) as the audit layer. The mix matters because resolution without judgment is reckless and judgment without an audit trail is unsellable to compliance — the three together turn a chatbot into an insurable endpoint product.

MVP

Build: a policy pack (YAML) plus an ARC-1 wrapper that intercepts the 5 most common fixes on one Mac/Windows agent, with a yes/no/escalate gate per fix and a JSON audit log. Skip: HR/Ops domains, MDM integration, the Respan audit pipeline (log locally, analyze later), multi-OS polish.

Distribution

B2B2C via managed service providers. MSPs own the SMB IT relationship, bill per device already, and need margin: a white-labeled on-device agent that cuts tier-1 labor cost is a direct P&L win for them. Second wedge: cyber-insurance brokers who want auditable endpoint hygiene evidence from policyholders.

Why it wins

Everyone else sells a smarter chatbot in front of the same cloud queue; DeskZero sells resolution without egress. The fix happens on the laptop, the judgment happens on the laptop, and the MSP gets a per-device audit log — a compliance story Moveworks structurally cannot tell.

Risks

Device-agent installation is the graveyard of IT startups — MDM friction and IT-admin distrust of autonomous actions. De-risked by shipping as an MSP-deployable package with the decision gate defaulting to suggest-then-confirm, earning trust before autonomy.

Build it with

Repo to start from

deskzero-policy — open policy packs (fix recipes plus decision-gate thresholds) per OS with a local audit-log schema; the commercial layer (MSP console, fleet audit) stays closed.

Evidence

Get the week's best AI launches, plus 3 ideas worth building

One email every Saturday. Ranked by traction, not hype. Free.