# How Fireblocks replaced Jira Service Management with agents its own team builds

_Fireblocks · 2026-05-19_

**Topics:** ITSM, Access Management, Security

Fireblocks provides digital asset custody and infrastructure, so every internal system - including the IT service desk - is held to a security bar most companies never face. Five months on from an empty tenant, Harmony answers first across IT, security operations, physical security and AI in Tel Aviv, New York and Singapore: the simple half of the queue never reaches a technician, and the engineers who used to wait behind it now ship agents of their own.

## Results

- **33%** - of 4,800+ employee conversations resolved with no ticket opened
- **915** - application access requests processed by agents
- **24** - agents on the platform, many built by Fireblocks' own team
- **2 days** - from a Slack spec to a production access agent, now at 269 runs

## At a glance

- **Industry:** Digital asset infrastructure and custody
- **Headquarters:** Tel Aviv, with offices in London, New York and Singapore
- **Workforce:** About 1,600 employees
- **IT team:** Security & IT under Kobi Seviliya, VP Security Engineering, with IT led by Meir Grinberg, Global IT Manager, and helpdesk teams in Israel, New York and Singapore
- **Where employees ask:** Slack, the self-service portal, email broadcasts
- **Connected context:** Okta, Jamf, CrowdStrike, HiBob, Google Workspace, Apple Business Manager, Slack, Jira and Confluence, JumpCloud, FleetDM, Figma, SIEM over webhook
- **Replaced:** A heavily customized Jira Service Management portal for employee support
- **Desks on the platform:** Eight, including IT, SecOps, Physical Security and AI

## The challenge: fragmented tools and a reputation to repair

Kobi Seviliya, who runs Security & IT at Fireblocks, did not soften the starting point when the evaluation opened: no processes, no automation, and an image problem for IT to match.

The tooling was fragmented. Tickets lived in Jira Service Management, heavily customized and shared with procurement, InfoSec and GRC. SaaS management ran in a separate product. Onboarding and offboarding were stitched together in an automation tool on top of a JSM ticket. Asset data came from personal scripts pushed into Jira. The AI team had built its own request intake, with a landing page and workflow tooling, and was struggling to keep up with volume.

Harmony's analysis of a year of JSM history found that 44% of all tickets were application access requests - the simple, repetitive half of the queue, sitting in front of technicians every day.

The AI bar was set early, and Kobi set it himself: a generic, unrelated answer destroys faith in a way that is very hard to recover, and the responsibility for that would sit with Harmony.

## Why Harmony: a security review first, then an operating model

The evaluation started as a security review. Fireblocks required IP allow-listing so the tenant is reachable only from its network, fixed egress IPs for every API call Harmony makes, masking of tokens and keys, secrets held in a dedicated secrets store, an audit log streamed to its SIEM, a kill switch through Okta, and AI models served through AWS with zero data retention. Harmony worked through each of these with the Fireblocks security team.

Then came the operating model. Meir Grinberg, who joined as Global IT Manager in March 2026 and took ownership of the rollout, wanted the agent to work the way a good technician does: "All these steps should be ping-pong, not sending him a whole guide." He also insisted on stronger verification than a simple approval for sensitive actions, and Harmony built the challenge to his bar.

> It can't be just an approval - the actions the agent can take are too critical. Harmony put the challenge at a higher level, exactly where we needed it.
>
> - Meir Grinberg, Global IT Manager, Fireblocks

The goal was consolidation, and Meir said it plainly in April: "The goal is to replace JSM so that everyone will be there." By the end of the month: "We are full power on this."

## Deployment: 39 minutes to five integrations, then a deliberate rollout

Onboarding started on April 12, 2026. Okta SSO with group mapping, Jamf, CrowdStrike, Google Workspace and Apple Business Manager were connected in 39 minutes. Two days later Harmony had ingested a year of Jira Service Management tickets, generated knowledge base articles from them, tagged 184 service accounts, and was pulling FileVault recovery keys and endpoint status. HiBob followed the next day, and SCIM provisioning with Okta push groups days later. Rather than rebuild the application approval workflows already defined in JSM, Meir asked Harmony to carry them over.

Meir's rollout plan was deliberate. A pilot group of 60 to 70 "stars" - a mix of the most and least technical people in the company - went first in May, and the JSM portal was closed to new tickets. Full IT team training and a company-wide launch followed in mid-June, with teams for Israel, New York and Singapore and round-robin assignment. On the training call Meir summed up where things stood.

> It's already operational for us. The organization is fully in it, and the teams are happy with what they are getting.
>
> - Meir Grinberg, Global IT Manager, Fireblocks

## The results

Since launch, Fireblocks employees have had more than 4,800 conversations with the Harmony agent, running at 300 to 560 a week, about two-thirds over Slack and most of the rest through the portal. A third ended without a ticket. SLA attainment climbed from 66% in the launch period to 80% over the most recent five weeks, reaching 85% in the last full week of August. Feedback on the agent's answers has been positive in 89% of responses.

### The simple tickets stopped reaching a technician

The 44% of the old JSM queue that was application access is now the platform's largest automation: Harmony's access request agent has run 915 times, resolving the application, routing to the right approver and provisioning through Okta groups. Device recovery and password resets run behind Okta Verify challenges. Between them, the requests that used to fill a technician's morning now close on their own.

Meir had stopped routing that work to his team before the company-wide launch had even happened. In April, with an employee locked out of her computer, his first instinct was already the agent rather than the helpdesk: "I sent her to Harmony. I said, talk to it, tell me if you get stuck." Five months on, that is simply how the queue works.

> Harmony took over all of our simple tickets. My team doesn't see them anymore, and the engineers finally spend their day on the work that actually needs them.
>
> - Meir Grinberg, Global IT Manager, Fireblocks

### The customer's own engineers build on it

With the routine layer handled, the interesting work moved up the stack. On July 21 Itzik Krikov, AI Solutions Architect, posted a spec in the shared Slack channel: an employee tags Harmony in Slack asking for access to a new AI model; the agent asks for a business justification and uses AI to turn away the empty ones; on a real justification it adds the user to the Okta group; 12 hours later it removes them. Two days later it was live. It has run 269 times since.

Fireblocks teams, from IT to BizApps, have built a growing set of their own agents. Among them: email release approvals routed to security operations with Okta-group approvers, Loom and Atlassian sub-app access, unblocking mobile devices in Google Workspace, a badge-system access form, and an after-hours office entry flow that reads HR data and triggers the door system. The AI team folded its home-built intake into a Harmony desk, with forms that open the right Jira epics and notify its channel.

Across all agents, Harmony has executed more than 4,200 workflow runs for Fireblocks. Eight desks now run on the platform, including IT, SecOps, Physical Security and AI.

## What's next

Fireblocks is moving its onboarding and offboarding flows out of the old automation tool and JSM entirely into Harmony, so provisioning, repository access and deprovisioning run from one place. Procurement and contractor processes are being designed on the platform, and the Physical Security desk is expanding.

Meir set his measure of success in April: "If even the non-technical people have a good experience with the agent, the technicians are happy, ticket volume goes down and people get answers."