B
BestDesk
Cold open
Live · bestdesk.my
01 / 31

Bestinet AI Builders Challenge 2026 · Demonstration

The ticketing system that already runs.

BestDesk is an AI-augmented support operations platform built inside Bestinet, by the people who answer the calls. It is not a proposal, not a prototype, and not a slide. It is in production at bestdesk.my right now — and we will drive it live in this session.

Live in production FWCMS · ePLKS · VDR · Levy · PLKS Built in-house · owned by Bestinet

Presented 27 August 2026 · Bestinet Sdn Bhd

Team BestDesk

IffahOpening & framing
01
NorizanThe problem on the floor
02
AzamThe system & the live demo
03
HidayatArchitecture & integration
04
AzamThe business case & the ask
05

Industry context · why now

Traders have a name for this year: the SaaSpocalypse.

In one trading session this January, US$285 billion was wiped off enterprise software stocks when AI agents moved directly into CRM and support territory. The per-seat software model — the model Bestinet pays for today — is the one under attack.

“We were more confident about what the AI could do than we were prepared for what it couldn't.” Senior Salesforce executive — three months after cutting 4,000 support staff, and shortly before hiring people back
4,000

support staff cut by Salesforce, announced as an AI success. Three months later they were redeploying and rehiring.September–December 2025

77%

of Agentforce enterprise deployments failed to reach successful deployment.Valoir research

0 / 3

showcased customers were actually using the AI when Bloomberg called them. The official answer: the adverts were “future-oriented”.Bloomberg, May 2026

3%

of Salesforce revenue is what the AI bet actually generates, behind the bundled headline figure.Q1 2026 filings

Industry context · the second warning

The other trap: the vibe-coding backfire.

AI made building software fast. It did not make software understood. Teams shipped AI-generated systems nobody could maintain — the industry calls it the day-two problem: the demo works, then the billing system changes, and no one knows how the code actually flows.

“Almost right, but not quite.” The #1 developer complaint about AI-generated code — Stack Overflow survey, 2025. Almost-right code is worse than broken code: it fails after you trust it.
39%

of business leaders made staff redundant after deploying AI.OrgVue, 2025

55%

of those same leaders later admitted the decision was wrong.OrgVue, 2025

700

agents' worth of work Klarna claimed its AI was doing — before quality collapsed and they rebuilt human support.Klarna, 2025

risk in one finding: developers using AI assistants wrote less secure code while feeling more confident it was safe.Security research, 2025

Our answer, point by point

What we did instead.

Day-two problem — AI writes it fast, nobody understands it later.
35+ documented build sessions, an append-only decision history, and a locked-decisions register in the repo. Every choice has a written reason.
"Almost right, but not quite" — AI output that is wrong in ways you don't notice.
AI in BestDesk never auto-applies. It is confidence-gated, the operator accepts or rejects, and every interaction is logged with feedback.
Less secure, more confident — AI-assisted code that feels safe and isn't.
Role enforcement on every endpoint, a full activity log, CI lint on every push, a three-tier QA gate, and Sentry in production.
"Future-oriented" demos — marketing showing features that don't exist.
Nothing in this deck is a mockup. In a few minutes we switch tabs and drive the production portal live in front of you.
Cut heads, hire back — AI sold as headcount reduction.
BestDesk removes the minutes of copying data between three portals — not the operator. The case is capacity, not redundancy.
Per-seat lock-in — the bill grows with the team, the roadmap belongs to the vendor.
Zero per-seat cost. Bestinet owns every line, every config table, and the roadmap. Adding the 400th operator costs nothing extra.
Norizan · the problem on the floor

One call. A dead, empty form. Three portals before anyone starts solving anything.

ManageEngine

The operator opens a ticket — and gets a dead, empty form. It knows nothing about the caller, the application, or the module. Every field starts blank.

1–2 min
FWCMS portal

Second tab. Search the employer by name or ROC. Find the application. Read the status. Copy the details out by hand.

3–5 min
MyIMMs checker

Third tab. Cross-check the immigration status. Then paste everything back into the dead form in tab one — and hope nothing was mistyped.

3–4 min
6–8 min

of copying between portals before a single word of the actual problem gets addressed — per ticket, every ticket. At 2,000 interactions a day that is roughly 200 operator-hours a day moved between windows by hand.

~15%misroutedfor missing context at creation

Current state · until today, this is how we operate

The parts nobody outside operations ever sees.

Integration No connection to FWCMS — and the API idea always dies

ManageEngine has no reference data and no link to FWCMS. Connecting it via API has been raised more than once — the answer is always the same: platform limitations, and the famous financial limit. A custom integration is a vendor project with a vendor price.

Email Email support is 100% manual — every single step

No cockpit, no auto-acknowledgement, nothing. An operator reads the inbox, creates the ticket by hand, replies by hand — and at the end of the day counts by hand how many emails they handled, because nothing counts it for them.

Bulk Bulk requests exist only as email threads

"Process these fifty workers" lives in a mailbox. No ticket, no line items, no owner — and because there is no ticket, no SLA can even be counted. Zero percent tracked, by construction.

SLA / OLA No OLA — the system design doesn't allow it

ManageEngine tracks one clock. The team-level response targets our operation actually runs on cannot be represented in the tool, so they live in spreadsheets and memory instead.

Knowledge The KB is a SharePoint folder

Procedures sit as files in a team folder. An operator on a live call digs through documents with no real search — and none of it is connected to the ticket in front of them. Imagine the KB living inside the ticketing system instead.

Reporting A dashboard nobody understands, a report built by hand

ManageEngine has a dashboard — did anyone understand it? did anyone use it? Every week the CS meeting reviews performance retrospective-style, from a report that still has to be generated manually from raw data.

Operators25→ 400+ planned
Interactions / day2,000calls + email + bulk
SLA compliance~72%tracked in spreadsheets
Bulk tracked0%email only — no SLA possible
Weekly reporting2–4 hmanual, from raw exports

We did look at the alternatives

Four category leaders. The same missing piece in all four.

JIRA

A developer tool repurposed as a service desk. Its workflow model is built for code sprints, not call-centre queues.

Configuration needs IT expertise. No concept of a requester linked to a live government record.

Wrong shape for a contact centre

Zendesk

A real support tool — but designed for e-commerce and SaaS. Every customisation for a government operations centre is billable.

Per-agent pricing. The KB is generic and cannot be seeded with FWCMS content or linked to live application data.

SLA reporting sits behind paid add-ons

Salesforce

Enterprise-grade and genuinely powerful — and it needs a dedicated administrator, months of configuration, and a consultant ecosystem.

The licensing model prices out a Malaysian centre scaling from 25 to 400 operators. And its AI story is the one from slide two.

Overhead exceeds the problem

ManageEngine

The closest operational fit — and what we use today. Ticket types, SLA rules, escalation paths, a knowledge base.

But it knows nothing about FWCMS, cannot model our OLA, and the API integration we asked for repeatedly was never feasible — limitations, and the financial limit.

Two systems. Double the time. No shared context

None of them can be told what ePLKS is. None of them know the difference between a BULK_SR and an SR to a Bestinet operator. And if a feature isn't on the vendor's roadmap, you wait — or you pay. So we stopped waiting.

Azam · the system & the demo

One workspace that already knows who is calling and what they applied for.

BestDesk sign-in page: dark command-centre layout with an animated capability showcase on the left and the sign-in card on the right
The production sign-in page at bestdesk.my — screenshot from the deployed build — the live portal in the next tab is the real exhibit.

BestDesk is an AI-augmented support operations platform, built inside Bestinet for FWCMS operations, and running in production today.

  • Connected to 340,000+ FWCMS application records and 43,000+ requesters
  • Claude Haiku classifies, drafts, summarises and suggests — the operator always decides
  • SLA and OLA calculated automatically, working-hours and Malaysian public-holiday aware
  • Inbound email becomes a triaged ticket with a full audit trail
  • Every configuration table is editable by an admin at runtime — no deployment to change an SLA
The tagline on that screen is not marketing copy we wrote for this deck. It has been on the production login page since June: “Your command centre for every query that matters.”

What is shipped and running

Eight capabilities. All of them in production.

These are the same eight the login page cycles through — the product introduces itself before anyone signs in.

Unified ticket queue

Every incident and service request — logged, routed and resolved in one workspace. Five ticket types: INC, SR, INT, ISR and Bulk.

AI-assisted triage

Claude classifies, drafts and pre-fills. Operators decide instead of typing. Nothing is applied without a human click.

Reference intelligence

Live FWCMS, ePLKS, VDR, eQuota and PLKS status inside every ticket — including a live call to Bestinet's own SST API.

SLA & escalation engine

Deadlines, pause/resume, breach detection and escalation paths that run themselves — working hours and public holidays included.

Email triage cockpit

An IMAP poller turns inbound mail into a triage queue. One click converts to a ticket with the requester matched and a confirmation sent.

Bulk operations

The batch work that used to live in email chains — now a parent ticket with tracked line items, promotable to child tickets.

Knowledge base

FWCMS-specific articles — ePLKS, eVDR, eCOM, eQuota, Levy, PLKS Card — surfaced at the moment an operator needs them, and cited by the AI.

Live dashboards & reports

Queue health, SLA compliance, FCR and time analysis for the whole floor — a dashboard export instead of a Friday spreadsheet.

▶ Switching to the live portal

Live demo · bestdesk.my

Six stops, four minutes — the production system, on the production domain, with production-shaped data.

1
Sign in

Sign in to the production system on the real domain — no staging, no mockup.

0:20
2
Queue

The operator queue — team views, live counts, and one P1 already flagged by the breach engine.

0:30
3
New ticket — the hero moment

Type one employer name — watch 340,000+ FWCMS records answer in under three seconds and the ticket fill itself.

1:00
4
AI panel

AI Solve on an open ticket — a KB-grounded suggestion that cites its articles, which the operator can accept or reject.

0:50
5
Email cockpit

The Email Tray — an inbound email with its age badge, converted to a ticket in one click, confirmation sent automatically.

0:50
6
Dashboard

The live dashboard — the floor's health in one screen, updating itself.

0:30

What the room should watch for

  • One search field replacing three portals
  • 340,000+ FWCMS records answering in under three seconds
  • The AI suggesting — and the operator deciding
  • An SLA clock that was set by the system, not a spreadsheet

Everything shown is the production system at bestdesk.my with production-shaped data. If the room wants to see anything again, ask — we will happily go back.

▶ Live demo · stop 1 of 7 — show reference-first creation in the portal tab

The form isn't a form. It's a search that fills itself in.

BestDesk new ticket workspace: subject and description filled, classification row, and an intelligence panel listing similar tickets and matched knowledge base articles
New ticket workspace — reference search and requester lookup on the left, classification across the top, and similar tickets plus matched KB articles surfacing on the right as the operator types. (fallback screenshot — drive it live)
  • Operator types an employer name, ROC or application reference — one field
  • Matches against 340,000+ FWCMS records and 43,000+ requesters in under three seconds
  • Requester, module, status, contact and prior ticket history populate themselves
  • Multiple reference records can be linked to one ticket, with a designated primary
  • Ticket numbers are sequence-generated per type: INC-100001, SR-200001, BR-500001
This single screen is where the six minutes goes. Everything else in the system is a consequence of getting this one right.

▶ Live demo · stop 2 of 7 — show ticket detail & the SLA strip in the portal tab

The clock is part of the ticket, not part of a spreadsheet.

BestDesk ticket detail view: properties and linked references on the left, SLA command strip across the top, conversation in the centre, intelligence panel on the right
Ticket detail — properties and linked references left, conversation centre, intelligence panel right. The response / OLA / SLA / FCR strip sits above everything. (fallback screenshot — drive it live)
  • Response · OLA · SLA · Paused · FCR always visible at the top of every ticket
  • Deadlines calculated on working hours, with the Malaysian public-holiday calendar seeded
  • SLA pauses when a ticket is waiting on the customer and resumes on update — paused minutes accumulate and extend the deadline
  • Breach detection and escalation paths are configurable per category and priority
  • Every field change is written to ticket history — who, when, from what, to what
P1 · 30-minute OLA / 4-hour SLA. P2 · 2h / 8h. P3 · 3h / 3 working days. P4 · 5h / 5 working days. All editable in the admin panel without a deployment.

▶ Live demo · stop 3 of 7 — show the Intelligence panel in the portal tab

AI that shows its working — and can be rejected.

BestDesk intelligence panel showing Requester 360, a reference snapshot, similar tickets and matched knowledge base articles alongside the ticket
Intelligence panel — Requester 360, live reference snapshot, ranked similar tickets, and the KB articles the AI is grounded in. (fallback screenshot — drive it live)
  • Classify · category, subcategory, priority and language, with a confidence score
  • Solve · a KB-grounded resolution that cites the article IDs it used
  • Draft · a reply in Bahasa Melayu or English, matched to the requester's language
  • Summarise · a three-line handover summary for long threads
  • Sentiment · flags an angry or urgent requester before it becomes an escalation
Confidence below the threshold means the AI suggests and stops. Every interaction — input, output, model, latency and the operator's accept/reject — is written to the ai_interactions table. The AI is audited like a staff member.

▶ Live demo · stop 4 of 7 — show the email cockpit in the portal tab

The support inbox becomes a queue with a clock on it.

BestDesk email tray showing inbound email drafts with age badges awaiting triage
Email tray — inbound mail polled from the support mailbox, aged, and queued for one-click conversion. (fallback screenshot — drive it live)
  • An IMAP poller pulls the support mailbox on a schedule; the nav rail carries an unread badge
  • Age badges make waiting visible: green < 2h amber 2–8h red ≥ 8h
  • One click converts to INC or SR with the requester matched and the original mail preserved in the thread
  • A confirmation email goes back to the requester automatically, from a configurable template
  • Rejection is a first-class action — five categories, an optional remark, and no auto-reply
Before this, an inbound email took 5–10 minutes of reading and manual ticket creation. Now it is under a minute, and nothing sits in an inbox unowned.

▶ Live demo · stop 5 of 7 — show bulk requests in the portal tab

“Process these fifty workers” is now a ticket, not a thread.

BestDesk bulk request list showing parent bulk tickets with tracked line items
Bulk requests — a parent ticket with tracked line items, each promotable to its own child ticket. (fallback screenshot — drive it live)
  • Each application reference in a batch becomes a tracked line item with its own status
  • Any item can be promoted to a child ticket in one click, inheriting the parent's type
  • A new ticket matching the same employer and module auto-links to the open bulk item
  • SLA applies to the parent; progress is visible as a counter on the ticket
  • A bulk status check hits Bestinet's SST API once for the whole batch instead of once per item
Bulk requests were previously 0% tracked — they existed only in email. This is the single largest governance gap BestDesk closes.

▶ Live demo · stop 6 of 7 — show the admin panel in the portal tab

Changing an SLA takes a minute, not a release.

BestDesk admin panel showing the SLA rules configuration screen
Admin · SLA rules. One of seventeen configuration screens, all editable at runtime. (fallback screenshot — drive it live)
  • Classification tree, SLA and OLA rules, working hours, public holidays, teams, roles
  • Escalation paths, canned responses, email templates, workflow rules, notification rules
  • Email channels, statuses, user types, ticket sources, feature access
  • Zero hardcoded values — a locked project rule since the first session
  • Every admin action is written to the activity log with the old and new value
This is the direct answer to “you can't add a feature the vendor doesn't have.” Bestinet does not wait for anyone's roadmap.

▶ Live demo · stop 7 of 7 — show queue & dashboard in the portal tab

The queue on the left. Friday’s report on the right.

BestDesk ticket queue: compact list with team views sidebar, filters, count badges and a ticket preview panel
The queue — team and personal views with live count badges, filters, and a preview panel. This is where an operator lives all day.
BestDesk supervisor dashboard showing ticket counts by status, priority and team
Supervisor dashboard — queue health by status, priority and team, with a kiosk mode for ops-centre screens. Figures shown are seeded demo data.
SLA compliance by team & category Ticket aging Agent performance First Contact Resolution rate Per-ticket time analysis CSV export Ctrl+K universal search Saved & shared views Light & dark themes Mobile-responsive across every route

The same call, both ways

What actually changes for the person on the phone.

Today — manualWith BestDesk
1 Opens ManageEngine, the FWCMS portal and the MyIMMs checker in three tabs. Searches the employer manually across all three. 3–5 min Types the employer name or application number in one field. Requester and FWCMS records return from 340k+ entries in under three seconds.
2 Copies name, ROC, contact, module and status into the ticket form by hand. Typo and wrong-code risk. 3–4 min Every field populated from the matched record, with prior ticket history attached. Zero re-entry.
3 Picks a category from memory, sets priority by instinct, writes into a blank box. No guidance, no knowledge base. 2–3 min AI suggests category, priority and a KB-grounded note citing the FWCMS procedure. Operator reviews and confirms. Under 30 seconds.
4 Bulk requests handled by email outside the system — no ticket, no SLA, no visibility. A bulk ticket with tracked line items, promotable child tickets, and SLA on the parent. 100% in-system.
5 SLA tracked in a spreadsheet. Breaches discovered after the fact. Deadlines set automatically, working-hours aware, with pause/resume and breach alerts before the deadline.
Ticket creation< 2 minfrom 6–8 minutes
Email to ticket< 60 sfrom 5–10 minutes
Bulk tracked100%from 0%
Weekly reporting< 5 minfrom 2–4 hours
Hidayat · architecture & integration

Five layers. Nothing exotic. Everything owned by Bestinet.

Users &
interfaces
Operators (SD · CC · PS)SupervisorsResolversManagement Desktop browserMobile browserTelegram alerts
Application
React + ViteFastAPI + SQLAlchemyPython 3.13 JWT auth · bcrypt7 roles, enforced per endpointSLA + OLA engine Automation & workflow rulesActivity logIMAP poller
AI
Anthropic Claude Haikuclassifydraft replysummarise sentimentAI Solveconfidence gating every call logged + ratedOllama fallback (local dev)
Knowledge
& retrieval
FWCMS knowledge basekeyword top-4 retrievalbilingual BM / EN canned responsesescalation pathsemail templates no external vector DB
Enterprise data
(FWCMS)
PostgreSQL · 58 tables340k+ reference records43k+ requesters Bestinet SST API — liveMyIMMs status checkIMAP / SMTP channel Phase 10 · full live FWCMS feed
All of this can be demoed live on request Interactive API docs — bestdesk.my/docs 17 admin configuration screens Full commit history on GitHub

Counted from the repository, August 2026

This is a system, not a script.

DB tables58PostgreSQL in production
API endpoints256across 20 routers
Backend services25SLA, AI, email, escalation, bulk…
React components88pages, panels and primitives
Lines of code75.5k37.7k Python · 37.7k JS/JSX
Build sessions35+every one documented

What is live in production today

5 ticket types — INC · SR · INT · ISR · BR 7 roles, enforced per endpoint 17 admin configuration screens SLA + OLA dual clocks Working hours + MY public holidays Pause / resume SLA Ticket merge Collision detection Full ticket history audit Activity log on every admin action FCR auto-computed Per-ticket time analysis Bilingual BM / EN Light + dark themes Mobile-responsive across every route Ctrl+K command palette Saved & shared queue views Telegram escalation alerts

A note on the submitted proposal

The proposal submitted in June said 32 tables and 73 endpoints. Both figures are now out of date — the current repository has 58 tables and 256 endpoints.

We are correcting our own numbers upward, and we can show you where every one of them lives.

Integration · built inside Bestinet, by Bestinet

BestDesk already reads live Bestinet data — not a copy of it.

BestDesk requesters directory, searchable across 43,000 employer and agent records
The requester directory — 43,000+ real employer and agent records, searchable by name, ROC or contact.
  • The live Bestinet SST API was extended in-house to serve BestDesk — ePLKS and VDR/BPA are read live, per reference
  • A bulk status endpoint checks a whole batch in one call instead of one call per item
  • MyIMMs status is checked separately and shown as its own badge
  • The two sources are never merged — an operator must be able to see when they disagree
  • Daily and monthly extracts still back the fuzzy search across all modules
This is what an internal build makes possible: the API and the consumer were extended together, in the same company, in the same week. No vendor ticket. No integration quote.

Answering the first video, directly

The day-two problem is a process failure. So we built a process.

Nobody understands it later

Written decisions

An append-only programme history records every commit, decision and phase — 48 dated entries. A separate locked-decisions register lists what may not be changed without approval, and why.

Silent regressions

A three-tier QA gate

API smoke tests, a Playwright visual suite across light, dark and mobile, and a mobile contact sheet that walks every route. All three must pass before any push.

Code quality drift

CI on every push

GitHub Actions runs a lint pass, an import check and a database initialisation on every commit to main. A colour guard fails the build on any raw hex outside the token file.

Failures you find from customers

Sentry in production

Errors are reported from the live service, and the health endpoint reports the actual deployed commit — so “what is running right now” is never a guess.

Untraceable changes

Audit by default

Every ticket field change writes to ticket history. Every admin action writes to the activity log with old and new values, user and timestamp. Not a feature — a rule.

Bugs that come back

A known-bugs register

Fixed defects are recorded with their root cause and a “do not reintroduce” note. Open items sit in dated bug documents with an owner and a status, indexed from one place.

Answering the second video, directly

The AI is a colleague on probation. Permanently.

Five functions, all live

FunctionWhat it doesTemp
ClassifyCategory, subcategory, priority, language — with a confidence score0.3
SolveKB-grounded resolution guidance, citing the article IDs used0.3
Draft replyA reply in BM or EN, grounded in retrieved KB articles0.7
SummariseA short handover summary of a long conversation thread0.3
SentimentFlags an angry or urgent requester for early attention0.3
CONFIDENCE ≥ 0.7

Fields are pre-filled for the operator to review. Nothing is submitted.

BELOW THRESHOLD

The AI suggests and stops. The operator classifies it themselves.

ALWAYS

A reply to a requester is never sent by the AI. A human presses send. Always.

Every AI call — the prompt, the response, the model, the latency, the KB articles used, the confidence, and the operator's accept or reject — is written to the ai_interactions table. If the AI gets worse, we will see it in the data before a customer does. AI never blocks ticket creation: if the model is slow or down, the ticket is still created.

Measured, not projected

The AI bill for June 2026 was nine ringgit and forty-six sen.

June 2026 · actualRM 9.46USD $2.01 — full month, including development and testing
Input tokens1.25M22 active days
Output tokens153k22 active days
ModelHaiku 4.5$1.00 / M in · $5.00 / M out

Projected from that real baseline

ScaleTickets / dayAI cost / monthPer ticket
Current demo~50RM 7≈ RM 0.005
Phase 1 rollout1,000RM 146≈ RM 0.005
Operational target2,000RM 291≈ RM 0.005
Mid-scale5,000RM 729≈ RM 0.005
Full scale10,000RM 1,457≈ RM 0.005
Keyword retrieval — no vector database cost Batch API available at 50% discount for background calls Prompt caching available for static system prompts Operators choose when to invoke AI — not every ticket uses all five
Azam · the case & the ask

Monthly running cost at 300 operators.

ManageEngine Professional300 technicians · published rate · no AI included
RM 38,070
BestDesk · cloud, 10,000 tickets/dayRender Pro + PostgreSQL + AI at full scale
RM 2,045
BestDesk · Bestinet server, 10,000/dayon-premises · power and maintenance only
RM 1,857
BestDesk · cloud, 2,000 tickets/daythe operational target scale
RM 879
BestDesk todaycurrent demo infrastructure, live right now
RM 33

Sources — ManageEngine Professional Cloud at USD $27/technician/month (published, 2026) × 300 technicians × RM 4.70. BestDesk figures = Render hosting plus measured Anthropic Haiku usage projected to scale. Full workings on the following slide.

Per operator · ManageEngineRM 127per month
Per operator · BestDesk at full scaleRM 6.82per month · cloud, 10,000 tickets/day
Difference95%cheaper — with AI included, not excluded

Everything on this slide is PER YEAR

The yearly maths.

Build cost · one-offRM 0already built and in production
BestDesk running costRM 20k–37kper year — hosting + AI + one maintainer
Licensing it replacesRM 446kper year — ManageEngine, 300 operators

Where the RM 20k–37k a year goes

Cost item · RM per yearA · CloudB · Bestinet server
Hosting / infrastructure7,0564,800
AI (Claude Haiku) — at 2,000 tickets/day3,4923,492
Maintenance — 1 internal developer12,00012,000
Total per year · at 2,000 tickets/day22,54820,292
…and if volume grows 5× to 10,000 tickets/day, only the AI line grows36,54034,284

All figures RM per year · AI line projected from the measured June 2026 bill (previous slide).

What comes back, per year

ManageEngine licensing eliminated
hard, verifiable — published rate × 300 operators
RM 446,000
Operator time recovered
modelled — 300 ops × 30 min/day × 250 days × RM 15/hr
RM 562,500
Payback< 1 month
Every year after~RM 985k net

One month of ManageEngine licensing (RM 38,070) already exceeds BestDesk's entire cost for a full year.

What we would ask about, if we were you

The honest risk register.

RiskImpactLikelihoodWhat we are doing
Key-person dependency HIGHMED The most real risk on this list. Mitigation is already running: the team is now four, the decision history and locked-decisions register are in the repository, and the operating manual is written. A second maintainer is part of the ask.
Scale performance HIGHMED Schema designed for 10,000 tickets/day; 340k reference records already live. Scaling is a hosting plan change, not an architecture rewrite. Load testing before pilot rollout.
FWCMS data freshness HIGHMED ePLKS and VDR already read live from the Bestinet SST API. Remaining modules run on periodic extracts. The admin Data Sources UI for a full live feed is built and waiting on the connection.
Security hardening incomplete HIGHLOW JWT with role enforcement on every endpoint, bcrypt, full activity logging and Sentry are live today. 2FA/OTP, rate limiting and CSP headers are scoped as the next phase and were deliberately deferred until after this submission.
Operator adoption MEDMED Designed by an operations manager alongside the team that uses it. Adoption has natural pull because it is faster than the current process. Pilot with five operators before the wider rollout.
AI model dependency MEDLOW The AI layer sits behind a single service module with a local fallback wired. AI never blocks ticket creation — with the model unavailable, the system keeps working without it.

The timeline if the answer is yes

From “yes” to system of record in four months.

DAY 0

Decision day

Executive sponsor named. Funding and FWCMS data-feed access approved. Nothing needs to be built to start — the system is already live.

Milestone · approval
DAY 1–30

Validation & sign-off

Success KPIs agreed — SLA %, tickets per operator, resolution time, FCR. Five-operator pilot team assigned. Existing ManageEngine ticket data mapped for migration.

Milestone · KPIs locked, pilot team named
DAY 31–60

Production hardening

Security phase ships — 2FA/OTP, rate limiting, CSP headers, audit log viewer. Server upgraded. Load-tested at a 10,000 tickets/day simulation. Email channels connected for all support inboxes. Admin training done.

Milestone · security phase live, server upgraded
DAY 61–90

Full pilot live

All 25 operators live. Supervisor wallboard on the ops-centre screen. First real SLA compliance dataset replaces the spreadsheet estimate. FCR baseline established.

Milestone · first management report NOT built from Excel
MONTH 4+

Scale to system of record

Rollout toward 400 operators. Self-service portal for employers and agents. Live FWCMS API feed replaces periodic extracts. Call-centre trigger opens a ticket as the phone is answered. Reuse assessment for MiFPS and overseas operations.

Milestone · single system of record for Bestinet support

Decision required

We are not asking you to fund a build. We are asking you to adopt one.

Funding

RM 20,000 – 37,000 per year — hosting, AI API and maintenance at 300-operator scale. This replaces roughly RM 446,000 per year in ManageEngine licensing.

People

One additional developer alongside the existing team — this is the mitigation for the key-person risk, and we would rather have it than not.

Access

A formal FWCMS data feed to replace periodic extracts, and support in extending the SST API to the remaining modules.

Timeline

Approval to begin security hardening and the server upgrade: immediate. Full rollout by month four.

Sponsor

An executive sponsor — COO or Head of IT — to authorise the infrastructure upgrade and coordinate operator onboarding across departments.

Our recommendation

Proceed. The risk of building it has already been taken — by us, on our own time, and it worked. What remains is a decision to resource something that is already running.

Three things we are not asking for

  • Not a headcount reduction. BestDesk gives operators time back; it does not remove them.
  • Not a greenfield budget. The build is done and paid for.
  • Not a leap of faith. You watched it run ten minutes ago, and you can log in yourself after this session.

Question & answer · agreed in advance

Four people, four lanes. Nobody answers outside their lane.

Azam Product, operational case, cost, ROI, roadmap, scope, and anything starting with “why did you…”. Default owner when a question has no obvious home.
Hidayat Architecture, database, the SST API, integration paths, security posture, AI reliability and model choice, hosting, scale and performance, code quality and maintenance.
Norizan How the floor actually runs — current process, operator behaviour, training and ramp-up, adoption, shift coverage, what changes on day one.
Iffah Timekeeping and traffic control — repeats unclear questions, redirects to the right person, closes the session.

The five questions you will definitely get

“What if Azam leaves?”
Azam. Team of four, written decision history, operating manual, second developer in the ask — and Azam raised it first on the risk slide.
“Is this secure enough for foreign-worker data?”
Hidayat. JWT + per-endpoint roles + bcrypt + activity log live today; 2FA, rate limiting, CSP are the next phase. Data stays on Bestinet-controlled infrastructure.
“Why not just buy a product?”
Azam. We looked at four. None can be told what ePLKS is, and all of them charge per seat as we go from 25 to 400.
“How do we know the AI is accurate?”
Hidayat. Confidence gating, KB grounding with citations, human approval on everything customer-facing, and an accept/reject rate we measure in the database.
“Will operators actually use it?”
Norizan. It is faster than what they do now — and a five-operator pilot proves it first.

Rules for the four of you

  • One answer per question. Two people answering the same question reads as an unrehearsed team.
  • If you don't know, say so. “We don't have that measured yet — we'd have it after the pilot” is a strong answer. Guessing is not.
  • Never contradict a teammate in the room. Add, don't correct. Sort it out afterwards.
  • Bring it back to the live system. When a question drifts abstract, offer to show it live.
  • Label estimates as estimates — the 6–8 min, the ~72% SLA, the productivity value — before anyone else does.

Team BestDesk · Bestinet AI Builders Challenge 2026

It's not a proposal. It's a login.

Everything in this session is running right now. The screenshots came from production. The demo was production. The numbers came from a real invoice and a real repository.

Systembestdesk.my
StatusLive
OwnerBestinet
AzamHidayatNorizanIffah

Terima kasih.