Authorisation routes and what a service desk is

What decides which authorisation route a change takes, and what the service desk actually is — a point of contact rather than a place, a team, or a substitute for the practice that resolves incidents.

Lesson 7 of 12 in objective 7. Seven ITIL practices in detail, part of ITIL 4 Foundation.

Most incidents pass through both, and neither practice is a subset of the other. The service desk and Incident management overlap. The service desk alone: The single point of contact for users; Capturing and coordinating demand; Every channel users arrive by, and consistency across them. Incident management alone: How an incident gets resolved, wherever it is handled; Specialists, second-line teams and automation the desk never touches. In both: Most incidents: logged at the desk, resolved under incident management. What each holds alone In both The service desk The single point of contact for users Capturing and coordinating demand Every channel users arrive by, and consistency across them Incident management How an incident gets resolved, wherever it is handled Specialists, second-line teams and automation the desk never touches Most incidents: logged at the desk, resolved under incident management
Most incidents pass through both, and neither practice is a subset of the other.

What routes a change

The authorisation route a proposed change takes is determined primarily by its TYPE — standard, normal or emergency — because the applicable change model links each type to a defined assessment and authorisation route. The model is the mechanism; the type is the input.

It is tempting to answer "the risk" or "the cost", and both influence which type a change is classified as, but the question asks what determines the routing, and the routing is a property of the type and its model rather than something recalculated per change.

The type decides the route, and risk only influences which type it is. One test, and exactly one way out of it. The test is: Which type is this change, under the applicable model? (risk and cost shape the classification, never the routing itself). Standard leads to Runs under the authorisation given once, at the procedure (no fresh approval per instance); Normal leads to Assessed and authorised by the route the model defines (the model names who assesses and who authorises); Emergency leads to A compressed route, often a separate authority (expedited and never skipped; the record catches up). Which type is this change, under the applicable model? risk and cost shape the classification, never the routing itself Standard Normal Emergency Runs under the authorisation given once, at the procedure no fresh approval per instance Assessed and authorised by the route the model defines the model names who assesses and who authorises A compressed route, often a separate authority expedited and never skipped; the record catches up
The type decides the route, and risk only influences which type it is.

The service desk is a point of contact, not a place

An organisation that closes its single co-located help desk and staffs the function from three countries, with every contact arriving through one shared tool alongside a chatbot, still has a service desk. The practice is defined by being the single point of contact for users, not by being a room, a team, or a phone number. Distributed staffing, multiple channels and automation are all compatible with it, provided the single point of contact holds.

Adding a self-service portal and a chatbot alongside the telephone is therefore not a replacement for the service desk. Those are additional CHANNELS into the same single point of contact, and the requirement they bring with them is consistency: a user should get a comparable experience whichever route they come in by, and a contact should not fall between channels.

New channels are routes into the one point of contact, not replacements for it. Left column, The route a user arrives by; right column, Where every route lands. The telephone, A self-service portal and A chatbot all point at The single point of contact (A comparable experience whichever way in, and no contact falling between channels). The route a user arrives by Where every route lands The telephone A self-service portal A chatbot The single point of contact A comparable experience whichever way in, and no contact falling between channels
New channels are routes into the one point of contact, not replacements for it.

Why the service desk does not replace incident management

A manager arguing that the organisation needs no incident management practice because the service desk already logs and resolves incidents has confused a point of contact with a practice that governs resolution. The service desk captures and coordinates demand; incident management defines how incidents are resolved wherever they are handled — including by second-line teams, by specialists, and by automation the service desk never touches.

The clean way to hold the two apart: the service desk answers "how does work reach us and get owned", incident management answers "how does an incident get resolved". Most incidents pass through both, and neither is a subset of the other.

Who to hire onto it

The capability profile for service desk staff leans towards empathy, communication and emotional intelligence, combined with an understanding of the business the users work in. Deep technical specialism is not the priority, because the desk's job is understanding what the user actually needs and getting it owned and progressed, not resolving every case itself.

That is a genuinely counter-intuitive answer for a technical exam, and it is asked directly for that reason.

Worth carrying in

Change model
Links a change type to its defined assessment and authorisation route.
Single point of contact
What defines a service desk. Not a room, a team or a location.
Channels
Phone, portal, chatbot — routes into one point of contact, with a consistent experience.
Service desk capabilities
Empathy, communication, emotional intelligence, business understanding.

What the exam does with this

Objective
7. Seven ITIL practices in detail
Share of the exam
47.5% (the whole objective)
Questions in this lesson
5
Signed for by a person
0

Partly checked. None of the 5 questions here has been read against the cited source by a person. 5 questions have been checked against their cited clause by an automated pass — which is not the same thing, and is not a signature.

Only questions a person has signed for are used in mock exams here. That is the whole difference between the two kinds of checking above.

How these questions are written — where each question comes from, what the verification ledger records, and what happens when one is found wrong.

Drill this lesson

A lesson is one sitting: the trainer draws a short run from these questions alone and spaces the ones you get wrong.

Practise Authorisation routes and what a service desk is

Questions in this lesson

Practise Authorisation routes and what a service desk is

The rest of objective 7