Inventory you can trust
Every vendor pull lands in one normalized fleet model: serial, brand, source, product type, and lifecycle status, with per-account uniqueness enforced and staleness reconciled. A device shows no site until its network mapping is confirmed through a review journey, because a guessed site assignment is worse than an honest blank. The add-integration wizard renders each vendor's credential form from the plugin's own schema.
Standards and vulnerabilities, scored deterministically
The compliance engine evaluates Wi-Fi standardization and vulnerability posture against policies scoped to an organization, a label, or a site. Results are pass, fail, or not-applicable per resource, with drill-down and on-demand re-runs. Vulnerability data comes from CISA KEV and incremental NVD ingest, matched with real CPE 2.3 version-range parsing; every finding records whether it matched by CPE or heuristic.
Scores that survive scrutiny
Composite health folds four dimensions: health, compliance, vulnerability, and lifecycle, each scored 0 to 100 or honestly absent, weighted by a per-account scoring profile. A missing dimension renders as missing, never as zero. Monthly snapshots give month-over-month trends, and scheduled reports deliver CSV and presentation decks with per-tenant branding.
Visibility and governed remediation
An on-site collector enrolls with signed keys, executes cloud-issued SSH recipes for inventory and config backup, and streams NetFlow, IPFIX, and sFlow into hourly conversation aggregates: top talkers, services, and conversations per site across 24-hour, 7-day, and 30-day windows. Actions carry a declared risk class, permission, and input schema; device-writing steps enter an approval queue before anything runs, execute with idempotency and audit rows, and can be scheduled for maintenance windows.