← All industry field guides

Applied research 07 · Telecom

Operate the service, not the alarm queue.

Networks already automate devices. The next challenge is cross-domain intent: understanding how a radio, transport, core, cloud, IT, or field event affects the service and customer—then closing the loop within policy.

Decision domainNetwork operations, service assurance, care, fraud, and revenue
Evidence surfaceTopology, telemetry, alarms, tickets, probes, usage, billing, and CRM
Control boundaryDiagnose and remediate by policy; high-blast-radius change requires approval

Our point of view

Autonomy is an operating contract.

A self-healing claim is meaningless without stating which domain, service, change class, confidence, blast radius, rollback, and approval policy it covers. We model service intent and dependency across network and business layers, then grant automation progressively.

Detection models find unusual behavior; the service graph identifies impact; causal reasoning tests likely root cause; deterministic policy defines permitted actions; agents coordinate execution and verify recovery.

Design principleEvery closed loop needs a declared intent, measured outcome, maximum blast radius, safe rollback, and a human who can stop it.

These are applied research patterns, not descriptions of completed customer engagements. Operator and regulator sources describe the UAE market direction; they are not Zustis deployments.

Applied research outputs

Three loops from network state to customer outcome.

The work crosses OSS, BSS, cloud, customer, and field operations while preserving change and privacy controls.

01

Cross-domain service assurance

Reason from degraded experience back to probable cause.

This research pattern connects topology, configuration, telemetry, alarms, changes, probes, incidents, and service/customer dependencies so operations could see one causal case instead of correlated noise.

The decision

Observe, reroute, restart, rollback, dispatch, escalate, or wait—and which services and customers need protection?

The evidence

RAN/transport/core/cloud/IT telemetry, alarms, topology, config and change, probes, tickets, inventory, SLA, customer experience, and weather/power.

System behavior

Suppresses symptom storms, ranks causal hypotheses, estimates impact, retrieves runbooks, simulates policy-permitted actions, executes approved steps, and verifies outcome.

Human boundary

High-risk, novel, cross-domain, security, and high-blast-radius changes require NOC/change authority. Failed verification triggers rollback.

02

Proactive customer care

Resolve the service story before asking the customer to repeat it.

The reference design joins experience, network, order, device, billing, contact, and policy context in a multilingual case that explains the issue and the available recovery.

The decision

Inform, troubleshoot, reprovision, reschedule, compensate, protect, or escalate?

The evidence

Consent, product/order, service tests, network experience, device, usage, bill, payments, prior contact, field appointment, outage, and treatment policy.

System behavior

Understands Arabic/English intent, diagnoses against live service state, provides cited bill/policy explanation, proposes eligible action, and records completion.

Human boundary

Disputes, vulnerable customers, material credits, collections, contract change, and uncertain identity route to authorized agents.

03

Fraud & revenue assurance

Investigate the behavior, relationship, and leakage together.

This research pattern links subscriber, SIM/eSIM, device, account, dealer, usage, network event, payment, promotion, roaming, and interconnect evidence in explainable cases.

The decision

Observe, challenge, restrict, investigate, correct charging, recover leakage, or report?

The evidence

CDR/xDR, identity/KYC, SIM-device-account graph, dealer, recharge/payment, roaming/interconnect, rating, offers, provisioning, complaints, and known patterns.

System behavior

Detects behavioral and graph anomalies, quantifies exposure, tests typologies and exclusions, clusters related cases, and prepares a source-linked investigation.

Human boundary

Customer restriction, accusation, reporting, material adjustment, and novel typology decisions remain with fraud, legal, compliance, or revenue owners.

Reference architecture

An intent-led operations fabric.

The architecture separates prediction, causal reasoning, policy, and action so automation can mature without becoming ungovernable.

01 · Observe

Real-time event plane

Streaming telemetry, alarms, configuration, tickets, usage, experience, and business events share quality and time state.

02 · Understand

Service dependency graph

Resource, topology, slice, service, product, customer, location, change, incident, and SLA become connected.

03 · Decide

Causal + policy engine

Anomaly and causal models propose; intent, assurance, security, change, and customer rules constrain.

04 · Close

Verified automation loops

Agents plan, seek approval, execute through controllers, observe result, rollback, and learn from operator disposition.

The line we do not cross.

  • Blast radiusEvery action has a permitted domain, customer/service exposure, rate limit, maintenance context, and rollback.
  • Security separationNetwork credentials, privileged actions, and threat response remain isolated, least-privilege, and human-supervised.
  • Customer fairnessPersonalisation, retention, credit, fraud, and treatment policies are consented, explainable, monitored, and appealable.
  • Verify or revertNo automation loop declares success from command acceptance; service outcome must be observed within a defined window.

Validation by autonomy level

Earn each closed loop.

We evaluate by domain, scenario, action class, and blast radius—never by one global “automation rate.”

  1. 01

    Replay

    Back-test incidents, complaint journeys, fraud cases, and leakage using the exact point-in-time topology and policy.

  2. 02

    Fault-inject

    Test alarm storms, partial telemetry, topology lag, simultaneous change, controller failure, adversarial input, and rollback.

  3. 03

    Advise

    Run recommendations in the NOC or care desktop; measure operator acceptance, missed constraints, time, and outcome.

  4. 04

    Close narrowly

    Automate reversible, low-blast-radius actions first; expand only after sustained outcome and incident evidence.

What earns the right to scale.

Service outcome
Time to detect, understand, restore, and verify improves at the service/customer layer—not only the device layer.
Causal precision
Root-cause ranking reduces noise without hiding simultaneous or unknown failure modes.
Safe automation
Action success, rollback, change collision, blast radius, and unintended effect stay within release gates.
Customer trust
Resolution, repeat contact, complaint, fairness, consent, and explanation quality improve together.

Public sector signals

The UAE is moving toward AI-native networks.

  1. e& and TM Forum autonomous-network blueprint

    Current UAE roadmap toward intent-driven, closed-loop operations with human governance and policy controls.

  2. e& 2025 integrated annual report

    Public context for agentic AI, autonomous network capabilities, customer experience, and lifecycle AI governance.

  3. TDRA UAE Spectrum Outlook 2026–2031

    Regulatory signal for AI-native network management and the infrastructure supporting next-generation services.

  4. UAE TDRA initiatives

    Current consumer, resilience, digital trust, and AI initiatives informing telecom control and customer-protection boundaries.

Continue exploring

Related industry research.

Start with one service intent and the loop that cannot reliably protect it today.