IT AI Cockpit

Nexthink Workspace

Workspace is Nexthink's AI-native environment for IT teams. It replaces the fragmented workflow of opening dashboards, writing NQL in isolation, and manually correlating findings across tools: with a single conversational interface where investigations, insights, and actions all happen together. Ask in plain English, get answers with evidence, and act directly from the same window.

+30%
NQL query accuracy from domain-specific AI fine-tuning
80%
Reduction in AI token usage vs. general-purpose LLMs on NQL
AWS
Fully hosted on AWS: no OpenAI dependency since mid-2025
All IT
One interface for investigations, insights, dashboards & drafts

The IT Team's AI Environment

Workspace started as Nexthink Assist, a natural language query interface that translated plain English questions into NQL and returned results. It has since evolved into something broader: a full agentic environment where the AI can plan multi-step investigations, correlate findings across data sources, surface proactive diagnostic insights, recommend actions, and generate artifacts like dashboards or Engage campaigns,all from a single conversational interface.

Natural Language to NQL

Ask any question about your fleet in plain English. Workspace interprets the intent, constructs the correct NQL investigation, runs it against your live endpoint data, and returns results: often with a chart already built. No NQL expertise required from the person asking.

Proactive AI Insights

Workspace continuously monitors telemetry flowing through the platform and surfaces anomalies, performance degradations, and emerging patterns without being prompted. Findings appear as diagnostic cards: with affected scope, likely cause, and a recommended response.

Agentic Multi-Step Reasoning

Complex questions trigger multi-step workflows: Workspace runs several NQL queries, correlates the results, and synthesizes a narrative explanation. "Why did our DEX score drop last Tuesday?" becomes a reasoned answer with supporting data: not a dashboard to interpret yourself.

Tool Access & Artifact Generation

Workspace has access to multiple tools beyond NQL: it can look up Nexthink documentation, draft Engage campaigns, create or update Live Dashboards, and suggest remediation actions through Flow. One conversation can end with a campaign drafted, a dashboard created, and a Flow workflow triggered.

A Typical Workspace Interaction

Understanding how Workspace processes a question helps practitioners write better prompts and interpret results accurately. The flow below describes what happens from the moment you type a question to the moment you receive an answer.

1

You type a natural language question

You enter a plain English question in the Workspace chat interface: something like "Which devices have had three or more application crashes in the past 7 days?" No NQL syntax. No filter setup. Just the question.

2

Workspace interprets intent and selects tools

The AI parses your question and determines what tools are needed to answer it: NQL investigation, documentation lookup, dashboard generation, Engage campaign draft, or a combination. For most fleet questions, this means building an NQL query against the Nexthink data model.

3

Workspace runs the investigation(s)

The AI executes the NQL query against your live endpoint data. For complex questions, it may run multiple investigations in sequence: first identifying affected devices, then pulling performance metrics for that cohort, then correlating with software events from the same time window.

4

Workspace synthesizes and explains

The AI returns results with a narrative explanation, not just raw data. It identifies what's notable, what the likely cause is, and what the recommended next step is. A complex question gets a structured answer, findings, scope, reasoning, and action,not a table to interpret yourself.

5

You act from within the same interface

If the answer calls for action, sending an Engage survey to affected employees, triggering a Flow remediation, updating a dashboard,Workspace can initiate that directly. The investigation and the response happen in one conversation, without switching tools.

What Workspace handles well

Outbreak investigation Widespread performance drops, crash spikes, connectivity outages across a device cohort: Workspace correlates multi-source telemetry to surface root cause faster than manual investigation.
Fleet compliance checks Patch status, software versions, security policy compliance, OS distribution: quick answers that previously required opening the investigation editor and writing NQL from scratch.
DEX score analysis Understanding why the DEX score changed, which devices or departments drove the shift, and what the largest contributing factors were: Workspace turns a trend into a diagnosis.
Stakeholder briefing prep A DEX program manager can ask "What's the state of employee digital experience this week?" and get a briefing-ready summary, data points, trends, and narrative,ready to share with IT leadership.
Onboarding NQL learners Analysts learning NQL can study the queries Workspace generates and understand the Nexthink data model by seeing how their English questions map to specific NQL constructs. It accelerates the learning curve significantly.

Who Uses Workspace and How

Workspace was designed to make the full analytical depth of the Nexthink platform accessible beyond the small number of people who've mastered NQL. Its practical audience extends well beyond the IT organization: any stakeholder who needs to make decisions based on endpoint data, software usage, or employee experience can ask questions and get answers directly, without routing every query through an IT analyst.

IT Analysts & Engineers
  • Accelerate investigations that previously required NQL expertise
  • Run multi-source correlation without switching tools
  • Use Workspace-generated NQL as a template and refine it manually
  • Trigger Flow remediations or Engage surveys directly from findings
  • Generate dashboards from investigation results
DEX Program Managers
  • Monitor DEX score trends and understand drivers without running NQL
  • Prepare weekly or monthly DEX briefings for IT leadership
  • Investigate experience gaps by department, site, or device cohort
  • Draft Engage surveys targeting specific employee groups based on findings
  • Track progress of DEX improvement initiatives over time
IT Leaders & CISOs
  • Spot-check fleet security posture without waiting for a report
  • Ask "how are we doing this week?" and get a narrative answer
  • Verify patch compliance across the fleet in seconds
  • Understand the DEX impact of a recent change or incident
  • Review AI tool adoption and ROI data in plain language
Product Owners
  • Understand how IT conditions affect employee adoption of a product or service
  • Identify whether low usage correlates with device performance issues, not the product itself
  • Query experience data by cohort to find which groups are underserved by current tooling
  • Validate that a recent release did not degrade the endpoint experience for the target users
Cybersecurity & Compliance
  • Identify devices with outdated OS versions, missing patches, or lapsed AV definitions
  • Spot unauthorized or shadow software installations across the fleet
  • Check encryption and endpoint security policy compliance by department
  • Investigate specific devices or user groups in response to a security alert
  • Produce evidence for audit and compliance reporting without manual data pulls
Procurement & Asset Management
  • Query actual software utilization against licensed seat counts
  • Identify applications installed but unused for 30, 60, or 90 days
  • Surface devices approaching end-of-life for refresh planning
  • Validate hardware inventory data without relying on self-reported asset records
  • Generate data for license rationalization and renewal decisions
VMO & Vendor Management
  • Understand real usage depth for every major software contract before renewal
  • Identify which tools employees use heavily versus tools that were adopted in name only
  • Flag contracts where active usage is well below the licensed seat count
  • Build a usage-based case for renegotiation, consolidation, or non-renewal
  • Correlate tool adoption with employee experience data to evaluate vendor performance
HR & People Analytics
  • Understand how technology experience affects employee satisfaction, productivity, and retention
  • Query digital experience data by department, location, or role to identify underserved groups
  • Correlate onboarding device and software provisioning data with new-hire time-to-productivity
  • Validate whether workplace technology meets the needs of specific employee personas
  • Prepare technology experience data for people analytics reporting and leadership briefings

What to Ask Workspace

Workspace responds best to specific, scoped questions. Vague prompts produce vague answers: the same discipline you'd apply to a junior analyst applies to Workspace. The examples below are organized by category to illustrate the range of questions it handles well.

Incident Investigation

"Which devices had more than 3 application crashes in the past 7 days?"
"Show me all devices experiencing high CPU usage this morning: over 80% average."
"Find devices where Teams call quality dropped significantly in the last 48 hours."
"What changed on devices that started crashing after last Tuesday's patch?"

Compliance & Security

"Which devices haven't applied the latest Windows cumulative update?"
"Show me devices with Windows Defender definitions older than 7 days."
"Find all machines still running Windows 10 and group them by department."
"Which devices have less than 15GB free disk space and are running low?"

DEX Score & Trends

"Why did our DEX score drop between Monday and Thursday last week?"
"Which departments have the lowest DEX scores this month?"
"Compare average logon times by site for the past 30 days."
"What's driving the experience gap between London and New York devices?"

Software & Asset Management

"How many devices have Adobe Acrobat installed but haven't opened it in 90 days?"
"Show me all devices running an unsupported version of Chrome."
"Which Microsoft 365 Copilot licenses are assigned but unused in the past month?"
"List all devices where the VPN client hasn't connected in more than 14 days."
Prompt tips from practitioners: Include a time window ("in the past 7 days"), a threshold ("more than 3 crashes"), and a scope ("by department" or "for the Finance team") whenever you can. Workspace will ask clarifying questions if a prompt is ambiguous, but a well-scoped prompt produces a complete, actionable answer on the first pass.

Insights You Didn't Have to Ask For

Beyond answering questions, Workspace monitors the platform's telemetry continuously and surfaces findings on its own. This is the capability that used to be called AI Insights: it's now integrated directly into the Workspace environment rather than being a separate interface.

What gets surfaced

Workspace watches for patterns that signal an emerging or active problem: unusual spikes in crash events for a specific application version, a drop in connectivity quality correlated with a particular office location, memory pressure building across a device cohort that shares a recent software deployment, or a DEX score trend diverging from baseline without an obvious cause.

When the AI identifies something worth surfacing, it generates a diagnostic card that includes: the affected device scope (how many, which users, which sites), the likely root cause with supporting evidence, a confidence level, and a recommended response. The analyst's role shifts from "find the problem" to "validate and resolve the problem."

In Workspace 2026.4, DEX score change insights were added: automatic explanations of what drove changes in the DEX score over a selected time period, surfaced without requiring a question. When the score moves, Workspace explains why.

What it changes in practice

Before: Dashboard scanning
IT analysts open dashboards hoping to spot anomalies. Most problems surface only after an employee files a ticket: which means most problems are detected after they've already caused disruption.
After: Triage queue
Workspace surfaces findings proactively. Analysts start their day with a queue of prioritized issues to investigate: not a blank dashboard. Problems are detected before tickets are opened.
Maturation note: Proactive insights improve significantly with historical baseline data. A Nexthink deployment with 6+ months of data will surface more accurate findings than a fresh deployment. Plan for a maturation period before relying heavily on proactive insights for operational decisions.

How Workspace Is Built

Understanding what's under the hood matters for organizations with data residency, compliance, or procurement requirements: and for setting accurate expectations about what Workspace can and can't do.

Domain-specific fine-tuning, not general-purpose AI: General-purpose large language models, GPT-4, Claude, Gemini,have broad knowledge of SQL-like query languages but limited knowledge of Nexthink's specific entity model (the relationships between devices, users, applications, events, metrics, and binary entities in the Nexthink data model). Applying a general LLM to NQL translation produces frequent hallucinations: syntactically plausible queries that reference fields or relationships that don't exist. Nexthink's engineering team published that training the AI specifically on the Nexthink data model and NQL syntax produced a 30% accuracy improvement and an 80% reduction in token usage. Domain specificity is what makes this practical rather than a demo.

Runs on AWS: No OpenAI Dependency

As of mid-2025 (version 2025.6), Workspace runs entirely on AWS infrastructure, removing its prior dependency on OpenAI. This simplifies compliance processes, streamlines procurement for regulated industries, and ensures that the AI compute stays within Nexthink's managed environment. Data used for Workspace analysis remains within the customer's regional AWS tenancy.

Agentic Tool Orchestration

Workspace operates as an agentic AI system with access to a defined toolset: NQL investigation execution, Nexthink documentation retrieval, Live Dashboard generation, Engage campaign drafting, and Flow workflow initiation. When answering a question, Workspace selects and sequences tools based on what the question requires: a single query for simple lookups, multi-step orchestration for complex analyses.

Interruptible Responses

Workspace 2026.4 added the ability to stop an in-progress response when it's no longer relevant: without waiting for it to complete. For practitioners running iterative investigations, this significantly reduces the friction of refining a question or adjusting scope mid-session.

Live Data, Not Cached Reports

Workspace queries the live Nexthink data platform: the same data your Live Dashboards and Investigations use. Results reflect the current state of your endpoint fleet, not a periodic export or data warehouse snapshot. This matters for incident response, where a 24-hour data lag makes investigation useless.

What You Need Before Workspace Delivers Full Value

Workspace is included with Nexthink Infinity: there's no separate installation. But what you get out of it is directly proportional to the quality of the data it has to work with and the licensing your tenant is configured with.

High Collector coverage

Workspace queries your live endpoint fleet. If the Collector is only deployed to 60% of devices, Workspace can only see 60% of the picture: and will produce answers that represent that 60% without clearly flagging the gap. Target 95%+ coverage before relying on Workspace for fleet-wide conclusions.

Historical data for baseline

Proactive AI Insights improve significantly with historical baseline data. A deployment with 6+ months of data produces far more accurate and relevant findings than a new deployment with 2 weeks. Trend analysis ("why did this change?") is meaningless without a prior state to compare against.

Clean device taxonomy

Workspace answers questions like "show me by department" or "filter to Finance devices" using the metadata fields populated in Nexthink: department, location, device type, and custom tags. If that taxonomy is incomplete or inconsistent, Workspace's segmented answers will be too. Invest in data quality before relying on segmented insights.

Licensing & role access

Workspace is included in Nexthink Infinity but access to specific capabilities (Proactive AI Insights, DEX score change insights) may require specific license tiers or add-on modules depending on your contract. Verify with your Nexthink representative what's enabled in your tenant before planning a team rollout.

Related Topics

Workspace surfaces findings and generates actions: but those actions run through other parts of the platform. Engage handles employee communication and surveys; Flow executes remediation workflows; NQL is the language underlying all Workspace investigations. Understanding these alongside Workspace gives you the full picture.

Engage Flow NQL Guide Spark & AI

Statistics and technical details on this page are sourced from Nexthink official documentation, engineering publications, and release notes. View full references →