{{ pageTitle }}

{{ pageSub }}
Mode {{ mode }}
{{ criticalCount }} critical · {{ bannerMsg }}
Manage inventory {{ mgCount }} items
Enterprise mode — this inventory is synced read-only from NetBox. Edit at the source; changes flow back on next sync. Edit in NetBox {{ mgNetbox }}
Name{{ mgColLabels.1 }}{{ mgColLabels.2 }}Actions
{{ r.name }}decommissioned{{ r.aiTag }}
{{ r.c1 }} {{ r.c2 }}
read-only
Layout for {{ overviewPresetName }} — drag order & hide widgets
Hidden widgets:
{{ w.label }}
{{ k.label }}
{{ k.value }}
{{ k.sub }}
Global status by site
24 sites · 5 regions
{{ s.code }}
{{ s.city }}
{{ s.note }}
Capacity — primary DC (LON1)
{{ c.label }}{{ c.value }}
{{ c.sub }}
Upstream / BGP
Detail →
{{ b.isp }}
{{ b.asn }} · {{ b.type }}
{{ b.state }}
Facilities
{{ f.label }}
{{ f.sub }}
{{ f.value }}
{{ healthPct }}%
healthy
Fleet health
{{ fleetUp }} operational
{{ fleetWarn }} degraded
{{ fleetDown }} down
Active incidents by severity
{{ alertCount }} open
● {{ sevC }} critical● {{ sevW }} warning● {{ sevI }} info
Incident activity
last 24h · peak {{ actPeak }}/h
Sites
5 regions · live status
● operational● degraded● outage
Site status
load · 24h
{{ s.code }}
{{ s.city }}
{{ s.load }}
Capacity heat
{{ h.code }}
{{ m.k }}
{{ m.v }}
Transit throughput
{{ thruNow }}
Aggregate edge egress · Lumen + Cogent
Inject fault:
Healthy Isolated Down
{{ faultSummary }}
{{ n.label }}
{{ n.sub }}
{{ n.badge }}
{{ k.label }}
{{ k.value }}
{{ k.sub }}
Switches & port availability
DeviceModelSitePorts (used / free)UplinkStatus
{{ r.name }}{{ r.model }}{{ r.site }}
{{ r.ports }}
{{ r.uplink }}{{ r.status }}
{{ k.label }}
{{ k.value }}
{{ k.sub }}
eBGP / iBGP sessions
PeerISPASNTypePrefixes (rx / tx)UptimeState
{{ r.peer }}{{ r.isp }}{{ r.asn }}{{ r.type }} {{ r.prefixes }}{{ r.uptime }} {{ r.state }}
{{ k.label }}
{{ k.value }}
{{ k.sub }}
{{ g.name }}
{{ g.ver }}
{{ g.status }}
{{ g.roleLabel }} · {{ g.site }}
CARP {{ g.carp }} {{ g.bgpd }} {{ g.ifaceCount }} ifaces {{ g.jailCount }} jails drift
Open detail
Unknown device detected
{{ unknownMsg }}
Data from{{ p.label }}
{{ k.label }}
{{ k.value }}
{{ k.sub }}
{{ k8sTile.name }}
Kubernetes · {{ k8sTile.nodes }} nodes · {{ k8sTile.namespaces }} namespaces · {{ k8sTile.pods }} pods · {{ k8sTile.site }}
CPU
{{ k8sTile.cpu }}%
Mem
{{ k8sTile.mem }}%
Showing the Kubernetes cluster only — clear the filter to see hypervisors and guests.
{{ s.site }}
{{ hv.id }}
{{ hv.kind }} · {{ hv.extra }}
CPU{{ hv.cpu }}%
Mem{{ hv.mem }}%
{{ hv.guestCount }} guests
{{ g.name }}
{{ g.kind }} · {{ g.os }}
{{ g.customer }}
CPU{{ g.cpu }}%
Data from{{ p.label }}
{{ rk.name }}
RU used{{ rk.ru }}
Sw ports{{ rk.ports }}
Draw{{ rk.power }}
Inlet{{ rk.temp }}
{{ u.name }}
{{ u.model }} · {{ u.site }}
{{ u.status }}
Battery{{ u.battery }}%
Load
{{ u.load }}
Runtime
{{ u.runtime }}
Input
{{ u.input }}
Output
{{ u.output }}
{{ a.name }}
{{ a.model }} · {{ a.site }}
{{ a.status }}
{{ a.temp }}
return air · set {{ a.set }}
Humidity{{ a.humidity }}
Fan{{ a.fan }}
Cool load{{ a.cool }}
{{ g.name }}
{{ g.model }} · {{ g.site }}
{{ g.state }}
Fuel{{ g.fuel }}%
ATS
{{ g.ats }}
Runtime
{{ g.runtime }}
Output
{{ g.output }}
Next test
{{ g.test }}
{{ inc.title }}{{ inc.stateTag }}
{{ inc.countLabel }} · {{ inc.sites }} · {{ inc.protos }}
{{ inc.age }}
{{ c.msg }} {{ c.src }} {{ c.proto }} {{ c.age }}
{{ v.name }}auto-opened
{{ v.caseId }} · {{ v.type }} · {{ v.site }} · opened {{ v.opened }}
{{ v.stateLabel }}{{ v.model }}{{ v.conf }}
No active investigations. Open one from an incident, device or service.
{{ v.name }}
{{ v.caseId }} · {{ v.type }} · {{ v.site }} · closed {{ v.opened }}
{{ v.stateLabel }}{{ v.model }}{{ v.conf }}
No closed cases yet.
Knowledge is promoted from resolved cases. Each article grounds the local model (RAG) and tracks how often it recurred and whether its fix worked. Verified articles need admin sign-off.
{{ a.type }}VerifiedDraft
{{ a.title }}
{{ a.summary }}
seen {{ a.seen }}×{{ a.success }}{{ a.applies }}
{{ a.owner }} · {{ a.updated }} · {{ a.sources }}
{{ invD.name }}
{{ invD.caseId }} · {{ invD.sub }}
{{ invD.model }}
Assembling context bundle · walking blast radius · running local model…
Using remote frontier provider — infra telemetry leaves the network for this step. Local remains the default.
Hypothesis{{ invD.conf }}
{{ invD.hypothesis }}
Seen before · related knowledge
{{ rk.type }}{{ rk.title }}seen {{ rk.seen }}× · {{ rk.success }}
{{ invD.groundedNote }}
Ranked probable causes
{{ c.rank }}{{ c.cause }}{{ c.conf }}
Implicated: {{ c.devices }}
{{ e }}
{{ c.distinguish }}
Suggested next checks · read-only (T0)
{{ ck.label }}
via {{ ck.tool }}
{{ ck.result }}
Proposed remediations
{{ r.tier }}
{{ r.label }}
{{ r.via }}
Blocked (403)
T2+ actions are proposals only — they route through the approval matrix (P4). Every AI-initiated action records the human approver.
Citations{{ ct.label }}
Context bundle
{{ b.title }}
{{ ln.k }}{{ ln.v }}
Tool-call steps
{{ invD.stepBudget }}
{{ st.tool }}{{ st.tier }}
{{ st.det }}
Resolution
{{ invD.resolution }}
Resolved — recorded to audit
Every mutating action — human or AI — flows through one gateway that recomputes its tier from blast-radius × reversibility. T1 confirms inline; T2 needs an admin; T3 needs two distinct admins + a ticket. AI proposes, a human always disposes.
{{ a.tier }} {{ a.label }} AI-proposed {{ a.stateLabel }}
{{ a.target }} · requested by {{ a.requestedBy }} · via {{ a.tool }}
Gateway upgraded {{ a.proposedTier }} → {{ a.tier }} — {{ a.upgradeReason }}
Blast radius:{{ a.blast }}
local-model-suggested — review carefully
{{ e }}
Approved 1 of 2 by {{ a.approver1 }} · ticket {{ a.ticket }}
Approver(s): {{ a.approver1 }} {{ a.approver2 }}
No actions in the queue. Propose a remediation from an investigation, or onboard a device — it lands here for approval.
Per-site change windows. T2/T3 actions outside a window require an explicit “proceed outside window” flag, which is audited.
{{ w.site }}{{ w.window }}{{ w.label }}
Monitoring protocols
{{ i.name }}{{ i.status }}
{{ i.desc }}
{{ i.devices }}{{ i.poll }}
MCP — external tools
ServerTransportExposed toolsStatus
{{ m.name }}{{ m.transport }}{{ m.tools }} {{ m.status }}
{{ preview.sev }} incident {{ preview.age }}
{{ preview.title }}
{{ preview.countLabel }} · {{ preview.sites }}
{{ c.msg }}
{{ c.src }} · {{ c.proto }} · {{ c.age }}
Preferences
{{ user.initials }}
{{ user.name }}
{{ user.roleLabel }}
{{ secTitle }}
{{ secSub }}
Reserved for the initial administrator.
{{ reservedMsg }}
{{ user.initials }}
{{ user.name }}
{{ user.email }}
{{ user.roleLabel }}
Two-factor authentication
TOTP · enabled
Theme
Density
Accent
Preview MI as each role to see exactly what that person can see and do. Changes this session's view only.
Subscribe to all issues or a filtered slice, and choose where each is delivered.
{{ s.name }}
Scope{{ sc }}
Deliver to
Identity sources
{{ p.name }}{{ p.badge }}
{{ p.detail }}
{{ p.status }}
6 members · the initial admin is protected from changes by other admins.
{{ u.initials }}
{{ u.name }}
{{ u.email }} · {{ u.last }}
{{ u.idpLabel }}{{ u.roleTag }}
8 of 24 sites shown · manage locations, timezones and collectors.
{{ s.code }}{{ s.city }}{{ s.note }}
Polling engines and intervals. The AI can tune intervals against collector load.
{{ i.name }}
{{ i.devices }} · {{ i.poll }}
{{ i.status }}
Deployment mode — {{ modeName }}
{{ modeTagline }}
Primary sources
{{ sourcesIntro }}
{{ s.name }}{{ s.mode }}{{ s.tier }}
{{ s.role }} · {{ s.stat }}
{{ s.health }}
sync {{ s.sync }}
Collection protocols
{{ i.name }}{{ i.status }}
{{ i.desc }}
Collector adapters
Vendor differences live in pluggable adapters — adding a vendor is a new adapter, not a new feature. Adapters read now; config-write stays propose-and-handoff.
{{ ad.name }}
{{ ad.dev }}
{{ c.label }}
Configure with AI
Describe your infra & connect sources — the agent drafts a config diff you approve
Local-first. MI defaults to your on-prem model — no infra telemetry leaves the network unless you enable a remote provider.
Proactive investigations
Auto-open a read-only (T0) investigation on unacknowledged high-severity incidents
Model providers
{{ p.name }}{{ p.badge }}
{{ p.model }} · {{ p.ep }}
{{ p.status }}
MCP servers
{{ m.name }}
{{ m.tools }}
{{ m.transport }}
Condition → severity → routing. Rules feed the alert correlation engine.
{{ r.name }}
{{ r.cond }}
{{ r.route }}
{{ c.name }}{{ c.status }}
{{ c.dest }}
Config backup schedule
Retention
Append-only, tamper-evident. Every action attempt — including denied ones — is logged with actor, approver(s), requested-vs-enforced tier and outcome. Filter to reconstruct all attempts touching a device.
{{ a.time }}{{ a.who }}{{ a.tier }}{{ a.action }}{{ a.det }}{{ a.outcome }}by {{ a.approvedBy }}
{{ user.initials }}
{{ user.name }}
{{ user.email }}
Preview as role
MI Assistant
I auto-opened a read-only investigation into {{ aiProactiveMsg }} — ranked causes and citations are ready.
MIMI Assistant
local · llama3.1:70b · MCP
Ask about any device, incident, or BGP session — or have me run an action. Running on your local model.
{{ m.text }}
Tool calls
{{ s.tool }}{{ s.det }}
{{ c.c }}
Suggested action
{{ m.actLabel }}
via {{ m.actTool }}
Read-only role — actions disabled
Thinking · calling tools…
AI configuration agent
Describe your infrastructure — review a diff before anything applies
Runs on your local model. Credentials are stored as secrets and used only to read state — the agent proposes changes as a diff you approve.
Connect sources (optional now)
Reading state · mapping to NetBox / Prometheus / Icinga · drafting config…
The agent proposes these change groups. Untick any you don't want. Nothing is written until you apply.
{{ p.group }}
{{ p.title }}
{{ r.sign }}{{ r.k }}{{ r.v }}
Configuration applied
{{ cfgApprovedCount }} change groups committed and written to the audit log. MIMI is now reading live state from your connected sources.
{{ cfgApprovedCount }} groups selected
Confirm action
{{ pendingLabel }}
Executed via {{ pendingTool }}. This makes a real change to infrastructure and is written to the audit log.
Discover & onboard a device
Discover → identify → profile → correlate → approve. Nothing is written until Apply.
Discovery is trigger-based and uses the least-privilege probe available (ICMP → SNMP → vendor API). It reads only — the local model drafts an onboarding diff you approve.
Try the demo seed 10.0.0.5 — a Juniper MX204 wired to the existing core.
{{ s.label }}
Probing {{ discSeed }} with least-privilege collectors…
{{ discDevName }}
{{ discDevLine }}
Reachability
{{ r.step }}{{ r.result }}
{{ c.msg }}
Onboarding diff
observedinferred (editable)
{{ g.group }}{{ g.title }}
{{ r.sign }}{{ r.k }}{{ r.v }}{{ r.tag }}
{{ discDevName }} onboarded
Collection started at the chosen cadence. It now participates in topology, incident blast-radius and investigations — no special-casing. Logged to audit.
{{ discApprovedCount }} groups selected · observed committed as-is, inferred editable
{{ rackUEd.title }}
{{ rackUEd.faceLabel }} face
Placed at the first free slot; layout changes route through the gateway (T1) and are audited.
{{ mgEditor.title }}
Saving routes through the action gateway — tier-checked and written to the audit log.
Action gateway
Single mutation path · tier recomputed server-side
{{ gwView.tier }}
{{ gwView.label }}
{{ gwView.target }} · via {{ gwView.tool }}
Gateway upgraded {{ gwView.proposedTier }} → {{ gwView.tier }} — {{ gwView.upgradeReason }}. The proposer can’t self-downgrade.
Blast radius:{{ gwView.blast }}
{{ gwView.windowLabel }}
{{ d.line }}
AI proposal · evidence
{{ e }}
Outside {{ gwView.site }}’s change window — proceed anyway?
{{ gwView.approvalNote }} Every attempt — including denials — is written to the audit log.
{{ cmdkCount }} results · Esc
No matches.
Case report
{{ reportData.caseId }} · {{ reportData.title }}
{{ reportData.site }}{{ reportData.sev }}{{ reportData.model }} modelopened {{ reportData.opened }}
Root cause
{{ reportData.hypothesis }}
Timeline
{{ t.tier }}{{ t.tool }}{{ t.det }}
Ranked causes
{{ c.rank }}.{{ c.cause }}{{ c.conf }}
Blast radius
{{ ln.k }}{{ ln.v }}
Resolution
{{ reportData.resolution }}
Related KB: {{ reportData.related }}
Approvals & full audit trail attach from the append-only audit log.
Close with resolution
{{ closeTargetName }}
Promote to knowledge base
Create a draft article (admin verifies later)
{{ t.title }}
{{ t.msg }}