Current-state intelligence for MSPs

Clear the fog.
See the whole picture.

cfg continuously maintains a high-fidelity picture of every managed device and Microsoft 365 tenant, and keeps each one in the state you declared. See what you need without drilling through portals, ask the whole fleet a question and get a live answer in seconds, investigate complex issues at machine speed, and turn proven answers into automation that lasts.

AGPL-3.0Open source and self-hostable
Zero trustMutual TLS and signed modules
MSP-nativeRecursive multi-tenancy
Cross-platformWindows, Linux, macOS, and Microsoft 365
Current state / Fleet + Live Activity

A current answer, not another place to look.

Most IT tools tell you something happened, show you a snapshot, or make you run scripts or log into a remote system before you can trust the answer. cfg keeps the operational context current, then gives you a live path to verify what is missing.

●
Correct by designDesired state continuously converges managed conditions on what should be true.
●
Current by defaultContinual system-DNA reporting gives the controller a current operational picture without a round-trip query.
●
Live across the fleetAsk every endpoint a question and get the answer in seconds. Which machines still run the vulnerable version? Verify a blind spot, collect deeper evidence, or answer the question your tools cannot. Then act on the answer at the same speed.
cfg fleet list with the dc-01 asset drawer open to live CPU, memory, disk, network, process, and service activity cfg fleet list with the dc-01 asset drawer open to live CPU, memory, disk, network, process, and service activity
cfg Fleet + Live ActivitySee · every client · every endpoint
Investigate / Investigation Workspace

Investigate the full picture at machine speed.

cfg connects current system state, recent changes, dependencies, desired state, and live endpoint evidence around the problem being described. Its AI-enhanced investigation workspace can form and test hypotheses as the case develops, surfacing the likely path to resolution and ruling out dead ends before a technician has to chase them across portals.

●
Evidence, already connectedCurrent state, configuration drift, live signals, tickets, and topology converge around the affected entity.
●
Test the path, not just the alertCorrelate onset with recent changes, dependencies, and live evidence to prove or disprove a hypothesis.
●
A safe next actionStage a validated, scoped, and reversible remediation with approval built in.
cfg Investigation Workspace showing a sql-primary case with desired-versus-actual drift, dependency blast radius, change timeline, and staged remediation cfg Investigation Workspace showing a sql-primary case with desired-versus-actual drift, dependency blast radius, change timeline, and staged remediation
cfg Investigation WorkspaceInvestigate · full picture → answer
cfg Workflow Studio editing canvas with triggers, inputs, connected workflow steps, live run progress, and YAML cfg Workflow Studio editing canvas with triggers, inputs, connected workflow steps, live run progress, and YAML
cfg Workflow StudioAutomate · complete processes across systems
Automate / Workflow Studio

Automate work across every tool.

Your most valuable technical processes rarely stay inside one system. cfg turns documented work into safe, reusable workflows that coordinate endpoints, identity, cloud services, infrastructure, ticketing, and the tools your team already relies on. Problem resolution is one use case; end-to-end onboarding, access changes, client setup, and the complex processes your team repeats are others.

●
Model the whole processStart from an event, schedule, request, or operator intent; capture the steps and decisions your team already knows.
●
Coordinate every system involvedCreate an on-premises AD user, provision Microsoft 365, purchase a CSP license, and apply memberships in one controlled onboarding workflow.
●
Make complex work repeatableUse RBAC, step-up authorization, approvals, and complete audit history to run critical work with confidence.
Converge / Desired state

Recurring problems disappear.

Define the correct state. cfg continuously eliminates drift and self-heals known conditions before they become tickets. Alerts are reserved for exceptions it cannot safely resolve.

01

Define correct

Declare the configuration, policy, or condition that should be true and inherit it through the tenant tree.

02

Converge continuously

cfg detects and corrects drift idempotently, using the same current context that makes the condition understandable.

03

Escalate true exceptions

A device drifts, a user is added, a certificate nears expiry: cfg runs the response you declared, on its own. Only when a condition cannot be safely corrected does it send the technician evidence and a scoped path to resolution instead of another unexplained alert.

The foundation behind every answer

Current state, built for operations.

cfg joins the capabilities that usually live in separate tools around the real entities your team manages.

Desired state

Correct by design

Define configuration as code, inherit it through the tenant tree, detect drift, and converge endpoints without losing where each value came from.

System DNA and the knowledge graph

Current by default

Every managed object has a DNA record: its exact state, with provenance and history. The knowledge graph links those records: which server an application depends on, which policy set a key, what changed last Tuesday. Together they turn reported state into an operational model built for impact and root-cause analysis.

Experience

See the human impact

Understand whether a person’s device or application experience is degraded, what changed, and which underlying dependency is responsible.

Reactions

Respond before the ticket

Declare what should happen when something changes. When a device drifts, an account appears, or a certificate nears expiry, cfg runs the response you defined and records what it did.

Workflow

Turn answers into action

Connect APIs, endpoints, directories, cloud services, infrastructure, and the systems your team already uses. Build reusable workflows triggered by evidence, schedules, or operator intent.

MSP operations

Built for the way MSPs work

Model MSPs, clients, groups, and devices at any depth. Inherit configuration and enforce tenant-aware authorization at every level.

Security

Bound the blast radius

Mutual TLS, signed modules, encrypted secrets, continuous authorization, and durable audit trails are foundational, not premium add-ons.

Distributed by design

Central intelligence. Local execution.

cfg separates orchestration from endpoint execution and future network-local discovery, keeping every boundary explicit and authenticated.

Control plane

Controller

Configuration, orchestration, workflows, entity history, APIs, and multi-tenant fleet operations.

Endpoint

Steward

A cross-platform agent that observes local reality, enforces desired state, and executes signed work.

Planned

Outpost

A network-local proxy, discovery point, and agentless bridge for infrastructure that cannot host a Steward.

gRPC over QUIC · mutual TLS · tenant-aware authorization
What is taking shape now

The foundations are becoming a product.

The active roadmap is turning deep architecture into direct operator experiences.

Explore the product roadmap →
Live remote shellEntity query APITemporal DNA syncWorkflow canvasPasskey-first accessFleet operations
Open source. Built in public.

Own the control plane.
Understand everything.

cfg is AGPL-3.0, self-hostable, and designed for operators who believe their infrastructure intelligence should belong to them.