Define correct
Declare the configuration, policy, or condition that should be true and inherit it through the tenant tree.
cfg continuously maintains a high-fidelity picture of every managed device and Microsoft 365 tenant, and keeps each one in the state you declared. See what you need without drilling through portals, ask the whole fleet a question and get a live answer in seconds, investigate complex issues at machine speed, and turn proven answers into automation that lasts.
Most IT tools tell you something happened, show you a snapshot, or make you run scripts or log into a remote system before you can trust the answer. cfg keeps the operational context current, then gives you a live path to verify what is missing.
cfg connects current system state, recent changes, dependencies, desired state, and live endpoint evidence around the problem being described. Its AI-enhanced investigation workspace can form and test hypotheses as the case develops, surfacing the likely path to resolution and ruling out dead ends before a technician has to chase them across portals.
Your most valuable technical processes rarely stay inside one system. cfg turns documented work into safe, reusable workflows that coordinate endpoints, identity, cloud services, infrastructure, ticketing, and the tools your team already relies on. Problem resolution is one use case; end-to-end onboarding, access changes, client setup, and the complex processes your team repeats are others.
Define the correct state. cfg continuously eliminates drift and self-heals known conditions before they become tickets. Alerts are reserved for exceptions it cannot safely resolve.
Declare the configuration, policy, or condition that should be true and inherit it through the tenant tree.
cfg detects and corrects drift idempotently, using the same current context that makes the condition understandable.
A device drifts, a user is added, a certificate nears expiry: cfg runs the response you declared, on its own. Only when a condition cannot be safely corrected does it send the technician evidence and a scoped path to resolution instead of another unexplained alert.
cfg joins the capabilities that usually live in separate tools around the real entities your team manages.
Define configuration as code, inherit it through the tenant tree, detect drift, and converge endpoints without losing where each value came from.
Every managed object has a DNA record: its exact state, with provenance and history. The knowledge graph links those records: which server an application depends on, which policy set a key, what changed last Tuesday. Together they turn reported state into an operational model built for impact and root-cause analysis.
Understand whether a person’s device or application experience is degraded, what changed, and which underlying dependency is responsible.
Declare what should happen when something changes. When a device drifts, an account appears, or a certificate nears expiry, cfg runs the response you defined and records what it did.
Connect APIs, endpoints, directories, cloud services, infrastructure, and the systems your team already uses. Build reusable workflows triggered by evidence, schedules, or operator intent.
Model MSPs, clients, groups, and devices at any depth. Inherit configuration and enforce tenant-aware authorization at every level.
Mutual TLS, signed modules, encrypted secrets, continuous authorization, and durable audit trails are foundational, not premium add-ons.
cfg separates orchestration from endpoint execution and future network-local discovery, keeping every boundary explicit and authenticated.
Configuration, orchestration, workflows, entity history, APIs, and multi-tenant fleet operations.
A cross-platform agent that observes local reality, enforces desired state, and executes signed work.
A network-local proxy, discovery point, and agentless bridge for infrastructure that cannot host a Steward.
The active roadmap is turning deep architecture into direct operator experiences.
Explore the product roadmap →cfg is AGPL-3.0, self-hostable, and designed for operators who believe their infrastructure intelligence should belong to them.