Platform capabilities

Everything Opsore does, explained properly

Twenty documented modules across five capability areas — what each one actually does, how it behaves when things go wrong, and the controls that sit around it. Open any card for the full detail.

Capability areas
5
Documented modules
20
Automation triggers
8
Endpoint platforms
3

01 — Core Platform

The engine the rest of the platform runs on

Assistive AI, one configuration database, service targets that understand your working week, and workflows you change without writing code.

4 modules in this area

TicketsAssetsSLAsWorkflowsONE ENGINE

AUTOMATION ENGINE

AI Incident Triage & Auto-Remediation

Opsore brings a model to every ticket without handing your service desk to one. The assistant proposes; your agents and your rules decide. You choose the provider and supply your own key, and every capability can be switched off independently.

Providers
4, swappable
Capability switches
Per feature
Audit retention
Configurable
What this includes(6 capabilities)
  • Bring your own provider — OpenAI, Groq, Anthropic or Google. An admin tests the connection before the assistant goes live.
  • On a ticket: suggest a category, surface similar past tickets, recommend knowledge articles, draft a resolution, summarise a long thread and read requester sentiment.
  • Recommend the right assignee based on how comparable work was routed and resolved before.
  • Generate root-cause summaries on problems and plain-language risk explanations on changes.
  • A virtual agent chat for end users, with a clean handoff to a human — the conversation becomes a ticket carrying the full transcript.
  • Turn a resolved ticket into a draft knowledge article in one step.
Governance enforcementGovernance is built in, not bolted on: every assistant action can be audit-logged with a configurable retention window (180 days by default), each capability has its own on/off switch, and retrieval is permission-aware — the model is never handed a knowledge article the requester is not allowed to read.

LIVE DEPENDENCY MAP

Unified CMDB & Asset Graph

One configuration database behind incidents, changes, problems and assets — with a typed vocabulary, so the graph stays meaningful as it grows instead of degrading into free text.

Traversal depth
1 – 5 hops
Node ceiling
500 per view
Directions
Up / down / both
What this includes(6 capabilities)
  • A registry of CI classes and a registry of relationship types. Creating an edge with an unregistered type is rejected, with an error that names the screen where you register it.
  • Classes are deactivated, never deleted — configuration items carry their class as a value, so removing one would quietly orphan them.
  • Global defaults plus per-tenant overrides. A tenant never edits a shared default; it writes an override, which is also how it hides a default it does not use.
  • Bounded, seeded traversal: anchor on a CI, pick a direction — upstream, downstream or both — and a depth, and the database walks it in a recursive query rather than shipping the whole estate to the browser.
  • Business services map to the CIs that deliver them, with service maps and saved map layouts.
  • The relationship map, impact analysis and saved business views all share one traversal, so the picture and the count can never disagree.

BUSINESS-HOURS TARGETS

Smart SLA Management

Service targets that count the hours you actually work. Deadlines are computed against a business calendar with an explicit timezone — not against wall-clock time in whatever region the server happens to sit.

Clocks
Response + resolution
Escalation levels
Unlimited, % based
Calendars
Per policy, TZ aware
What this includes(7 capabilities)
  • Separate response and resolution targets per policy, matched to priority.
  • Business calendars carry working-day slots, holidays and a timezone. A four-hour target raised at 4pm on a Friday is due Monday morning, not Saturday.
  • Pause and resume: time a ticket spends on hold is added back to the deadline. A reopened ticket gets a fresh resolution clock.
  • The escalation ladder is configured, not fixed. Levels fire at a percentage of the target — 50%, 75%, 90% — each with its own action: notify the group lead, reassign, bump priority, call a webhook.
  • Priority-changing escalations sit behind their own policy switch, so an escalation can never silently rewrite severity unless you allowed it.
  • OLA policies track the internal team-to-team commitments that sit underneath a customer-facing SLA.
  • Live countdown per ticket with ok, at-risk and breached states, and breach events that other rules can trigger on.

NO-CODE WORKFLOWS

Visual Workflow Builder

Design the states your work moves through and the approvals it has to clear, in configuration. The rules you draw are enforced by the API, not just hidden in the interface.

Workflows
4 entity types
Enforcement
Server-side
Approvals
Multi-stage
What this includes(6 capabilities)
  • Independent status workflows for incidents, service requests, problems and changes — each with its own states and its own transition map.
  • A service request fulfils forward; an incident can be reopened. They share a table and stop sharing a lifecycle.
  • Change carries a full lifecycle including evaluation, approval, qualification, testing, implementation, review — and rolling back and rolled back.
  • Illegal transitions are refused by the server with a conflict response. Editing a workflow propagates within seconds.
  • Multi-stage approval workflows: named approvers per stage, a required number of approvals, automatic escalation to a fallback approver after N hours, delegation, and per-stage conditions on requester, role, department, site or category.
  • Reusable request templates and ITSM templates, plus recurring tickets and recurring changes generated on a schedule.

02 — Operations & ITSM

The service desk, on a bad day and a normal one

Major-incident command, change control that can be audited, monitoring noise turned into work worth doing, and a portal that deflects the rest.

4 modules in this area

RAW ALERTSCORRELATEMAJOR INCIDENTP1 · API Gateway5 tickets grouped · RCA running

INCIDENT MANAGEMENT

Major Incident Triage & Problem Management

When one failure becomes fifty tickets, Opsore gives you a single record to run the response from — and a structured path from the outage to the root cause to the fix.

What this includes(7 capabilities)
  • Declare a major incident, and stand it down when the bridge closes. Both are recorded events, not a status someone remembered to change.
  • A structured war-room record: assigned roles such as incident manager and communications lead, timestamped checkpoints, and stakeholder updates published from one place — including out to the public status page.
  • A post-incident review with its own handoff and completion steps, so the review is a tracked piece of work rather than a promise.
  • Promote an incident into a problem, link every related incident to it, and attach the affected configuration items and business services.
  • Raise a change request directly from the problem record, so the fix is traceable to the cause.
  • Root-cause review, workaround validation and prevention follow-up tasks are separate, reviewable steps.
  • A known-error database: flag a problem as a known error and publish it to the knowledge base automatically, with a review gate and a republish path.

CHANGE MANAGEMENT

Change & Risk Scoring

A risk score anyone can reproduce by hand, approvals that follow from it automatically, freeze windows that respect your timezone, and a CAB outcome nobody can type.

Risk inputs
Impact + urgency + inherent
Approval policies
4
Decision
Derived from votes
What this includes(7 capabilities)
  • The formula is published, not inferred: impact plus urgency plus inherent risk, with a premium added for emergency changes. Nothing is hidden in a black box.
  • Bands map to required approvals. A critical-band change demands more approvers than a normal one, and the thresholds and minimums are yours to set.
  • Risk score is deliberately not priority. Priority comes from its own urgency × impact matrix, so a risky change is not automatically an urgent one.
  • Blackout and freeze windows are evaluated in an explicit timezone, day by day, start-inclusive and end-exclusive, correctly across midnight and across daylight-saving shifts.
  • CAB meetings with a member roster and individually attributable votes. The decision is derived from the votes — the chair cannot type an outcome.
  • Four approval policies: anyone-rejects, majority, unanimous, or a quorum percentage. Quorum is checked before an item can be finalised at all.
  • Standard and recurring changes, a release schedule, and an approval inbox for people who only ever need to say yes or no.

EVENT MANAGEMENT

Event & Alert Correlation

Monitoring tells you something fired. Opsore decides whether that is work. Thousands of daily alerts collapse into a handful of deduplicated, CI-bound incidents.

Native sources
3 + generic webhook
Severity scale
5 levels, normalised
Repeat firings
Counted, not cloned
What this includes(7 capabilities)
  • Native ingest for Prometheus Alertmanager, Zabbix and Datadog, plus a generic webhook for everything else.
  • Severity is normalised across tools, so a Zabbix "disaster", a PagerDuty "page" and a "P1" all land in one scale.
  • Deduplication on a stable key: a repeat firing bumps the occurrence count and last-seen time on the existing alert instead of creating another one — and can escalate its severity.
  • Every alert binds to a configuration item, matched by hostname, IP, name, or the asset the endpoint agent is linked to.
  • A resolved signal from the source closes the alert automatically, with the reason recorded.
  • Every occurrence is appended to an immutable event trail, so the count on the alert is always defensible.
  • Rules decide what becomes an incident. A rule on the event entity raises a deduplicated incident and back-links it to the alert — so one flapping disk is one ticket, not forty.

SELF-SERVICE HUB

Self-Service Request Portal & Knowledge Base

The cheapest ticket is the one nobody raises. The requester portal leads with search and a short list of things people actually ask for, backed by a knowledge base with one visibility rule that every surface obeys.

What this includes(8 capabilities)
  • A requester home with one global search, the handful of primary actions, live counters drawn from real aggregates, and a clear split between what is happening and what is mine.
  • A service catalogue organised by category, with request templates behind each item.
  • One canonical answer to "may this person read this article?" — used by the portal, unified search, PDF export and AI retrieval alike, and it fails closed.
  • Public, internal and restricted articles, with per-grant access for the restricted ones. Internal content is never readable without editorial rights.
  • Scheduled publish and unpublish, swept every minute, so an article goes live at the time you chose without anybody being awake.
  • Article feedback, knowledge analytics and search logging, so you can see what people looked for and did not find.
  • A public status page readable without a login, showing only what an operator chose to publish externally.
  • CSAT surveys delivered by tokenised link — no account needed to answer.

03 — CMDB & Discovery

Find everything, then keep knowing it is still true

Agent and agentless discovery, health scoring that names real gaps, blast-radius analysis before you touch anything, and a full asset lifecycle.

4 modules in this area

SVCAPPAPPDBVMVMNETDiscovery activeDEPTH 3 · BOTH

DISCOVERY ENGINE

Agent & Agentless CMDB Discovery

Two ways in, one database out. Put a lightweight agent on the endpoints you manage, and sweep the rest of the network without installing anything at all.

Agent platforms
Windows / Linux / macOS
Agentless probes
ICMP · SNMP · SSH · vCenter
Scan ceiling
/22, 1024 hosts
What this includes(8 capabilities)
  • The agent is a single static binary for Windows, Linux and macOS, hosted by the operating system service manager. It enrols once with a one-time token and generates its own key pair.
  • It reports inventory as deltas against the last acknowledged baseline, so a quiet machine costs almost nothing to keep current.
  • When the server is unreachable it buffers everything to an encrypted on-disk queue and drains it on reconnect. Nothing is lost, nothing is sent twice.
  • It updates itself from signed releases, verifies them before they ever run, health-checks the new binary and rolls back automatically if it fails.
  • Agentless sweeps: parallel ICMP ping across a subnet, SNMP walks for network gear, an SSH probe that collects OS, CPU, memory, disk, interfaces, installed packages and hardware serials from Linux and Unix hosts, and a VMware vCenter connector for ESXi hosts and virtual machines.
  • Wake-on-LAN for machines that are asleep when the scan runs.
  • Scheduled recurring scans, plus on-demand scans dispatched to a specific agent.
  • Discovery rules decide what happens next: match a discovered device on any field, then promote it to an asset, assign it a site, category or status, or ignore it entirely.

DATA ACCURACY

CMDB Health & Baselines

A configuration database is only worth what its accuracy is worth. Health scores the estate against specific, fixable gaps — and baselines tell you exactly what has moved since you last agreed on the truth.

What this includes(7 capabilities)
  • Health counts what is actually wrong: configuration items with no relationships, no owner, no class, no update in ninety days, and duplicates sharing a name and type.
  • It scores relationships too — edges left behind when both ends went stale or retired.
  • And services: business services with no configuration items behind them, services hanging off a single CI, critical services with no coverage at all, and CIs inside a service that connect to nothing else.
  • Baselines snapshot the estate. Comparison then shows drift field by field — baseline value against current value — with the fields that matter most called out separately.
  • Every drift finding has two honest answers: roll the CI back to its baseline values, or accept the change into the next baseline. Both are recorded decisions with an actor and a reason.
  • Attestation campaigns push configuration items to their owners to confirm, with a per-item record of who attested to what and when.
  • Governed lifecycle transitions, with a preview of the effect before anything commits.

IMPACT ANALYSIS

Dependency & Impact Maps

Before you reboot it, see what else goes with it. Pick a configuration item, choose a direction and a depth, and get the blast radius as a map and as a list.

What this includes(5 capabilities)
  • Impact analysis and the relationship map walk the same bounded traversal, so what you see on the canvas is exactly what the count says.
  • Choose upstream, downstream or both, and how many hops out to go. The graph is capped so a large estate cannot render itself into a hairball.
  • Export the affected set to CSV for a change record or an approval pack. An empty result still produces a valid file with headers, because a zero-byte download reads as a broken export.
  • Saved map layouts, business service maps and network topology views for the pictures you keep coming back to.
  • Cluster configuration items with their member assets, roles and priority — and trigger a failover from the same screen.

ASSET LIFECYCLE

Hardware & Software Asset Inventory

Every asset from purchase order to disposal certificate, on a lifecycle that only moves in directions that make sense — and a record of who moved it and why.

Lifecycle stages
6, gated
Every move
Actor + reason logged
SaaS flagging
Under 50% utilisation
What this includes(8 capabilities)
  • A lifecycle state machine: procurement, deployment, active, maintenance, retired, disposed. Allowed transitions are deliberately narrow, with an admin-only override for data fixes.
  • Every transition is stored with the actor, the reason and a snapshot of the asset at the time.
  • Asset templates, bulk import and export, reservations and transfers between people, sites and departments.
  • Physical estate: racks, data centre layout, IP networks, DNS and domains, certificates, consumables and printer cartridges.
  • Software inventory with licence allocation and compliance position.
  • SaaS entitlements track seats owned against seats used, with rolling snapshots for the trend and automatic flagging of anything under half-utilised as a cost-avoidance candidate.
  • The financial side attached to the same record: procurement, purchase requests, depreciation, leases, warranties and total cost of ownership.
  • Mobile device management, deployment jobs and a field workbench for the people doing the physical work.

04 — Automation & Governance

Work that runs itself, under controls you can show an auditor

Conditional automation on every entity, closed-loop remediation that always offers a dry run, staged patching, and an audit trail that proves it was not edited.

4 modules in this area

TRIGGERticket.createdIFCONDITIONpriority = P1Notify #opsAssign Tier 2EXECUTEDNO-CODE PIPELINE

CONDITIONAL AUTOMATION

Business Rules Engine

If this, then that — across tickets, changes, problems and monitoring events. The engine is deep enough that most of what teams normally script ends up as configuration instead.

Triggers
8
Operators
24+
Actions
19
What this includes(7 capabilities)
  • Eight triggers, not two: on create, on update, on a schedule, on status change, on assignment change, on SLA breach, on approval decision, and on a comment being added.
  • Conditions nest into AND / OR groups, so "VPN or WiFi in the subject, and not already assigned" is one rule rather than four.
  • Operators that cover real routing: contains, starts and ends with, regular expressions — including capture groups you can reuse inside the actions — list membership, emptiness, numeric and date comparison, and CIDR-contains-IP for source addresses.
  • Category is a tree, and the operators know it. "Under Hardware" matches every subcategory beneath it without listing them.
  • Actions cover the whole handling path: set any permitted field, set priority or category, assign a user or a group, round-robin across a group, escalate to a named person, set a due date, recompute priority from the urgency × impact matrix, attach an SLA or OLA policy, notify by channel and recipient role, call an outbound webhook, add a task, add a public or internal follow-up, and stop rule processing.
  • Rules are ranked and evaluated in order, with per-rule stop-on-match, so precedence is explicit rather than emergent.
  • Outbound webhooks are guarded against server-side request forgery and restricted to an allowlist.

PLAYBOOK RUNNER

Automated Remediation Playbooks

Closed-loop remediation with the brakes fitted first. A playbook can raise the incident, open the change, wait for approval, dispatch the fix, verify it worked and close the loop — and you can always see the plan before anything happens.

Run modes
Simulate / dry run / live
Gates
None / admin / CAB
Every run
Fully audited
What this includes(7 capabilities)
  • Three run modes, always available: simulate computes the whole plan with zero side effects, dry run walks it per device without executing, live actually does the work.
  • Steps compose from a fixed set: raise an incident, open a change, hold at an approval gate, dispatch a signed command to endpoints, launch a patch campaign, validate by re-collecting inventory, and close out.
  • Approval gates are graded — none, administrator, or full CAB — and a live run refuses to pass a gate it has not actually cleared.
  • Blast radius is capped per playbook, and rollouts can be ring-staged so a bad fix meets a small population first.
  • Destructive steps — uninstall, script execution, reboot — are gated by construction. Nothing runs autonomously.
  • Steps carry their own inverse action, so a rollback is part of the definition rather than an incident of its own.
  • Two playbooks ship ready to run: remove unauthorised software (incident, change, CAB approval, uninstall, verify the product is gone, close) and deploy a missing critical patch (change, CAB approval, ring-staged campaign, verify the patch is present, close).

PATCH GOVERNANCE

Clusters & Patching

Patch the estate in waves, not all at once. Each device walks its own state machine, and the next wave only starts if the last one actually held.

Rings
Canary ~2% · Early ~8% · Broad ~90%
Wave gating
Soak + failure threshold
Halt
One switch, all devices
What this includes(6 capabilities)
  • A campaign owns ordered waves. Every device in it is an assignment moving through pending, scheduled, dispatched, installing, awaiting reboot, rebooting, verifying, and then succeeded, failed, deferred or rolled back.
  • Three default waves with soak time between them: canary, early, then broad. Wave two waits for wave one to soak and stay under the failure threshold.
  • Ring membership comes from a stable hash of the device identity, so a machine always lands in the same ring and never flaps between heartbeats.
  • Delivery reuses the signed-command channel, results come back through the agent heartbeat, and every state change is kept as deployment history per device.
  • Agent self-updates ride the same rings. Setting the stage to paused halts a rollout everywhere, immediately.
  • Cluster configuration items with member assets, roles and priorities, and a failover trigger for the ones that support it.

SECURITY GOVERNANCE

Audit Log & Reconciliation Queue

An audit trail is only evidence if you can prove it has not been edited. Opsore hashes every entry into a chain and re-verifies the whole thing on a schedule.

What this includes(7 capabilities)
  • Every audit row carries the tenant, the actor — including API clients — the action, the entity and its identifier, the source IP, the user agent, a structured detail payload, and before-and-after snapshots for sensitive operations.
  • Audit writes are deliberately not scoped, so administrative and cross-boundary actions stay visible instead of hiding behind the isolation they used.
  • Any elevation of privilege has to log itself, with the reason it was taken.
  • A verifier re-walks the log daily, recomputes each entry against its stored hash, and reports two distinct failures: altered content, and a broken link between entries. Each finding names the row and shows expected against actual.
  • Findings raise an event, notify every administrator in-app and are cached for the console — and an operator can re-run the walk on demand.
  • The reconciliation queue holds discovered devices that conflict with what is already in the database: assign to an existing asset, link, create a new one, restore, ignore, or merge duplicates — with a configurable policy and reconciliation campaigns.
  • Around it: data-retention sweeps, legal hold, privacy and consent records, separation-of-duties and SOX controls, and dead-letter consoles for email and notification delivery.

05 — Analytics & Financials

What it is costing you, and whether it is getting better

Dashboards built from a typed widget catalogue, forecasting without an external ML service, supplier and contract control, and reports an executive will actually read.

4 modules in this area

Ticket volume · 7dSLA met99%Spend by category

ANALYTICS ENGINE

Analytics v2 & Custom Dashboards

Definition-driven reporting: widgets come from a typed catalogue with validated configuration, and every report — on screen, on a schedule, or embedded — executes through one path, so permissions and caching behave identically everywhere.

Widgets
Typed + extensible
Forecast band
95% confidence
Exports
CSV · XLSX · PDF
What this includes(7 capabilities)
  • A widget registry with schema-checked configuration. Dashboards are assembled from registered widgets, and extensions can register their own.
  • One dispatcher runs every report, whether the browser asked for it, a schedule fired it, or an embedded widget refreshed. Access rules, row filters, tenant scope, caching and audit apply the same way in all three.
  • Every execution writes a run record, so "where did this number come from" has an answer.
  • The KPI engine reads pre-computed snapshots rather than re-aggregating raw fact tables on every page load, and respects business-calendar paused time. Values arrive with their target and a breach flag attached.
  • Forecasting uses double-exponential smoothing with a 95% confidence band, and anomaly detection combines a rolling z-score against a smoothed baseline with change-point candidates — no external ML service, no data leaving the platform.
  • Ask for a chart in English. "Open tickets by priority last 30 days" is parsed into an entity, a metric, a grouping, a time window and a chart type, scored for confidence, previewed, and saved to a dashboard.
  • Export to CSV, XLSX and branded PDF, with tenant logo and brand colour applied.

FINANCIAL OPS

Vendor & Contract Management

Suppliers and contracts as operational records rather than a folder of PDFs — with a renewal queue that reaches you before the auto-renew does.

What this includes(7 capabilities)
  • A vendor register with server-side sorting, filtering and paging, grouping, bulk actions and export, plus a watchlist, an obligation queue and coverage hotspots.
  • Vendor scorecards computed from real transactions: on-time delivery rate, average lead time and defect rate from purchase orders and goods receipts, risk from logged incidents, compliance from certifications, quality from tolerated invoice holds — combined using weights you set.
  • A contract register with renewal and obligation queues. Every summary tile is a filter, because a number nobody can click is a number somebody has to reproduce by hand.
  • The view, filters, page and sort live in the URL, so any state of the screen is a link you can send to a colleague.
  • Clause extraction identifies liability, termination, indemnity, intellectual property, data, service-level, renewal and payment clauses and scores their risk — with a human review step before anything counts as reviewed.
  • SaaS subscription tracking with seat utilisation and over-provisioning flags feeding the same cost picture.
  • A full finance layer around it: invoices, purchase requests, cost centres, general ledger, budgets and variance, tax, multi-currency and FX, bank reconciliation, chargeback, approval chains and an audit trail.

TEAM PERFORMANCE

Agent Metrics & Time Logs

Where the hours went, what they were worth, and who is carrying the load — with the billable question answered at the point the time is logged.

What this includes(4 capabilities)
  • Time entries against tickets, split into billable and internal, costed, and moved through an approval flow with pending, approved and rejected states.
  • Reporting on entries, tickets logged, active agents, total and average minutes, total cost, billable hours and billable amount — every figure drilling through to the tickets behind it.
  • An agent leaderboard over a rolling period, with badges for the things worth recognising.
  • Platform telemetry in Prometheus format on a scrape endpoint, and a live console that parses and renders it every ten seconds — queue depth, patch assignment outcomes, background job health.

EXECUTIVE REPORTING

SLA Dashboards & Service Reports

One set of reports that answers a single question between them: how is each business service actually doing — and the SLA view that tells you which tickets need attention in the next hour.

What this includes(8 capabilities)
  • An SLA dashboard with live time remaining per ticket in ok, at-risk and breached states, broken down by priority, with the attainment trend behind it.
  • Availability achieved against target, per service.
  • SLA attainment by service and by policy — so you can tell a failing service from a badly written policy.
  • What each service costs to run, and service-request fulfilment throughput per catalogue item.
  • Capacity: agent utilisation now and disk forecast ahead.
  • Chat deflection, so the self-service investment has a number attached.
  • Scheduled delivery with generated artifacts, branded PDF for the board pack, CSV and XLSX for the people who will re-cut it anyway.
  • A dashboard builder for role-specific views, so a service owner and a CFO do not have to share one screen.

See it running on your estate

A 30-minute walkthrough against your own use cases — no slides, no obligation.