Home About Labs Projects Contact Email Me ↗
Khaneil Campbell · New York

Enterprise IT support, systems, and automation.

I keep the technology people depend on working — service desk to directory to documentation — and I automate the parts that should never have been manual. Five plus years across two of New York's largest institutions, with the working notes to show for it.

5+
Years Enterprise IT
4
Documented Builds
2
Certifications
NYC
Home Base
Practice

Four things
I get asked for.

The day job spans support, administration, process, and automation. These are the areas where I do the work rather than just know the terminology.

01
Support Operations

Systems and end-user support

Frontline and escalated support for staff in high-demand institutional environments — Windows endpoints, peripherals, access problems, and the long-tail issues that never match a script. Structured triage first, guesswork never.

Environments
Columbia University · NYC Health + Hospitals
Tools
Windows, ServiceNow, remote support tooling
02
Administration

Microsoft 365 and identity

Account lifecycle, group membership, licensing, mailbox and Teams administration, MFA enforcement, and least-privilege access reviews in Active Directory. Every change traceable to a request and a reason.

Platforms
Microsoft 365, Active Directory, Entra-style identity
Practices
Joiner-mover-leaver, MFA, access review
03
Service Management

Process, tickets, and documentation

ITIL 4 practices applied to the ordinary stuff: incident and request handling, queue hygiene, knowledge articles people actually reuse, and handoffs that survive a shift change. Documentation is deliverable, not afterthought.

Framework
ITIL 4 Foundation certified
Output
Runbooks, knowledge base articles, decision records
04
Automation

Scripted and AI-assisted workflows

Python and shell automation for the repetitive work, plus production AI workflows with real guardrails — credential isolation, validation gates, retry logic, and state you can audit after the fact.

Stack
Python, Bash, SQLite, REST APIs
Selected Work

Built, broken,
and written down.

Labs and projects I run outside of work to keep sharp. Each one is documented the way I would hand it to a colleague: what the problem was, what I did, and what the evidence says.

W/01
AI Automation Published

AI product pipeline

An autonomous multi-agent pipeline that researches a brand, writes listings, generates design mockups, and publishes to a marketplace over OAuth — with credential scanning, validation gates, exponential backoff, and SQLite state tracking, deployed on a VPS under systemd.

Stack
Python, CrewAI, Anthropic API, SQLite
Controls
gitleaks pre-commit, .env isolation, OAuth2 PKCE
Outcome
Continuous operation across BUILD / DESIGN / MAINTAIN modes
W/02
Monitoring & Detection Published

Log analysis with Splunk

Windows authentication logs ingested into Splunk, SPL queries written to group failed logons by source and account, thresholds tuned to cut noise, and the whole triage path written up so the next person can repeat it.

Telemetry
Windows Security logs, Event ID 4625
Evidence
80+ failed logons isolated in one window
Deliverable
Reusable triage notes and escalation logic
W/03
Incident Handling Staged

Phishing response walkthrough

A phishing-to-malware scenario worked end to end: user report, host indicator review, containment decisions, and an incident summary written for people who were not in the room.

Telemetry
Host process review, Windows Event Logs
Goal
Timeline from delivery through containment
W/04
Identity & Access Staged

Access control workflows

Access-request, recovery, and MFA scenarios documented with the decision points that matter — who approves, what proves identity, what least privilege actually resolves to, and what gets recorded.

Platforms
Active Directory, MFA policy, privileged access
Goal
Escalation-resistant approval workflows
Method

Same four moves,
every time.

A stuck laptop and a failing automation get the same treatment. It is the reason the write-ups look alike, and the reason the fixes hold.

01

Define

Establish what is actually broken, for whom, since when, and what changed. Reproduce it before touching anything.

02

Investigate

Go to the logs, the directory, the config. Separate signal from noise and write down what the evidence supports.

03

Resolve

Apply the smallest change that fixes the cause, verify it with the user or the data, and note what was ruled out.

04

Document

Leave a record someone else can act on — knowledge article, runbook step, or script — so the next occurrence is shorter.

About

Five years in
rooms that
cannot go down.

I have spent five plus years in enterprise IT at institutions where downtime is not an inconvenience — Columbia University and NYC Health + Hospitals — supporting the infrastructure and the people who rely on it at scale.

My work sits where support, administration, and process meet: keeping endpoints and accounts healthy in Microsoft 365 and Active Directory, running requests and incidents through ITIL 4 practices, and increasingly replacing repetitive work with automation I can audit.

Certified in CompTIA Security+, and ITIL 4 Foundation completed in 2023. The labs and projects here are how I build depth on purpose rather than by accident.

Technology should simplify complexity, strengthen security, and create repeatable outcomes.

Focus
Enterprise IT & automation
Experience
5+ years
Location
New York, NY
Credentials
Security+ · ITIL 4
Credentials

Certified,
and dated.

ITIL 4 Foundation in April 2023, CompTIA Security+ in May 2025. Each has its own page with the credential details.

C/01
CompTIA Valid to 2028

Security+

Baseline security competency across threat analysis, architecture, network security, identity management, operations, governance, and risk.

Certified
May 12, 2025
Candidate ID
COMP001022470377
Valid Until
May 12, 2028
C/02
IT Service Management Renewal lapsed

ITIL 4 Foundation

Service value chain, the four dimensions model, guiding principles, and continual improvement practices as applied in enterprise IT.

Certified
April 23, 2023
Credential ID
GR671511333KC
Renew By
April 23, 2026 — not renewed
Next

Got a system that needs a hand?