# Automated Policy Exception Routing

*/Opportunities/Automated_Policy_Exception_Routing*

## Opportunity Overview

**Wedge**: Start exclusively with developer endpoint security exceptions, such as requests for local admin rights or bypassing corporate proxies. Developers generate the highest volume of valid, complex exceptions, and SecOps experiences acute pain manually unblocking them while preserving audit trails. Expand laterally from endpoint exceptions to network perimeter changes, and finally capture identity and access management lifecycle exceptions.
**Timing**: Large language models with expanded context windows ingest hundreds of pages of corporate policy documents and accurately map unstructured employee requests against complex compliance frameworks. This capability replaces the human judgment previously required to determine if a request violates a hard baseline or qualifies for a temporary exception.
**Why This I C P**: Enterprise SecOps teams experience severe friction between enforcing rigid compliance mandates and meeting strict SLAs for unblocking employee productivity. They hold dedicated budgets for automation tools that resolve this operational bottleneck without degrading the organization's security posture.
**Size Of Prize**: ~25,000 mid-to-large enterprises globally dedicate at least one full-time equivalent or ~$80,000 annually in Level 1 and Level 2 labor specifically to triage and route security policy exceptions. Multiplying 25,000 enterprises by $80,000 yields a $2B addressable market for exception routing automation.
**Gap Narrative**: Enterprise SecOps and IT teams manually triage policy exception requests, such as local admin rights, firewall rule changes, or non-standard software installations. Current ticketing systems rely on static routing rules that fail to capture the nuance of the request, forcing Level 1 analysts to read tickets, consult policy documents, and manually identify the correct risk owner for approval. These teams require an engine that maps natural language requests directly against compliance frameworks and routes them autonomously.
**Defensibility**: Defensibility stems from deep workflow lock-in and the accumulation of historical exception data. As the system routes thousands of requests, it builds an institutional graph of which specific risk owners approve distinct edge cases, establishing a shadow-policy engine that becomes deeply embedded in the enterprise's compliance audit processes and highly painful to replace.
**Why This Thesis**: An Agentic thesis fits this problem because exception handling is an unstructured, multi-step reasoning task. The system retrieves identity context, reads natural language requests, reasons against a set of written policies, and executes actions via API in Jira or Slack, which traditional static rules engines cannot accomplish.

## Opportunity Linked Thesis

**Thesis**: [Software](/Theses/Software)

## Opportunity Linked I C P

**Icp**: [Financial Services Firm](/CompanyTypes/Financial_Services_Firm)

## Opportunity Market Sizing

_Illustrative — target and order-of-magnitude estimate figures, not an achieved track record (this Thing is concept-stage)._

**S A M**: ~$1.5B-$2B representing US and European mid-market to enterprise financial services firms
**S O M**: ~$30M-$60M realistically obtainable over 3 years targeting US regional banks and asset managers
**T A M**: ~75k-100k global financial institutions × ~$60k/yr average exception management software value ≈ ~$4.5B-$6B
**Growth Rate**: ~12-16%/yr, driven by expanding global regulatory compliance mandates and rising transaction volumes generating edge-case exceptions
**Paid Comparable Spend**: ~$100k-$250k/yr per firm spent on tier-1 compliance analyst labor for manual triage and legacy workflow system maintenance

## Opportunity Incumbents

- [ServiceNow GRC](/Products/ServiceNow_GRC) — Tool
- [Jira Service Management](/Products/Jira_Service_Management) — Tool
- [RSA Archer](/Products/RSA_Archer) — Tool
- [Shared Email Inboxes](/Products/Shared_Email_Inboxes) — DIY
- [Excel Exception Logs](/Products/Excel_Exception_Logs) — Spreadsheet
- [SharePoint Lists](/Products/SharePoint_Lists) — DIY

## Opportunity Win Conditions

**Kill Thresholds**:
- Auto-routing accuracy remains < 80% after 14 days of data ingestion
- Pilot deployment takes > 21 days due to IT hurdles
- Analyst override rate > 15% across early cohorts
- ACV falls below $40k due to perceived lack of enterprise readiness
**Leading Metrics**:
- Time-to-first-automated-route
- Auto-routing accuracy rate
- Analyst override rate
- Average time spent per triage event
**What Proves Right**: Compliance operations teams deploy the routing engine and bypass manual tier-1 triage entirely. The system achieves high straight-through routing accuracy, allowing analysts to focus strictly on resolving the exceptions rather than assigning them. Mid-market financial institutions convert from pilots to $60k annual contracts within 60 days because the labor savings are immediately quantifiable.
**What Proves Wrong**: Firms abandon pilots because the routing logic fails to handle bespoke regulatory edge cases or complex internal data silos. Analysts frequently override the automated assignments, negating the time savings and reverting trust back to shared email inboxes. The integration requires heavy IT involvement, extending time-to-value beyond the patience of the compliance buyers.

## Opportunity Build Profile

**Hardest Part**: Mapping fluid organizational hierarchies and fragmented policy ownership structures across disconnected HRIS and IT systems to dynamically identify the single exact human authorized to accept a specific risk.
**Min Viable Scope**: A routing engine exclusively for internal software access exceptions that reads tickets from ServiceNow and pings the requester direct manager and the specific application owner. Leave out auto-approvals, compliance risk scoring, and multi-tier escalation logic.
**Cold Start Problem**: The system requires deep integrations with proprietary identity providers and ticketing software before it routes a single request. Break this by deploying a lightweight Slack or Teams bot that intercepts unstructured requests and prompts the user to manually tag their assumed approver, logging these pairs to map the initial graph.
**Time To First Value**: 1-2 weeks of HRIS and ITSM integration to establish baseline reporting lines
**Data Moat Available**: false
**Technical Difficulty**: Moderate

## Neighborhood

### Surfaced from

- [Corporate Relocation Providers](/CompanyTypes/Corporate_Relocation_Providers) — surfaces · CompanyTypes

### Incumbent in

- [Microsoft Excel Tracker](/Products/Microsoft_Excel_Tracker) — incumbent in · Products
- [Excel Error Logs](/Products/Excel_Error_Logs) — incumbent in · Products
- [Jira Service Management](/Software/Jira_Service_Management) — incumbent in · Software
- [RSA Archer](/Products/RSA_Archer) — incumbent in · Products
- [ServiceNow GRC](/Products/ServiceNow_GRC) — incumbent in · Products
- [SharePoint Lists](/Products/SharePoint_Lists) — incumbent in · Products
- [Shared Email Inboxes](/Products/Shared_Email_Inboxes) — incumbent in · Products
- [ServiceNow HRSD](/Products/ServiceNow_HRSD) — incumbent in · Products
- [Topia Global Mobility](/Products/Topia_Global_Mobility) — incumbent in · Products
- [Custom SharePoint Workflows](/Products/Custom_SharePoint_Workflows) — incumbent in · Products
- [Equus AssignmentPro](/Products/Equus_AssignmentPro) — incumbent in · Products

### Applies thesis

- [Financial Services Firm](/CompanyTypes/Financial_Services_Firm) — applies thesis · CompanyTypes

### Embodies

- [Software](/Theses/Software) — embodies · Theses
- [Agent](/Theses/Agent) — embodies · Theses

### Similar Opportunities

- [Policy Exception Routing](/Opportunities/Policy_Exception_Routing) — similar · Opportunities
- [KYC Resolution Agent](/Opportunities/KYC_Resolution_Agent) — similar · Opportunities
- [Automated Policy Exception Routing](/CompanyTypes/Corporate_Relocation_Providers/Opportunities/Automated_Policy_Exception_Routing) — similar · Opportunities
- [Compliance Audit Agent](/Opportunities/Compliance_Audit_Agent) — similar · Opportunities
- [Ticket Context Router](/Opportunities/Ticket_Context_Router) — similar · Opportunities
- [Continuous Evidence Gateway](/Opportunities/Continuous_Evidence_Gateway) — similar · Opportunities
- [Shadow Approval Engine](/Opportunities/Shadow_Approval_Engine) — similar · Opportunities
- [Code Compliance Triage](/Opportunities/Code_Compliance_Triage) — similar · Opportunities
- [Policy Exception Routing](/CompanyTypes/Corporate_Relocation_Providers/Opportunities/Policy_Exception_Routing) — similar · Opportunities
- [Compliance Reporting Engine](/Opportunities/Compliance_Reporting_Engine) — similar · Opportunities
- [Autonomous Exception Handler](/Opportunities/Autonomous_Exception_Handler) — similar · Opportunities
- [Continuous Compliance Automation](/Opportunities/Continuous_Compliance_Automation) — similar · Opportunities
- [Just-In-Time Provisioning for DevOps](/Opportunities/Just-In-Time_Provisioning_for_DevOps) — similar · Opportunities
- [Automated Compliance Gate](/Opportunities/Automated_Compliance_Gate) — similar · Opportunities
- [Audit Request Fulfillment](/Opportunities/Audit_Request_Fulfillment) — similar · Opportunities
- [Compliance Assessment Agent](/Opportunities/Compliance_Assessment_Agent) — similar · Opportunities
- [Compliance Remediation Pipeline](/Opportunities/Compliance_Remediation_Pipeline) — similar · Opportunities
- [Automated Compliance Reporting Generation](/Opportunities/Automated_Compliance_Reporting_Generation) — similar · Opportunities
- [Managed Auth Operations](/Opportunities/Managed_Auth_Operations) — similar · Opportunities
- [Automated Evidence Collection](/Opportunities/Automated_Evidence_Collection) — similar · Opportunities
