Cadres IT Operations & Infrastructure
Sheet 02 Rev 2026.08
Start Trial

Sheet 02 — Architecture

Clear ownership. Optional bridges.

Cadres products integrate natively without collapsing into one ambiguous admin surface. Each product is authoritative for its own domain, ships with its own vendor integrations, and works alone. Where two products can help each other, the connection is an explicit, optional bridge over a signed, versioned interface, not a hidden dependency.

Sect. A — System ownership Six units · clean boundaries

Relay owns the machines

Agents, endpoints, patch state, monitoring, alerts and incidents, PAM, discovery, and operational automation, across servers, workstations, and ruggedized devices. Its vendor integrations, Linux, Windows, VMware, SNMP, and network protocols, ship in the unit. When Beacon is present, Relay forwards incidents, changes, and asset state over the ITSM bridge and reads ticket status back; it keeps no ticket mirror of its own.

Beacon owns the tickets

Incident, service request, change, and problem, with SLA policies, journeys, the service catalog, change governance, and the CMDB. Its inventory connectors, Intune, Jamf, Meraki, Mist, Aruba Central, HPE GreenLake, Qualys, Tenable, ship in the unit, as do the Teams and Slack intake channels. When Relay is present, Beacon executes device remediations through it with fixed verbs against per-template allowlists.

Synapse owns the network view

Normalized network inventory, standardization and vulnerability policies, health scoring, and flow analytics. The vendor layer is a plugin ETL bridge, so integrations grow without frontend changes. Device-writing actions run behind approval gates with idempotent, audited execution. When Beacon is present, Synapse raises tickets in it; when Meridian is present, Synapse exports its audit trail as evidence.

Portal owns identity

Authentication, federation, provisioning, identity profiles, IGA, and lifecycle. Its connector catalog, 29 providers across workforce systems and HR sources, ships in the unit. Portal is included as the identity layer with every Cadres product: humans authenticate through Portal OIDC, and directory changes arrive over signed webhooks with a snapshot API for recovery. This is the oldest and most proven handoff in the suite.

Meridian owns evidence

Compliance programs, frameworks, controls, evidence, reporting, internal audit, vendor risk, and auditor collaboration. Its remediation connectors, Jira, GitHub, ServiceNow, ship in the unit. When other Cadres products are present, Meridian collects evidence from the operating record they leave behind, SHA-256 verified, with collection timestamps that cannot be backdated.

Keystone owns the business

CRM, contracts, subscriptions, billing, invoicing, accounting, and finance for the company running the stack. Bank feeds and payment vendor integrations ship in the unit. Keystone is the back office: it does not sit on the operations map, and the other products do not depend on it.

Sect. B — The bridges All optional · all signed

What moves,
when you connect them.

Every bridge is inert until configured, non-blocking when the far side is down, and carried over signed, versioned interfaces.

B-01

Identity, included

Portal establishes the tenant, sign-in model, and governed access path. Every product authenticates through Portal OIDC and receives directory changes over signed webhooks.

B-02

Incidents and asset state, Relay to Beacon

Relay forwards incidents, changes, and asset sync to Beacon or an external ITSM and reads ticket status back. One active ITSM platform per account, enforced at the database.

B-03

Device actions, Beacon through Relay

Beacon executes remediations through Relay with fixed verbs against per-template allowlists, permission-gated, with an honest latency class declared per provider. No free-form scripts over the wire.

B-04

Tickets, Synapse to Beacon

Synapse raises tickets in Beacon through a typed event ingress with per-tenant signing secrets.

B-05

Evidence, everything to Meridian

Operational state, access posture, and audit trails flow into Meridian as verified evidence, drawn from the record the work actually left behind rather than a screenshot layer.

Start where the drag is.

The right starting point is whichever operating system is already creating drag, risk, or manual work: Relay and Beacon for the IT operations core, Synapse when the network needs a standard, Portal and Meridian when access and audit pressure come first. Every path starts with a Portal tenant.

Ops coreRelay + Beacon
InfrastructureRelay + Synapse
Access & auditPortal + Meridian
Back officeKeystone
Start Trial