Blog · July 15, 2026 · Knox Hutchinson
Why Every Network Ticket Lands on the Same Desk
- The Junior: Look Dumb or Touch Prod
- The Senior: The Delegation Deadlock
- The Manager: The Black Box
- One Flaw, Three Bills
- A Decade of “Self-Driving” Made It Worse
- What a Real Fix Has to Look Like
- What We’re Building
Walk into any shop with a network practice — an MSP, an enterprise team, doesn’t matter — and ask where the hard network tickets go. Nobody points at a queue. They point at a person.
Every shop has that desk. The engineer who knows why the VLANs are numbered the way they are, which firewall rule nobody is allowed to touch, what actually happened during the 2019 outage. The one who takes their hotspot on vacation.
We talk about this like it’s a staffing problem: hire another senior, cross-train, write more documentation. Twenty years of that advice hasn’t moved the needle, because it isn’t a staffing problem. It’s a design flaw in how network work is structured — and it traps three different careers in three different ways.
The Junior: Look Dumb or Touch Prod
A ticket lands: “branch is slow.” The junior has two options.
Option one: escalate with nothing. “Client says it’s slow” gets forwarded up with no interface stats, no routing table, no evidence — because gathering evidence means logging into gear they’re not fully trusted on. The senior sighs, the ticket bounces, and the junior learns nothing except that escalating feels like failing.
Option two: start poking at production. Which is how résumés get updated.
Everything else they could ask is blind. Google has never seen their network. Neither has a chatbot — paste in a symptom and you get generic advice about a topology it can’t see. The lab they built for their CCNA doesn’t have this network’s twelve years of accumulated decisions in it.
So they under-investigate, escalate thin, get dismissed, and the fear compounds. Here’s the part that should worry everyone: networking is learned by touching gear, and touching gear is precisely what juniors aren’t allowed to do. The first three years decide whether someone becomes a network person at all — and in most shops, fear is doing the deciding.
The Senior: The Delegation Deadlock
Ask the senior why they don’t delegate investigations and you’ll get a version of the same answer everywhere: because on network gear, the tool that lets you look is the tool that lets you change.
The session that runs show ip ospf neighbor is one command away from conf t. Yes, you can in principle build read-only views — TACACS command authorization, RBAC profiles, login classes. Every senior knows the reality: it’s per-vendor, per-platform, brittle, and perpetually half-deployed. Most environments run flat admin credentials, and everyone quietly knows it.
And even a perfect read-only account doesn’t close the gap, because access isn’t the only thing the junior is missing. They don’t yet know what to look at. The senior can’t sit beside every investigation and narrate.
So the senior faces their own bad pair of options: hand a junior interactive access to production and accept the risk, or keep the access and accept the queue. They keep the access. Rationally — preventing that risk is their job.
The result is the deadlock: every ticket above L1 routes to one desk. Interrupt hell all day. On-call that never rotates in practice, because nobody else can clear the page. 3am wake-ups for faults an L1 could have found with guidance. The design and architecture work they were actually hired for, permanently displaced by triage.
Twenty years of expertise, and what it built is a jail cell.
The Manager: The Black Box
One level up sits someone who holds the budget and cannot evaluate the work.
Every escalation is a black box. Is this ticket genuinely hard, or is my engineer just buried? Is the network practice healthy, or is it one bad month from collapse? The manager can’t audit their own dread, because they can’t read a routing table — they manage outcomes they have no instruments for.
What they can see is the shape of the risk. The senior is a single point of failure: if that engineer resigns, the shop holds contracts it can’t service, and it can’t hire its way out quickly — senior network engineers are scarce, expensive, and the good ones don’t want the on-call. Meanwhile the most expensive hour in the building spends its time on work a cheaper hour could have done, if the cheaper hour had a safe way to do it. Every escalation that waits on one desk burns SLA clock.
So the practice stops growing. Shops decline network-heavy work they can’t staff. Kaseya’s own 2026 State of the MSP survey has 48% of MSPs ranking AI and automation as the #1 client need — while only 13% say they make meaningful revenue from it. That gap is not a demand problem.
And there’s a newer anxiety stacked on top. The manager’s software vendors shout AI at them weekly, while AI touching client gear — under contracts that promise change control — is a liability they can’t sign. Their insurer has made it concrete: AI exclusions started appearing in commercial policies in 2026, and renewal questionnaires now ask, in so many words, how do you validate your reliance on AI-generated results? The manager has no permission structure for saying yes. So they say nothing, and the ladder below them stays stuck.
One more cost hides in plain sight: a large share of “network” tickets aren’t network problems at all. Proving that — proving innocence — takes the same scarce expertise as fixing a real fault. So even the tickets that aren’t network tickets land on the same desk.
One Flaw, Three Bills
Line the three stories up and it’s one problem wearing three job titles.
The expertise is trapped in one head, and everyone in the building pays for it. The junior pays in fear. The senior pays in interrupts. The manager pays in risk. And the mechanism that keeps it trapped is a single coupling buried so deep in how network tools work that we stopped seeing it:
Investigation requires write access.
Because looking and changing arrive as one privilege, investigation can’t be delegated (the senior won’t hand out the keys), can’t be practiced (the junior can’t safely touch), and can’t be scaled (the manager can’t buy more of the one person it lives in). Expertise pools exactly where access pools. That’s the design flaw. Everything else is symptoms.
A Decade of “Self-Driving” Made It Worse
The industry noticed the bottleneck. Its answer was to aim billions of venture dollars at replacing the person: the self-driving network, the autonomous NOC, agents that “diagnose, decide, and act.” Autonomy in the headline; “human in the loop” somewhere in the body copy.
Run that pitch through the ladder and watch it fail. The manager hears a liability their change-control commitments can’t absorb. The junior hears that the career they’re bleeding for is being automated away. And the senior — the one person whose approval the whole stack turns on — hears a vendor selling their replacement, and vetoes it. Any tool the senior vetoes is shelfware.
Senior engineers’ hostility to AI isn’t ignorance. It’s a learned response to ten years of being told they’re the cost to eliminate.
What a Real Fix Has to Look Like
Strip the problem to its hinge and the requirements write themselves. Any tool that actually opens this trap — anyone’s tool — has to deliver four properties:
-
Investigation decoupled from change — structurally, not by policy. Not a “safe mode,” not a setting someone can toggle, not a promise in the docs. A safety mode is a promise. No write path is a property. It has to be impossible, by construction, for the investigating side to modify the network.
-
Guidance in the flow of work. The junior’s gap is judgment, not just access. An investigation should teach — what to check, in what order, and why — as a worked example on their own network, not a generic runbook.
-
Evidence as the output. The artifact of an investigation should be an escalation a senior respects and a summary a manager (or a client) can read: root cause, supporting output, what was checked and ruled out. Legibility is what turns the black box back into a management surface.
-
A human on the trigger, and a record of what ran. Anything that touches a device gets approved by the person at the keyboard, and the session log shows exactly what ran. That audit trail happens to be the literal answer to the insurance questionnaire — but mostly it’s what makes delegation something a senior can defend.
Hold those four and every rung opens. The junior investigates real gear safely — the “look dumb or touch prod” dilemma dissolves. The senior delegates the investigation without delegating the keys, and keeps making every call that matters. The manager gets escalations they can read, a hedge on their key person, and a way to say yes to AI without breaking the promises in their contracts.
What We’re Building
This essay is the problem statement for Transit. It’s an AI-native SSH client for network engineers whose agent is investigation-only by architecture: it reads your live sessions and proposes read-only diagnostics, and every command passes a per-vendor policy gate plus a human approval click before it runs. There is no code path from the agent to anything that changes your gear — the full enforcement story, down to the build check, is in Why We Made the AI Investigation-Only.
The terminal is free; the AI has a 14-day trial — transitai.app.
It proposed. I clicked. That’s the whole design.