A compliance ticket behaves like any other, except that its assignee writes back after every attempt. Two things are worth learning: how to read what it wrote, and how to tell it what to do next.
Overview
Notes are written to be skimmed. The first line says what happened; the last line says what is left for you. Everything between is evidence you only need when you disagree with the first line.
There are three shapes:
| Shape | Meaning | Your move |
| Fixed | A fix went out and the device confirmed it | None. The ticket closes on the next compliant report |
| Waiting | The fix is out but unconfirmed, or an employee was asked to act | None yet. Nobody will chase — after a reasonable wait, it is yours |
| Handed back | Only an admin can go further, and the note says why | Do what the last line says. There will be no retry |
A run that ends with the issue still open is a legitimate outcome. The note will not pretend otherwise.
How to use — who gets obeyed
The distinction below is the single most useful thing in this article.
- An employee's public reply is information. It can establish a fact — the laptop was restarted, the passphrase was entered — and that fact gets used. What it cannot do is start an action, grant an exemption, or reopen something already settled. If an employee asks to speak to a person, the messages stop.
- An admin's internal note is an instruction, and it is executed: move this device to stock, unassign it, try the push again, close this. No confirmation question, no proposal first. Internal notes are restricted to the ticket's admins and its assignee, and that restriction is exactly what makes them count as authority.
Where an instruction can only be partly satisfied, the satisfiable part is done and one line explains the rest.
Destructive instructions are the exception. Wipe, lock, retire and unenrol stay closed unless your remediation policy opens them. Writing one in a ticket does not open it.
How to use — closing
Three ways a compliance ticket ends, and only one is automatic:
- The device becomes compliant. The issue vanishes and the ticket closes itself. This is the normal path and needs nobody.
- You instruct a close in an internal note. It complies, and warns you what survives: the issue stays raised, the device still reads non-compliant everywhere, and no replacement ticket will open while that remains true.
- Never on its own initiative. It will not close or reopen a compliance ticket because it felt finished.
How to use — approving what it learned
Occasionally a run uncovers something that will change how the next ten tickets read: a site whose network blocks the agent, a group of devices sitting in stock. When that happens it offers, in a single line, to write that fact into the Company knowledge section of your policy — quoting the exact sentence it proposes.
- Read the quoted sentence. What you approve is what gets saved, word for word.
- Say yes in an internal note. That is the approval; nothing else counts.
- It merges, saves, publishes and confirms. With unfinished draft edits on your policy it saves but does not publish, and tells you.
Approving a fact never grants a permission. Only the policy's other sections do that.
Tips and best practices
- Read two lines per note and move on. They are written so the middle is optional.
- If you want something done, write it internally. A public reply reads as information no matter how imperative it sounds.
- Say yes to knowledge additions that are true. Each one removes a recurring misread, and you are approving exact wording, not a vague idea.
- Do not close a ticket to silence an issue. The issue survives the close — you only lose the ticket that was tracking it.
Troubleshooting and FAQ
Troubleshooting
-
You asked for something and it was ignored.
Check where you wrote it. Public replies inform; internal notes instruct.
-
A wipe instruction did nothing.
Destructive actions come from the policy, not from the ticket.
-
The ticket closed but the device is still non-compliant.
Expected after an instructed close. Closing the ticket never cleared the issue.
-
A demo ticket triggered something real.
Demo companies use fake device data but a live assistant, so a comment there starts a genuine run.
FAQ
-
Can an employee trigger an action?
No. Their replies are information only.
-
What normally closes a compliance ticket?
The device reporting compliant again. An admin can also instruct a close.
-
Does approving a learned fact expand what it may do?
No. It adds knowledge, not permission.