+33 (0)1 87 66 00 65 · Monday to Friday, 9am–6pm Free audit (15 min)
● Public sector — IT support (level 1 helpdesk)

The AI agent for IT support: take on level 1, free up the technicians

Everyday incidents — access, printing, business applications — swamp the helpdesk and tie up technicians whose expertise would be more useful elsewhere. Your AI agent takes on level 1 support: it guides resolution, qualifies and routes tickets, and applies your internal procedures. Hosted in France — on local inference or an isolated resource — the knowledge base and the incident data stay under control. The AI agent assists, the public official decides.

Hosted in France An isolated knowledge base GDPR & AI Act: governed deployment Human oversight

Updated on

Deployed in a few weeks
Level 1 helpdesk assistant · hosted in France
An official in the registry office has been unable to reach the business application since this morning. What do I tell them?
Incident identified: 3 similar reports since 8am on the same application — most likely an expired session renewal after last night's update. Internal procedure: full sign-out, clear the cache, then sign back in through the single sign-on portal.
If access does not come back, this is an incident to route to level 2 — I am preparing the qualified ticket.
⛓ Source · the internal knowledge base + the open tickets
The procedure did not work for them. Escalate the ticket.
Ticket escalated to level 2, high priority (a blocking business application, several officials affected). I have attached the workstation, the timestamps, the 3 related reports and the steps already tried. Category: access / single sign-on authentication.
The level 2 technician receives a complete file — the next step is theirs to decide.
✎ Action · qualified ticket ready — the public official approves the escalation
Local inference · no data outside the EU
Data hosted in France
Sovereign by designLocal inference or hosting in France
GDPR & AI Act: governed deploymentTraceability & human oversight
TurnkeyDesigned, installed and operated for you
The public officer decidesThe AI agent assists, never rules alone
✦ In brief

In a local authority, a government department or a public body, a Blue Lemon Agent agent takes on level 1 IT support: it guides the resolution of everyday incidents (access, printing, applications), qualifies, prioritises and routes tickets to the right level, and circulates the internal procedures and good practice. It runs on local inference or is hosted in France: the knowledge base and the incident data are never exposed to a foreign service, architecture designed to reduce exposure to extraterritorial legislation, location alone not being enough to guarantee immunity. The technicians' time is redirected to the subjects that add value. Live within a few weeks. Your staff write to it from Microsoft Teams, Slack or their email — nothing to install, nothing to learn. These connections are included in every plan, at no extra cost, within the number of connections your level includes.

100%
hosted in France in the target architecture
0
transfer outside the EU in the target architecture
8
uses ready to deploy on this scope
0
decision taken without human approval

Reference points describing our offer, not results measured at a client. The scale of the gain is confirmed by a pilot on your own scope.

The context

Why AI matters to public-sector IT departments — and why they hesitate

Public officials expect responsive support to stay productive in serving the public. But the helpdesk is swamped by repetitive incidents, and both the incident data and the internal knowledge base touch on the organisation and the security of the information system.

! The issue

The IT department is caught between officials who expect their incidents resolved immediately and a support team whose time is absorbed by repetitive level 1 work — at the expense of projects and of security. Yet most consumer AI tools amount to entrusting the map of the information system, accounts, internal procedures and incident data to a third party, often hosted outside Europe and subject to the Cloud Act.

Our answer

For a public service, AI is only of interest if it is sovereign and confidential by design. Local inference or an isolated resource hosted in France, systematic human oversight, the decision reserved for the public official: time gained on level 1 is never paid for in lost sovereignty. The aim is not to replace the IT team, but to give it back time for the subjects that add value and for continuity of service.

The decisive point

Keeping control of information-system data: sovereignty & compliance

A helpdesk handles sensitive information about the organisation and the security of the information system. Here is how the architecture of our agents protects it, organisation by organisation.

Local inference

The agent can run on a machine belonging to the organisation: no incident data leaves the network, nothing passes through a cloud.

Hosting in France

Otherwise, a dedicated and isolated resource, hosted in France under French law — your data: processing and access within the European Union targeted by the architecture.

Reduced extraterritorial exposure

Exposure of information-system data to the Cloud Act and FISA 702 is reduced by design; location alone does not guarantee immunity.

A knowledge base isolated per organisation

No pooling: a knowledge base and an environment strictly dedicated to your authority or body.

Encryption & controlled access

Encryption in transit and at rest, role-based access (RBAC), strong authentication and logging.

AI Act: governed deployment

The agent is strictly in support; no escalation or resolution approved automatically; traceability and human oversight from end to end.

What depends on the architecture chosen These points are not general guarantees: they are settled deployment by deployment, in the quotation.

  • The applicable location is that of the architecture set out in the quotation and verified before commissioning.
  • Local execution is announced only for the configuration explicitly described and accepted in the quotation.
  • The applicable isolation depends on the deployment mode set out in the quotation; no dedicated isolation is presumed.
  • The encryption mechanisms in transit and at rest, their components and key management are those documented for the architecture chosen.
  • Roles and permissions are configured and accepted for the identities and systems actually connected.
  • The events logged, their content, their retention period and who may access them are defined for the deployment chosen.
For the most sensitive data, SecNumCloud and HDS options are available depending on your requirements. A single architecture is designed to answer both the GDPR and extraterritorial exposure. Designed for deployment in line with the GDPR and the AI Act, after the processing, roles and context-specific risks have been assessed.
Demonstration

See the agent at work

5 real situations, taken from those that come up most often. Pick one: the exchange unfolds as it would in your organisation.

A scripted demonstration. These exchanges show how the agent behaves — its sources, its refusals, what it leaves to your teams. Nothing is sent from this page, no model is queried here, and the matters named are fictional. That is precisely what we promise your data.
The behaviours shown here — monitoring, automation rules, routing and reminders — are configured with you during deployment, from your tools, your rules and your thresholds.
The architecture points named in these exchanges — location, local execution, isolation, encryption, role-based access, logging — are not a guarantee attached to the demonstration: they are those of the architecture set out in your quotation, and verified before commissioning.

The public body in this demonstration

Fictional public body

Val-d'Arcy urban community — shared IT department for 23 municipalities

Sector
Fictional authority — shared information systems department: workstations, business applications (civil status, finance, human resources, planning), schools, libraries and the technical centre of the 23 member municipalities
Headcount
1,240 staff equipped; an IT department of 11 people including 4 on the helpdesk — 2 level 1 technicians and 2 level 2, the helpdesk being open from 8.30 a.m. to 5.30 p.m.
Public served
1,240 staff across 38 sites, who themselves serve 96,000 residents — one member of staff blocked in the morning means a public counter that does not open
Order of magnitude
6,400 tickets a year of which 3,900 are level 1, 2,600 calls to the helpdesk, 640 on-site interventions, 74 staff arrivals and 9 internal forms in the information system
Tools in place
Ticketing tool, staff directory, asset manager, single sign-on portal and a 9-year documentation base — 740 sheets; the agent plugs into them read-only, nothing is replaced and nothing is migrated
Who decides
The helpdesk manager approves every go-live; the information systems security officer rules on anything touching rights and access; the level 2 technician settles every escalation
Room for improvement
700 calls a year arrive outside helpdesk opening hours — 27 %; a ticket waits 3 h 40 before it is first picked up; 41 % of level 1 tickets land in the wrong queue on first routing; and across the 74 staff arrivals of the year, one access in five was still missing on the first day

At Val-d'Arcy, four people run support for 1,240 staff across 38 sites. Everyday incidents — access, printing, business applications — take up most of the team's time while projects and information system security wait. The agent runs on local inference on a machine of the IT department, reads the 9 years of tickets and the 740 sheets of the documentation base without ever writing to them, and closes no ticket outside the regime the helpdesk manager has signed. The exchanges that follow span one year, from the overhaul of the documentation base to the review presented to the chief executive.

This public body, its figures and the exchanges that follow were invented for the demonstration. They illustrate a common situation; they describe no real service.

Level 1 helpdesk assistant · hosted in France
I read your nine years of tickets over the weekend — 41,200 tickets, 740 sheets from your documentation base — and I draw from them a finding your logs carried without anyone ever having the time to see it.
Level 1 is the first floor of support: the everyday incidents that are settled without an expert — access, printing, a business application that no longer opens.
The measured gap, and it commands everything else: of the 6,400 tickets of last year, 3,900 are level 1 — 61 %, and twelve causes alone account for 2,650 of them, that is 68 % of level 1. Session expired after an update, blocked print queue, single sign-on password, mail profile to rebuild, network drive not mounted: the twelve fit on one page, and your four technicians handle them 2,650 times a year.
What that costs today, on the three items you can check in your ticketing tool: a level 1 ticket takes 20 minutes here, from report to closure.
· Triage and routing weigh 60 % of that time12 minutes spent working out who is calling, on which workstation, with which application, and into which queue the ticket should go.
· Guided resolution of a common incident: 30 %, that is 6 minutes.
· An answer to a recurring question from a member of staff: 12 %, that is 2 minutes 24.
What I propose, and it is not a promise — it is already written: each of the twelve causes now has its up-to-date resolution sheet, drafted last night from your own resolved tickets, with the step-by-step your technicians actually use rather than the one a vendor manual recommends. What it would have changed over the past year, since that is the only measure that counts: the 2,650 tickets of those twelve causes would have left with the right procedure at the first exchange.
What becomes of the three items once the sheets are settled: 60 % → 18 %, 30 % → 10 %, 12 % → 8 %3 minutes 36, 2 minutes, 1 minute 36. The rest is the technician's judgement, and it cannot be delegated.
The next step, and it takes half an hour: your helpdesk manager reads the three heaviest sheets, I present them to him tomorrow morning. He settles the version, and it is live the same eveningit is his approval that makes the sheet binding on the technician who will apply it, and it is the only act I leave to him. ticket-analysis_12-causes-for-68-percent.pdf41,200 tickets read, 12 causes, 2,650 tickets a year
⛓ Sourced · 9 years of the authority's tickets, documentation base of 740 sheets, 12 resolution sheets rewritten
Our documentation base holds 740 sheets and nobody has time to maintain it. Some of it must be wrong since the single sign-on migration.
96 sheets out of 740 describe a system that no longer exists, I have identified them and the 96 up-to-date versions are written.
What the comparison between your sheets and your actual configuration says:
· 62 sheets point to the old sign-on portal, the one the migration replaced eleven months ago — screens, button labels and login address have all changed. A member of staff following those 62 sheets cannot succeed.
· 21 sheets describe printers withdrawn from the estatethe estate is the set of workstations, printers and telephones the IT department manages and inventories.
· 13 sheets carry an internal contact who has changed department.
What those 96 sheets have cost, measured on your tickets and not assumed: they are cited in 430 tickets of the year, and 118 of those 430 led to a second call from the same person within 48 hours. It was not a shortfall of skill, it was documentation that had aged while nobody had time to reopen it.
What I do on top, and nobody has the time to do: I rewrite each sheet from the configuration in force and from tickets actually resolved, and I set the replaced line and the replacing line side by side — your technician validates at a glance instead of rereading a page. Of the 96, 74 can be approved in under a minute each; the other 22 carry a choice of procedure that is yours to make, and for each I propose the two possible wordings with the number of tickets each would have covered.
The next step I propose: that from now on, any sheet that a configuration change makes wrong be rewritten the night that follows that change, and reach you in the morning summary. Your 740 sheets will stop ageing in silenceit is the only way this work will not have to be redone in two years, and it will cost you no more than one reading per change. documentation-base_740-sheets-96-reworked.pdf96 outdated sheets, 96 up-to-date versions, 430 tickets involved
⛓ Sourced · documentation base of 740 sheets, estate inventory, sign-on migration log, tickets citing a sheet
All this assumes you read our tickets, our directory and the map of our information system. Where does that data go?
It goes nowhere. I run on local inference on a machine of the IT department, and nothing I read leaves the authority's network.
Local inference means the model computes on your machine: the text of a ticket, the name of a server or the list of one person's rights never cross an outside network to be processed. If the IT department would rather not host a machine, the other route is an isolated resource hosted in France, dedicated to Val-d'Arcyno pooling with another authority, your knowledge base lives in an environment that is yours alone.
What that changes, point by point:
· Your tickets and your system map train no model, neither ours nor a third party's.
· I work read-only on the ticketing tool, the directory and the asset manager, and the technical account through which I read has no write permissionthat is sturdier than a promise, because your security officer checks it with one command.
· Encryption in transit and at rest, strong authentication, and role-based accessrights follow the job: a level 1 technician opens the tickets of their queue, not the table of privileged accounts. 7 roles for your 11 people, and the log shows 0 out-of-role access since go-live.
· Hosting in France, under French law, architecture designed to reduce exposure to extraterritorial legislation, location alone not being enough to guarantee immunity.
· Logging: who asked what, when, which sheet grounded the answer and what the system produced.
One thing I do in no circumstances, and it is not caution on my part: inferring a member of staff's emotional state from the tone of their tickets or their voice on the phone. The European regulation on artificial intelligence flatly prohibits inferring people's emotions in the workplace, and it is one of the few truly firm bans in that text. What is permitted and renders the same service, I have already built: load by queue and by cause, hour by hourit is what showed you the 700 out-of-hours calls, and no individual is named in it.
The figure that sums all this up: 0 information system data left the authority's network across the 6,400 tickets of the year, and processing in the EU targeted.
What I propose: that I maintain the record your chief executive and your data protection officer will ask for — hosting, data processed, retention periods, who accesses what. It is requested once a year and takes two days to rebuild; the first version is already written and attached. technical-framework_where-your-it-data-lives.pdfLocal inference, read-only, processing in the EU targeted
✎ Framework · deployment architecture, technical account permissions, matrix of the 7 roles, first version of the register record
Local inference · no data outside the EU

Your case is not here? That is exactly what a 15-minute conversation is for. Book the free audit

Use cases

The uses of AI for support and for relations with officials

Each use corresponds to an agent we deploy. All of them work in support, subject to approval by a public officer.

Included in your agent The 8 capabilities essential to this promise are included, at no extra cost.
From 800 € incl. VAT / month

Internal knowledge base

Find a procedure, a set of instructions or a resolution sheet in the internal documentation instantly.

Answers to everyday questions

Answer officials' recurring requests: access, printing, applications, guided resets — 24/7.

Helpdesk switchboard & front desk

Take calls to support, qualify the request and direct it to the right person or the right procedure.

Booking a call-out

Automatically schedule on-site call-outs and slots with the technicians who are available.

Guide officials step by step through the support procedures

Guide officials step by step through the internal formalities and forms of the information system.

Multi-channel front desk for officials

A first point of contact for officials at the HR-and-IT desk, alongside the front-desk officer.

Onboarding & officials' accounts

Support an official's arrival: opening access, equipment, procedures — tied in with HR and payroll administration.

Monitoring & technical documentation

Sourced summaries on patches, updates and good security practice for the information system.

Controls and safeguards These 5 controls are built into the agent: they frame what it does, whatever plan you pick. They are not chosen and are not added to your order.
Human validation, exceptions and escalation Status, safe closure and audit trail Access the technical context with least-privilege permissions Run tests, security analysis and human review before any change Version, log, roll back and measure quality
The gain

How much time can a support team recover?

By automating the handling of repetitive level 1 work and the qualification of tickets, a team can aim for a significant reduction in time spent on everyday support — reinvested in projects and in the security of the information system.

Qualifying and routing a ticket
Today · done by hand
Prepared by the agent, to approve
Guided resolution of an everyday incident
Today · done by hand
Near-immediate
Answering a recurring question from a member of staff
Today · done by hand
Automatic
Qualitative, non-contractual comparison: the proportions shown illustrate the shift of the work towards review, they represent no measurement. Every output of the agent is reviewed and approved by a competent person.
How it works

The stages of your AI agent project

1

Audit & scoping

15 minutes to target the use case with the best return.

2

Quote or direct sign-up

A catalogue offer is bought online; a specific need gets a costed quote.

3

Design

We design the agent and its guardrails.

4

Integration & testing

We connect your tools to the agent, which is itself hosted in France.

5

Rollout

Going live and training your team.

6

Operation

Continuous supervision and improvement.

Pricing

Three options, one agent

A level 1 support agent (guided resolution, qualification, routing, procedures), installed and operated for you. Choose according to how you work.

Agility

Setup + controlled subscription

10,355 € incl. VAT setup
then 800 € incl. VAT/month — you invest at installation and pay a reduced subscription. Ideal for keeping the cost under control over time.
  • Installation, configuration and training for your teams
  • Operation, human oversight, updates and support
  • Sovereign hosting in France, a dedicated and isolated resource
Order →
The simplest Serenity

All inclusive, no setup fee

1,375 € incl. VAT /month
all inclusive, immediate start. No upfront investment: a single subscription. Ideal for starting quickly and simply.
  • Setup included (installation, configuration, training)
  • Operation, human oversight, updates and support
  • Sovereign hosting in France, managed end to end
Order →
100% Sovereign

On site, you own it

14,961 € incl. VAT setup
then 1,040 € incl. VAT/month · + hardware from 2,989 € (one-off purchase, in addition) — a sovereign computer installed on your premises, maintained remotely. Models run locally, your data returned at the end of the contract. 36-month commitment.
  • Hardware installed on your premises (you own it)
  • French / European AI models run locally
  • Secure remote maintenance (Pro support included)
Order →
Not included in the packages: AI consumption (model tokens), re-invoiced at real cost with no margin, and tracked in real time in your client area. Maintenance and supervision subscription for an initial term of 12 months for the Agility package, 24 months for the Serenity package and 36 months for the 100% Sovereign package, renewable; support levels (SLA 72 h / 24 h / 4 h) optional. Bespoke development, additional integrations or exceptional volumes are quoted separately. Support Monday to Friday, 9am to 6pm. Prices include VAT at 20%: as a public body that is not VAT-registered, you cannot reclaim it.
AI model: none of the AI models offered currently carries a fixed surcharge. When the selected model carries a cost, that cost is shown when you choose it, before you order, and re-invoiced at the cost incurred, with no mark-up; usage is billed at the publisher's price. Publishers' prices are published in US dollars: the amount re-invoiced is the amount in euros actually borne by Blue Lemon Agent on the publisher's invoice, at that invoice's exchange rate, with no commission or mark-up.
Included components and additional components Components included in the base offer: the Blue Lemon Agent software foundation, the AI models listed in the order journey, the standard channels (Microsoft Teams, Slack, WhatsApp Business, email, website chat, calendars, Microsoft 365 / Google Workspace, file storage, market VoIP telephony, professional social-media pages and accounts, Google Business Profile), hosting in France for the package chosen, backups, supervision, updates and support. If adapting the AI agent to your constraints, your needs or your requests requires other paid components — a third-party publisher's software licence, paid API access to one of your applications, hosting of health data, for which French law requires an HDS-certified host (art. L. 1111-8 of the French Public Health Code), SecNumCloud-qualified hosting, a speech synthesis service, particular hardware —, they are offered to you as an option or on quotation and re-invoiced at the cost incurred; nothing is committed without your written agreement. Where the artificial intelligence model you choose entails an additional cost, that cost is shown to you before you order and re-invoiced to you at the cost incurred, with no margin.
What to expect
Go-live 2 to 3 weeks
Agent designed, channels connected, team trained.
Steady state 4 to 7 weeks
After a few weeks of real use, once the agent's behaviour matches what you expect. Indicative estimate, adjusted to the options you keep. It is not a delivery commitment.
Our commitment

Four guarantees that matter to a public service

Information-system data never leaves the organisationLocal inference or an isolated resource hosted in France; no incident data entrusted to a foreign third party.
Data in France, under French lawInformation-system data: minimisation and location in France, architecture designed to reduce exposure to extraterritorial legislation, location alone not being enough to guarantee immunity.
The public officer keeps the decisionThe AI agent proposes resolutions, escalations and routings that can be checked; no action is automated without approval.
Human oversight & traceabilityMonitoring and logging frame the internal knowledge base; compliant with the requirements of the AI Act.
Frequently asked questions

Your questions, our answers

Does the AI agent replace the IT team?
No. It handles repetitive level 1 work — access, printing, everyday applications — to free technicians for the subjects that add value: projects, information-system security, complex incidents. The public official keeps the decision on every escalation and every resolution.
Does it connect to our ticketing tool?
Yes, to the main ticket-management tools. The agent qualifies, prioritises and routes tickets to the right level, and attaches the useful context (workstation, timestamps, steps already tried) without forcing a migration.
Does internal data stay under control?
Yes: sovereign hosting in France or local inference, and a knowledge base isolated per organisation. The map of the information system, the procedures and the incident data never leave the European Union, architecture designed to reduce exposure to extraterritorial legislation, location alone not being enough to guarantee immunity.
How does the agent know our internal procedures?
We feed its knowledge base with your sets of instructions, resolution sheets and good practice. It circulates them to officials and relies on them to guide resolution — always citing the internal source, which the technician can check.
Can the agent decide on an escalation or a call-out by itself?
No. In line with the AI Act, the agent stays in support: it proposes a qualification, a routing or an escalation that can be checked, but it is the public official who approves. Every action is recorded and supervised.
Does the agent state that it is an artificial intelligence?
Yes, from the very first interaction, and this is not a configuration option: since 2 August 2026, Article 50(1) of the European AI Regulation requires that any person interacting with an AI system be informed, unless this is obvious. The announcement is built into the greeting, in the other party’s language, and they can ask for a human at any time.
How long does it take to deploy the agent?
A few weeks as a rule, after a free audit that identifies the most valuable use, then a phase of design, integration with your ticketing and testing before going live and training the officials.
Which tools can staff use to talk to the agent?
The ones they already use. Your staff write to the agent from Microsoft Teams, Slack or their email, the way they would write to a colleague: nothing to install, nothing to learn. Oversight runs from a web dashboard. These connectors rely on open standards, including the MCP protocol; they are included in every plan, at no extra cost, within the number of connections your level includes, and the catalogue grows at no extra cost.
Let's talk

Let's size up the potential for your helpdesk

A few minutes to identify the most useful use case — hosted in France, supervised, with no commitment.