Skip to content

Directory

Search the whole connector set.

Type a name, an abbreviation or the thing you actually care about: PVU, CAL, FOCUS, SSO, offboarding. Filter by category, or by the CerteroX product that provides the connector.

Product

215 integrations, grouped by category.

  • ITAM
  • SAM
  • SaaS
  • Cloud
  • AI

Cloud & data platforms 9

Billing, usage and resource inventory read from the platform itself, then costed in one model.

  • AWS

    Writes back

    Provided by CerteroX Cloud Management CerteroX ITAM CerteroX AI Management

    Billing, resource inventory and all twenty-six optimisation checks. Also an ITAM cloud discovery source.

    Abandoned Instances, Obsolete Snapshot Chains, Abandoned Kinesis Streams, Reserved Instance opportunities — twenty-six named checks, each with its own thresholds, pool exclusions and account skips.

  • Alibaba Cloud Provided by Cloud

    Writes back

    Billing ingest and resource inventory, in the same cost model as every other provider.

  • Databricks Provided by Cloud , SaaS , AI

    Read-only connector.

    A first-class billing source, and a SaaS subscription with its own seats and last-used dates.

  • Datadog Provided by Cloud , SaaS

    Read-only connector.

    Observability spend as a billing source, and observability seats as a licence position.

  • Google Cloud Provided by Cloud , AI

    Writes back

    Cost Explorer, pool allocation and rightsizing across projects, regions and accounts.

  • Kubernetes Provided by Cloud , AI

    Read-only connector.

    Utilisation by namespace, node and service, with Kubernetes rightsizing as a named check.

  • Microsoft Azure Provided by Cloud , ITAM , AI

    Writes back

    Cost and usage, Azure VM tag-hygiene policy, and the same checks applied to ML executors.

Communication & meetings 12

Chat, meetings and telephony, counted by licence type and by how recently the seat was used.

  • Microsoft 365

    Writes back

    Provided by CerteroX SaaS Management CerteroX SAM

    Vendor-authoritative user and licence lists, and a provisioning and deprovisioning target.

    Mailbox, OneDrive and SharePoint activity land per user behind the one seat, so the licence and the evidence for it are never two records. The offboarding checklist then shows every licence a leaver held, the connector status behind each one, and whether revocation is pending, in progress or complete, with the monthly cost of whatever is still open.

  • Calendly Provided by SaaS

    Read-only connector.

    Free seats told apart from paid ones, with the bookings taken against each licence.

  • Dialpad Provided by SaaS

    Read-only connector.

    Licence tier per user, with the call volume placed on each one sitting behind it.

  • Discord Provided by SaaS

    Read-only connector.

    Which Discord servers the organisation is actually using, and the accounts inside each one.

  • Google Workspace Provided by SaaS , SAM

    Writes back

    Mailbox and Drive activity behind each seat, and deprovisioning that runs to completion.

  • GoTo Provided by SaaS

    Read-only connector.

    Meeting, webinar, support and remote-access seats read apart, because they are licensed apart.

  • Jive Software Provided by SaaS

    Read-only connector.

    Community and intranet accounts by licence type, and the spaces each one still reads.

Identity & directory 14

Who exists, who left, and who still holds a seat. The spine every other connector reconciles against.

  • Microsoft Entra ID

    Writes back

    Provided by CerteroX SaaS Management

    Identity sync including MFA enrolment, and a provisioning and deprovisioning target.

    Users, groups and MFA enrolment arrive in one directory read, and the same connector provisions and deprovisions. That is what SSO coverage gap analysis runs on: which applications sit outside the identity provider, and who is still holding a seat inside them.

  • 1Password Provided by SaaS

    Read-only connector.

    Members, groups and licence state, on the same person record as everything they sign into.

  • Auth0 Provided by SaaS

    Read-only connector.

    Tenant users, the connections they authenticate against, and their roles.

  • AWS IAM Identity Center Provided by SaaS

    Read-only connector.

    Users, groups and account assignments, feeding SSO coverage gap analysis.

  • Bitwarden Provided by SaaS

    Read-only connector.

    Organisation members and groups, with the state of every seat being billed for.

  • Cisco Duo Provided by SaaS

    Read-only connector.

    Enrolled devices and MFA state per person, on the same spine as the other identity providers.

  • Google Workspace Provided by SaaS , SAM

    Writes back

    Directory sync feeding the same user spine as Microsoft Entra ID and Okta.

Documents & work management 20

Files, wikis, boards and signature tools, where a paid seat and a free collaborator are separate positions.

  • Box

    Writes back

    Provided by CerteroX SaaS Management

    Deprovisioning transfers file ownership before it deactivates the account.

    Deprovisioning is not one action. File ownership transfers first, then the account is deactivated, and the offboarding checklist records whether that revocation is pending, in progress or complete — next to the monthly cost of every licence still open behind a leaver.

  • Adobe Acrobat Sign Provided by SaaS

    Read-only connector.

    Seats and agreement-sending activity, with unused signature licences listed ahead of renewal.

  • Aha! Provided by SaaS

    Read-only connector.

    Paid seat types separated from reviewers, with the roadmaps each one actually edits.

  • Airtable Provided by SaaS

    Read-only connector.

    Seat sync with Active Usage Rate, so a quiet licence is visible well before renewal.

  • Asana Provided by SaaS

    Read-only connector.

    Paid members feeding App Rationalization, where tool overlap is ranked by recoverable saving.

  • Basecamp Provided by SaaS

    Read-only connector.

    Account and project membership, with per-user activity behind the subscription.

  • ClickUp Provided by SaaS

    Read-only connector.

    Which workspace members occupy a paid seat, which are guests, and what activity sits under each.

AI & ML compute 8

Model and run tracking, the AI subscriptions people sign up to, and the compute burning underneath both.

  • MLflow

    Reads only

    Provided by CerteroX AI Management

    Task, run and runset tracking with console logs, artifacts, stages and milestones.

    The model registry versions each run, the dataset it trained on is versioned with lineage, and the executor underneath is visible, so the leaderboard entry and the GPU bill behind it are the same record.

  • Anthropic Provided by SaaS , AI

    Read-only connector.

    AI seats and spend, with OAuth grants risk-scored on sensitivity, scope, consent and dormancy.

  • Apache Spark Provided by AI

    Read-only connector.

    Instrumented through the Delight agent collector, down to the executors running the job.

  • Kubeflow Provided by AI

    Read-only connector.

    Pipeline workloads costed as cloud instances, with the full twenty-six checks applied.

  • Nebius Provided by Cloud , AI

    Writes back

    GPU-dense compute costed on the same terms as the hyperscalers, and billed into the same pools.

  • OpenAI Provided by SaaS , AI

    Read-only connector.

    AI seats and spend, ranked on the Shadow AI dashboard by share of the organisation using it.

  • PyTorch Provided by AI

    Read-only connector.

    Training runs tracked with custom metrics, target values and goal tendency.

Sales, service & support 22

Revenue and service platforms, where seat counts grow with headcount and almost never shrink with it.

  • Salesforce

    Reads only

    Provided by CerteroX SaaS Management CerteroX SAM

    The authoritative seat source, with every assignment read from Salesforce itself.

    Sales Cloud, Service Cloud and Platform licences are read as separate positions, each carrying its own last login and feature use. A tier recommendation then holds up in front of the licence owner.

  • Aircall Provided by SaaS

    Read-only connector.

    Numbers, the people holding them, and the calls placed on every licence.

  • Apollo.io Provided by SaaS

    Read-only connector.

    Seats and credit-consuming users, so an unopened licence surfaces before the renewal window.

  • Chorus Provided by SaaS

    Read-only connector.

    Recording licences and the number of calls actually captured on each one.

  • Close Provided by SaaS

    Read-only connector.

    Every user, the role they hold, and how recently they used the seat.

  • Copper Provided by SaaS

    Read-only connector.

    Which users hold a licence, in what role, and how active each one is.

  • DocSend Provided by SaaS

    Read-only connector.

    Members and seat types, with sending activity read alongside the other document tools.

Endpoint & deployment 9

Deployment, management and third-party inventory systems, imported into the schema the agents already write to.

  • Microsoft Configuration Manager

    Writes back

    Provided by CerteroX ITAM CerteroX SAM

    Applications, packages and jobs imported, then driven from the same console that sees them.

    The same console that imports Configuration Manager runs software distribution for MSI, EXE and Click-to-Run, Windows 11 upgrade orchestration, and WSUS-integrated patching with downstream servers.

  • Addigy Provided by SaaS

    Read-only connector.

    Administrative users and licence assignment, alongside the Apple fleet it manages.

  • Apple Business Manager Provided by ITAM

    Read-only connector.

    Zero-touch enrolment inside the iOS and Android mobile device management stack.

  • Ivanti Endpoint Manager Provided by ITAM

    Read-only connector.

    Third-party ITAM import (one of the ten discovery methods), landing in one schema.

  • Jamf Pro Provided by SaaS

    Read-only connector.

    Console users and their licence assignment, next to the Macs each one administers.

  • Kandji Provided by SaaS

    Read-only connector.

    Admin roles and licence state per console account, held on the same person record.

  • Microsoft Intune Provided by ITAM

    Read-only connector.

    Modern-managed devices folded into the one device record the agents already write to.

Marketing & analytics 16

Campaign, survey and analytics tools, where the seat outlives the campaign that justified it.

  • HubSpot

    Writes back

    Provided by CerteroX SaaS Management

    No suspend API exists, so there is a soft mode that strips roles and a hard mode that deletes.

    Deprovisioning here respects what the vendor actually allows rather than what a generic connector assumes. The soft mode strips every role and the hard mode deletes outright, and the offboarding checklist records which one ran and whether it finished.

  • ActiveCampaign Provided by SaaS

    Read-only connector.

    Permission levels and last activity, attributed to the department that is paying for them.

  • Adobe Analytics Provided by SaaS

    Read-only connector.

    Named users and product profiles read from the Admin Console, with last access on each.

  • Adobe Marketo Engage Provided by SaaS

    Read-only connector.

    Workspace access by role, with the campaigns each licence has actually been used to run.

  • Alchemer Provided by SaaS

    Read-only connector.

    Licence type per account user, and the survey activity underneath it.

  • Amplitude Provided by SaaS

    Read-only connector.

    Project access by role, and the dashboards each paid seat is still opening.

  • Constant Contact Provided by SaaS

    Read-only connector.

    Account users and permission levels, each with the date they last signed in.

Engineering & observability 20

Repositories, pipelines and monitoring, read for who holds a seat and for what the build is spending.

  • GitHub

    Reads only

    Provided by CerteroX SaaS Management CerteroX Cloud Management

    Organisation members and seat types, with the repositories and the CI/CD spend on one record.

    Enterprise and Team seats are read as separate positions, each carrying its own last activity, and the same connector attributes Actions spend to a cost pool. A seat and the compute it burns stop being two conversations.

  • AppDynamics Provided by SaaS

    Read-only connector.

    Application reach per licensed seat, held against the role the account actually carries.

  • Astronomer Provided by SaaS

    Read-only connector.

    Who holds a workspace seat, which deployments they can reach, and when they last used it.

  • Azure DevOps Provided by SaaS

    Read-only connector.

    Basic, Stakeholder and Test Plans access levels read as three separate licence positions.

  • Bitbucket Provided by SaaS

    Read-only connector.

    Repository activity per workspace member, against the licence tier they sit on.

  • BugSnag Provided by SaaS

    Read-only connector.

    Members and seat types, with the projects each licensed seat is still active in.

  • Codefresh Provided by SaaS

    Read-only connector.

    Roles per account, with the pipelines actually run under each licence.

People & HR 16

HR, payroll and workforce systems. They carry the joiners and leavers every other licence position depends on.

  • Workday

    Reads only

    Provided by CerteroX SaaS Management

    The joiner, mover and leaver record that the rest of the connector set reconciles against.

    Worker, organisation and employment-status records arrive on the same person spine as the identity providers and the vendor APIs. Every licence a leaver held then lands on one offboarding checklist, with the state of each one and the monthly cost of anything still open.

  • BambooHR Provided by SaaS

    Read-only connector.

    Employee, department and employment-status records: the leaver signal the rest of the list needs.

  • CharlieHR Provided by SaaS

    Read-only connector.

    Team and lifecycle records, feeding the same person spine every seat reconciles against.

  • ChartHop Provided by SaaS

    Read-only connector.

    Headcount, department and reporting-line records, read alongside the licence position for each person.

  • Deputy Provided by SaaS

    Read-only connector.

    Users by location and licence tier, and the rostering done on each.

  • Envoy Provided by SaaS

    Read-only connector.

    Workplace accounts and admin roles, held against the sites each licence actually covers.

  • Factorial Provided by SaaS

    Read-only connector.

    Departures land on the contract record first, and on every application list right after.

Publishers & licensing 10

The publishers with dedicated licence engines, where the entitlement maths is the product.

  • Oracle Database

    Reads only

    Provided by CerteroX SAM

    Options and packs with evidence and override, core factors, licence pools and cover-down.

    Processor types and core factors, licence pools with hosting rights and geographic rules, cover-down logic for Enterprise Edition, uncapped quantity for unlimited agreements. Oracle accepts our measurement data in place of running its own scripts.

  • Adobe Creative Cloud Provided by SAM

    Read-only connector.

    Named-user entitlement with usage evidence over a rolling ninety-day window.

  • IBM ILMT Provided by SAM

    Read-only connector.

    PVU and Virtual Processor Core metrics, compliance gap analysis and Component Resolution.

  • Microsoft 365 Provided by SAM , SaaS

    Read-only connector.

    Subscription entitlement read into the same Microsoft licence position as the servers.

  • Microsoft Exchange Provided by SAM

    Read-only connector.

    Mailbox entitlement evidence behind the Microsoft licence position.

  • Microsoft SQL Server Provided by SAM

    Read-only connector.

    Core and processor licensing with cluster and virtualisation awareness.

  • Microsoft Windows Server Provided by SAM

    Read-only connector.

    Device CALs, user CALs, named user and external connectors, alongside core licensing.

Talent, learning & engagement 11

Hiring, learning and engagement tools, bought per person and renewed long after the last login.

  • 15Five Provided by SaaS

    Read-only connector.

    Every user has a manager, a licence assignment and a last-use date.

  • Bonusly Provided by SaaS

    Read-only connector.

    Participation per member, held next to the licence status of every account.

  • Culture Amp Provided by SaaS

    Read-only connector.

    Account users and access levels, with the surveys each licensed seat has run.

  • Greenhouse Provided by SaaS

    Read-only connector.

    Permission levels and hiring activity per seat, set against the number of seats bought.

  • Harver Provided by SaaS

    Read-only connector.

    Licence assignment per account, and the assessments actually run under each one.

  • Lattice Provided by SaaS

    Read-only connector.

    Reviewers and their managers, each with the licence they hold and the reviews run on it.

Infrastructure & virtualisation 8

Hypervisors and hardware managers, read for inventory and for the host relationships licensing turns on.

  • VMware

    Reads only

    Provided by CerteroX ITAM CerteroX SAM

    Host and guest relationships: what per-core and per-processor licensing actually turns on.

    SQL Server and Windows Server core licensing, Oracle licence pools and IBM sub-capacity PVU are all computed against which guest ran on which host. The connector reads those host and guest relationships directly, so cluster membership and virtualisation are inputs the licence engine already holds.

  • Cisco Meraki Provided by ITAM

    Read-only connector.

    Network device inventory alongside SNMP switch port and routing tables.

  • IBM HMC Provided by ITAM , SAM

    Read-only connector.

    LPAR and frame topology, the basis of IBM sub-capacity PVU calculation.

  • Microsoft Hyper-V Provided by ITAM

    Read-only connector.

    Virtual machine inventory with the cluster and host awareness core licensing needs.

  • Nutanix Provided by ITAM

    Read-only connector.

    Hyperconverged host and guest inventory, in the same schema as everything else.

  • Oracle VM Provided by ITAM , SAM

    Read-only connector.

    Partitioning evidence behind Oracle licence pools, hosting rights and cover-down.

  • oVirt Provided by ITAM

    Read-only connector.

    Guest inventory across the open KVM virtualisation stack, host relationships included.

Design & creative 12

Creative, prototyping and content tools, where an editor seat and a viewer seat are separate licence positions.

  • Adobe Creative Cloud

    Reads only

    Provided by CerteroX SaaS Management CerteroX SAM

    Named-user seats by product, with usage evidence over a rolling ninety-day window behind each one.

    The Admin Console says who holds a licence. The usage evidence says who opened it. Both land on one record, next to every other creative tool the same person is licensed for, and App Rationalization reads that record.

  • Abstract Provided by SaaS

    Read-only connector.

    Version-control seats on a wound-down service: a dead tool still holding accounts is a finding.

  • Canva Provided by SaaS

    Read-only connector.

    Team members separated from paid seats, and the design work each has done.

  • Contentful Provided by SaaS

    Read-only connector.

    Every seat carries a space, a role, and the date the space was last opened.

  • FigJam Provided by SaaS

    Read-only connector.

    A FigJam-only seat carries its own licence, so it is counted on its own.

  • Figma Provided by SaaS

    Read-only connector.

    Editor, developer and viewer seats told apart, so a full seat doing viewer work is visible.

  • Frame.io Provided by SaaS

    Read-only connector.

    Reviewers and collaborators counted apart, with the projects each licence is still working in.

Workflow & delivery 10

Where a finding has to travel before it becomes a change, and how the platform answers other systems.

  • Model Context Protocol

    Reads only

    Provided by CerteroX AI Management

    Every product exposes an MCP server, with scoped tokens and every tool call audited.

    It is an MCP client as well as a server, so an agent working here can reach a system through the MCP server that system already publishes. Tokens are scoped per organisation and every call is audited and quota-tracked, so a security review has something to sign off.

  • Boomi Provided by SaaS

    Read-only connector.

    Platform users and roles, with the integrations each licensed seat still maintains.

  • GitHub Provided by Cloud

    Read-only connector.

    CI/CD cost pools and shareable environments with booking, SSH keys and webhooks.

  • Jenkins Provided by Cloud

    Read-only connector.

    CI/CD attribution, so build spend lands in a named cost pool rather than a shared bill.

  • Jira Provided by Cloud

    Read-only connector.

    A finding becomes a ticket, and the ticket carries the evidence that produced it.

  • Microsoft Power BI Provided by ITAM

    Read-only connector.

    A documented data source over the read-only Certero API, so your BI tool reads it in place.

  • Microsoft Teams Provided by SaaS

    Writes back

    Scheduled reporting-agent delivery into the channel that owns the decision.

Security & compliance 15

Security, vulnerability and awareness tooling: licensed per person, and just as capable of being over-bought as anything else.

  • CrowdStrike

    Reads only

    Provided by CerteroX SaaS Management

    Falcon console accounts, the roles on each, and the modules that licence actually reaches.

    Security tooling is bought per person and reviewed by nobody. Reading the console users, their roles and their last activity puts the security stack on the same licence position as everything else, and on the same offboarding checklist, where an administrator account outliving its owner is the finding that matters.

  • Aikido Security Provided by SaaS

    Read-only connector.

    Workspace members and roles, with the repositories each licensed seat is scanning.

  • Cisco Umbrella Provided by SaaS

    Read-only connector.

    Administrative roles per console account, and the policies each one is able to change.

  • Cloudflare Provided by SaaS

    Read-only connector.

    Account members, roles and Zero Trust seats, attributed to the team that owns the zone.

  • CyberArk Provided by SaaS

    Read-only connector.

    Which users hold which safes, under which licence type, and when they last opened one.

  • F5 BIG-IP Provided by SaaS

    Read-only connector.

    Administrator accounts and their roles, reconciled against the same identity spine.

  • Illumio Provided by SaaS

    Read-only connector.

    Each console seat carries a role, and the workloads behind it are read with it.

Finance & operations 9

Finance, procurement and spend systems, where an approver role outlives the reason it was bought.

  • Bill.com Provided by SaaS

    Read-only connector.

    Users, approval roles and last activity, attributed to the department that holds the budget.

  • Brex Provided by SaaS

    Read-only connector.

    Card roles and last activity, on one record with the software the same person holds.

  • Coupa Provided by SaaS

    Read-only connector.

    Approval roles and last activity, including the seats that have approved nothing in months.

  • Expensify Provided by SaaS

    Read-only connector.

    Members by policy, with the claims submitted behind each seat since it was bought.

  • NetSuite Provided by SaaS

    Read-only connector.

    Full, employee and self-service licence types held apart, each with its own last login.

  • Sage Intacct Provided by SaaS

    Read-only connector.

    Paid licences, the role each one carries, and the date it was last signed into.

A card marked writes back can perform a named action against that system. Every other card in the directory only reads.

How it works

Connectors feed one model,
and the products read it.

A competitor with five acquired products carries five sets of connectors and a reconciliation project between them. We run one set into one model, and every connector in the directory above feeds it.

One asset model

Five disciplines,
one set of records.

One device record
Agent, agentless, network scan and third-party import all land in the same schema.
One user
Directory, identity provider and vendor seat lists reconciled to the same person.
One cost line
FOCUS-native billing across twelve cloud and data platforms, in one cost model.
One licence position
Entitlement, usage and evidence computed continuously, and current on the day an audit letter lands.
One policy engine
The same governance rules over assets, licences, SaaS, cloud and AI.

Answers out 3 surfaces

  • Read-only API

    A documented Certero API with a published Power BI data source. Your BI tool reads our data where it sits.

  • MCP server, on every product

    Scoped per-organisation tokens, with every agent tool call audited and quota-tracked. External MCP plugins let it call out to other servers too.

  • Export and delivery

    Raw billing export to external BI, scheduled email reporting, and reporting agents delivering into Slack and Microsoft Teams.

One integration surface for the whole platform, and these three routes out of it.

The connector itself

What one looks like
once it is configured.

A connector is a small, unglamorous object: an authentication method, a schedule, a scope, a list of what it reads, and a list of named actions.

The interface and the data shown here are illustrative. The reads and all four write actions are CerteroX SaaS Management capabilities.

CerteroX · Connectors — illustrative sample data
Connectors 6 of 215 shown
  • Microsoft 365 SaaSSAM Writes back every 6 h
  • Oracle Database SAM Reads only every 24 h
  • IBM ILMT SAM Reads only every 30 min
  • VMware ITAMSAM Reads only every 12 h
  • AWS CloudITAMAI Writes back every 1 h
  • Entra ID SaaS Writes back every 4 h
Microsoft 365 Connected
Authentication
Application registration, delegated scopes
Schedule
Every 6 hours · last run 04:12
Scope
1 tenant · 1,284 users
Provides
SaaS Management, SAM

Reads

  • Users and licence assignments
  • Subscriptions: purchased, assigned, available, oversubscribed
  • Consented OAuth grants, risk-scored 0–100
  • Last activity per seat, over a rolling 90-day window

Writes 2 of 4 enabled

  • Deprovision user Enabled Offboarding checklist and workflow action
  • Revoke OAuth grant Enabled One click, or as a workflow action
  • Reclaim unused licence Off 30+ days of zero usage
  • Downgrade tier Off One of six licence actions

Every use of a write action lands in the audit log.

Read, act, prove

Read-only by default.

Security teams ask two questions about any integration: what can it see, and what can it change. Both answers are below.

01

It reads

What a connector reads depends on what the system will hand over.

  1. 01.1 Agentless and command-line inventory (csinvcli) for machines that will not take an agent
  2. 01.2 Standalone inventory for air-gapped and offline systems
  3. 01.3 A non-invasive ABAP connector for SAP, reading named users, roles, engines and authorisations
  4. 01.4 Vendor APIs returning the authoritative user and licence list for each application

02

It acts, only where you say so

17 of the 215 connectors can write anything at all.

  1. 02.1 Provisioning and deprovisioning across Entra ID, Okta, Google Workspace and Microsoft 365
  2. 02.2 One-click OAuth grant revocation, also available as a workflow action
  3. 02.3 SCCM applications, packages and jobs driven from the same console that sees them
  4. 02.4 VM power schedules and resource TTL, enforced against the cloud accounts you nominate

03

It leaves a record

Every action a connector performs stays attributable afterwards.

  1. 03.1 Audit log covering every provisioning and deprovisioning step
  2. 03.2 Scoped, per-organisation MCP tokens with full tool-call auditing
  3. 03.3 Constraint violation history and detected-constraints tracking
  4. 03.4 A six-tier role model including a dedicated Auditor role
Oracle LMS/GLAS verified

Verified by Oracle License Management Services. Oracle’s audit team can accept data from Certero during an official audit, as an alternative to installing Oracle’s own measurement tools.

Read the verification
Not on the list?

Then take one of the
four ways round it.

Three of these need nothing from us at all, and the fourth starts with a conversation.

Send the system name and what you need out of it, whether that is inventory, seat lists, billing or a named write action. Where one of the four routes above already covers it, we will point you straight at the documentation for it.

  1. 01 Build it yourself

    The read-only API

    A documented Certero API over the whole asset model, with a published Power BI data source. If your system can read HTTP, it can read everything you own.

  2. 02 Open standard

    FOCUS, natively

    A dedicated collector ingests the FinOps Open Cost and Usage Specification. Any provider that emits FOCUS is costed correctly without a bespoke connector at all.

  3. 03 No API required

    Import and agentless discovery

    Third-party ITAM import, network discovery across NetBIOS, SNMP and ICMP, agentless inventory and standalone inventory for air-gapped systems. Ten discovery methods, and every one of them writes to the same schema.

  4. 04 Agent-to-agent

    External MCP plugins

    The platform is an MCP server, and it is also an MCP client. External MCP plugin support means it can call tools published by your own servers, under the same scoped, audited tokens.

Name one system

Start with your messiest
source of truth.

An AD forest nobody has pruned since 2014, an Oracle environment with options nobody can account for, a Microsoft 365 tenant with more licences than people. Name it, and the demo is built on that connector — what it reads, what it returns, and the record every result lands in.

Nothing to connect, nothing to approve, no gated PDF.