Automation Catalog · ships with the platform

Already built. Ready to run.

The work every desk repeats (password resets, mailbox delegation, server reboots, endpoint fixes, onboarding), as automation flows that ship with the platform. No agent to design, no flow to chart: approval-gated, fully audited, live from day one.

redwood.virtualpeople.ai/automations/runs/8412Completed
Unlock Account / Reset PasswordAutomation Catalog · Identity & Access
Self-serve
“I’m locked out again. Can you fix it?”asked in Sidekick · Microsoft Teams · 9:41 AM
Run
1Verify identityMFA push · verified
2Unlock accountActive Directory
3Reset passwordsecure link · change at next logon
4Sync directoriesAAD Connect
Sensitive flows gate first, a group change here waits for the owner’s approval before anything runs.
41s to resolvedAudit entry writtenUser notified in Teams

A catalog flow in action: self-serve, executed end-to-end, audited.

29ready-to-run flows
7domains covered
14self-serve for employees
100%approval-gated & audited

Identity & Access

6 flows

Lockouts, resets and group changes executed against the directory, approval gates scale to the sensitivity of the action.

Unlock Account / Reset Password

Self-serve

Unlock and/or reset password, force change at next logon, run AAD Connect sync.

AD, Entra, Okta · None via self-serve + MFA; Manager if via ticket

Find User Lockout Source

Queries Event 4740 on the PDC, then 4625 on the source machine, to identify the stale mapped drive, cached credential, scheduled task or service behind repeat lockouts.

AD (PDC Emulator + source computer) · None

MFA Reset

Self-serve

Resets device registration and factors; the Okta variant supports single-factor deletion or a full reset.

Entra, Okta · Identity verify

Add / Remove User from Group

Self-serve

Single user or bulk CSV, with optional time-bound expiration on membership.

AD, Entra · Owner (sensitive groups) / Manager

Get BitLocker Recovery Key

Looks up the correct directory based on management source, returns the key with an audit trail, optional auto-rotate after use.

AD, Entra, Intune · Identity verify: helpdesk only, no self-serve

Account Expiration Reminder

Scans at 30/14/7/1 days, notifies user and manager, with an inline “extend” option.

AD, Entra · None · Scheduled

Exchange & Mail

6 flows

Mailboxes, delegation, DLs and message traces: Exchange Online and on-prem Server, owner- and manager-gated.

Distribution List Management

Add or remove members, create new DLs, bulk CSV supported.

Exchange Online + Server · Owner (existing DL) / Manager (new DL)

Create Shared Mailbox

Provisions the mailbox, sets Full Access and Send As, optional hide-from-GAL and DL attachment.

Exchange Online + Server · Manager

Delegate Mailbox Access

Full Access / Send As / Send on Behalf, with a calendar-delegate variant and automap toggle.

Exchange Online + Server · Mailbox owner or manager

Find Email Messages (Message Trace)

Trace by sender, recipient, subject or date; aggregates transport hops for on-prem.

Exchange Online + Server · None

Set Out-of-Office

Self-serve

Internal and external messages with date ranges; reused as an offboarding sub-step.

Exchange Online + Server · Self / Manager

Global Email Whitelist

Tenant-wide allow-list addition with full audit.

Exchange Online, Exchange Server · Security / Email admin

Server & Infrastructure

3 flows

Power actions and print queues inside change windows: from inside the guest, or at the hypervisor.

Reboot Server

Graceful reboot from inside the guest.

Physical/VM Windows via controlling agent; WinRM via network-adjacent agent for agentless VMs · Change window / Manager for production

Start / Stop / Reboot VM

Hypervisor-level power action for unreachable guests or scheduled maintenance.

Hyper-V (PowerShell), VMware API, cloud hypervisors · Change window

Print Server Queue Management

Restart the spooler, clear the queue for a specific printer, view printer config, server-side.

Windows Print Server · None

SharePoint

1 flow

Site permissions with granular inheritance control, down to a single library or folder.

Add / Remove SharePoint Site Permissions

Owners/Members/Visitors group changes, with optional break/restore inheritance on a specific library or folder, without affecting the parent site.

SharePoint Online or on-prem · Site owner

Licensing

1 flow

License moves that report pool availability after every change, cost control built in.

Remove / Assign / Update User License

Direct or group-based licensing; returns real-time pool availability after every change.

Entra (M365), third-party portals · Manager for cost-bearing SKUs

Endpoint Diagnostics & Remediation

10 flows

Just-in-time flows that run on the user's own device: no remote session, no queue.

OneDrive Sync Issues

Self-serve

Check sync status and stuck/paused files; restart OneDrive; clear the sync cache; run a reset if corruption is detected; verify sign-in and tenant config; report known blockers like long paths, invalid characters and file locks.

User's own device (JIT) · MFA identity verification · Teams bot or helpdesk ticket

Audio / Meeting Device Issues

Self-serve

Enumerate playback and recording devices; detect current default vs. expected meeting-app device; reset default I/O; check muted devices, disabled drivers and app-level permissions; restart the Windows Audio service.

User's own device (JIT) · MFA identity verification · Teams bot or helpdesk ticket

Printer Issues (Endpoint)

Self-serve

Check the local print spooler and restart if stuck; clear stuck jobs; detect offline printers; verify driver status and re-enumerate installed printers; test connectivity to the print server or network printer.

User's own device (JIT) · MFA identity verification · Teams bot or helpdesk ticket

Outlook Opening Issues (Clear Cache)

Self-serve

Kill hung Outlook processes; clear RoamCache, auto-complete and OST staging; detect a corrupt profile and offer reset; launch in safe mode to isolate add-ins; check Exchange/M365 connectivity.

User's own device (JIT) · MFA identity verification · Teams bot or helpdesk ticket

VPN Connection Diagnostics

Self-serve

Check VPN client status and version; restart the VPN adapter and related network services; clear cached VPN credentials; test reachability to gateway and internal endpoints; validate split-tunnel routes and DNS resolution.

User's own device (JIT) · MFA identity verification · Teams bot or helpdesk ticket

General Computer JIT Diagnostic

Self-serve

RAM usage and top memory consumers; stuck apps; disk usage and free space per drive; SMART disk health; Windows Update status and pending reboots.

User's own device (JIT) · MFA identity verification · Teams bot or helpdesk ticket

Disk Cleanup / Free Up Space

Self-serve

Inventory space by category (temp, cache, Windows.old, hibernation, old drivers); clear user and system temp files; clean browser and app caches; empty the Recycle Bin with user confirmation; report space reclaimed.

User's own device (JIT) · MFA identity verification · Teams bot or helpdesk ticket

Mapped Drives Reconnection

Self-serve

List configured mapped drives and status; detect disconnected shares; re-authenticate and reconnect; clear stale cached credentials from Credential Manager; verify network path and DNS resolution to the file server.

User's own device (JIT) · MFA identity verification · Teams bot or helpdesk ticket

Software Install / Uninstall

Self-serve

Company-approved apps only: pull from the internal catalog; silent install with the correct version and flags; verify install and register with inventory; clean uninstall including leftover registry keys and folders; report status to user and IT.

User's own device (JIT) · MFA identity verification · Teams bot or helpdesk ticket

Teams Cache Diagnostics

Self-serve

Detect classic Teams, New Teams, or both; kill running processes; clear the cache from the correct path per variant; reset sign-in state if auth is stuck; relaunch and verify startup.

User's own device (JIT) · MFA identity verification · Teams bot or helpdesk ticket

User Lifecycle

2 flows

HR-triggered onboarding and staged offboarding: disable, then delete, with retention enforced throughout.

Onboard a User

Creates the AD user from a role template and syncs to Entra; assigns licenses and group memberships; provisions the mailbox and enrolls the device in Intune; provisions workplace apps (Slack/Zoom/SaaS); pushes the record to the HR repo.

AD, Entra, Intune, SharePoint, workplace apps, HR repo · HR + Manager · HR-triggered

Offboard a User

Staged disable-then-delete: disables the account and strips groups; converts the mailbox to shared with manager delegation; delegates OneDrive and wipes/removes devices; deprovisions workplace apps; extends retention per policy.

AD, Entra, Intune, Exchange/OneDrive, SharePoint, workplace apps, HR repo · HR + Manager · HR-triggered

Beyond the catalog

Need something the catalog doesn’t cover?

The catalog covers the work every desk shares. For everything specific to yours, our team builds the automation for you: end-to-end, during onboarding, using the same internal AI tooling that powers Creator Studio: the conversational builder, coming soon, where your own team will create automations that run across Sidekick, Voice and Agent Studio. Governed and audited either way.