Draft a support response for the IT issue below. User’s message and observed symptoms: [TICKET DETAILS] User environment: [DEVICE AND ENVIRONMENT] Known service status, recent changes, and relevant policies: [KNOWN CONTEXT] Support channel and the user’s technical level: [CHANNEL AND USER LEVEL] Produce a response with these sections: acknowledgement; a plain-language summary of the likely issue without presenting it as certain; up to 5 numbered troubleshooting steps; what successful and unsuccessful results look like after each meaningful step; and a clear escalation path. Start with the lowest-risk, highest-information checks: service status, scope, network connection, account or permission state, browser or app version, and reproducible error details. Keep steps one action at a time and state what information to reply with if a step fails. Only include actions appropriate for the stated user role. Do not ask for passwords, MFA codes, recovery codes, private keys, full payment data, or unnecessary screenshots containing sensitive data. Do not instruct the user to disable security controls, bypass access restrictions, delete data, run unverified commands, or reinstall or reset a device without approval and a backup warning. If the symptoms could indicate an account compromise, malware, data exposure, or an urgent outage, prioritize containment and the organization’s incident path over normal troubleshooting. Before answering, verify that every proposed step is feasible in the stated environment and flag missing facts that change the safe next step. Ask up to 3 clarifying questions only if a required input is missing.
Fill in
| Placeholder | What to enter | Example |
|---|---|---|
| [TICKET DETAILS] | Paste the user’s request, error text, timeline, and what they already tried. | Maya says Outlook shows “Need Password” after she changed her company password this morning. Web mail works. She restarted Outlook once. |
| [DEVICE AND ENVIRONMENT] | State the device, operating system, application, network, and user role if known. | Company-managed Windows 11 laptop, Microsoft 365 desktop Outlook, office Wi-Fi, standard employee |
| [KNOWN CONTEXT] | Provide current service status, recent changes, approved troubleshooting guidance, and security policies. | Microsoft 365 status is normal. Password changes can take up to 15 minutes to sync. Staff may not share passwords or approve MFA prompts they did not initiate. |
| [CHANNEL AND USER LEVEL] | Specify where the response will be sent and the user’s likely comfort with technical instructions. | Help-desk email; nontechnical employee |
How to use
- Paste the exact error message and note which apps, users, or networks are affected.
- Add service status and device-management limits so the suggested steps are actually permitted.
- Confirm the reply never requests a secret or tells the user to weaken a security setting.
- Follow up with: “Rewrite this for a live chat and include one diagnostic question after step two.”
Variations
Knowledge base article
Use this to turn a recurring ticket into self-service guidance.
Create a help-center article for [COMMON ISSUE] on [PLATFORM] using [APPROVED RESOLUTION]. Include symptoms, prerequisites, numbered fixes, expected result, when to stop, and escalation information. Write for [AUDIENCE]. Keep each step safe for a non-admin and identify steps that require IT approval. Do not include secrets, security bypasses, or unverified commands. Check that steps match the named platform and flag gaps in the approved resolution. Ask up to 3 questions only if a required input is missing.
Incident intake
Use this when a report may need security or outage escalation.
Turn [USER REPORT] into an IT incident intake for [ON-CALL TEAM]. Extract timeline, affected people and systems, symptoms, scope, business impact, evidence available, and actions already taken. List immediate containment actions only if supported by [INCIDENT POLICY]. Separate facts, user claims, and unknowns. Do not speculate on cause or ask the reporter for passwords, codes, or sensitive files. End with the severity information still needed. Ask up to 3 questions only if a required input is missing.
Executive update
Use this to communicate an active IT issue to leaders.
Draft a concise executive update about [IT INCIDENT] for [AUDIENCE] based only on [CONFIRMED FACTS]. Include current impact, affected services or users, start time and timezone, actions underway, customer or employee guidance, next update time, and owner. Clearly mark unknown cause or resolution timing as unknown. Do not promise restoration, attribute fault, or expose sensitive security details. Check that all times and impact statements are supported. Ask up to 3 questions only if a required input is missing.
Tips
- Ask about scope early: one user, one network, or many users changes the likely path and the urgency.
- Write expected results beside troubleshooting steps so the user knows when to stop and report back.
- Keep identity verification on an approved channel; a ticket reply is not a safe place to collect credentials.
- For account-security symptoms, tell users how to reach the incident path without repeating potentially compromised contact details.
FAQ
Can AI diagnose an IT problem from one ticket?
It can organize plausible checks, but a single report rarely proves a root cause. Require it to label uncertainty and gather the observations that separate likely causes.
Should an IT support prompt include security rules?
Yes. Including rules on credentials, resets, and escalation prevents a polished response from recommending an unsafe shortcut.
When should a ticket skip normal troubleshooting?
Escalate immediately when there is suspected compromise, malware, data exposure, a widespread outage, or a user who cannot safely continue working.