One foundation. Four tiers. No governance upsell.
Every paid tier ships the same enterprise core — Policy-as-code, Zero Trust identity, Service Catalog, Stack Framework, multi-cloud inventory and two automation connectors. Tiers differ by breadth of environment, not by whether you get governance.
Pricing is quoted per environment after a short scoping conversation — cloud footprint, toolchain breadth and deployment model.
The non-negotiable enterprise core
This is the production-grade baseline in every tier at no extra charge. Governance is not a module you buy later.
- Policy-as-code enforcement with approval gating at every execution step
- Immutable audit logging and full execution lineage
- OIDC / SAML SSO with enterprise identity provider federation
- Fine-grained RBAC and just-in-time execution access
- Multi-tenant isolation with hard and soft security boundaries
- Environment segmentation — Dev, Test and Prod as distinct execution contexts
- Unified Service Catalog with versioned, parameterised automation services
- Stack Definition Framework with multi-step dependency sequencing
- Multi-cloud inventory — AWS, Azure, GCP, OCI
- Kubernetes inventory — OpenShift, RKE2 and managed clusters
- BYO automation — Ansible, Terraform and CI/CD ingested as catalog items
- Two automation connectors included in every tier
Choose your scale
All four tiers include the full Foundation Platform. Pick the one that matches your toolchain breadth, cloud footprint and operational complexity.
Starter
Single cloud, single ITSM. Entry-level governed automation for teams beginning a platform engineering programme.
- ✓1 public cloud — AWS, Azure, GCP or OCI
- ✓1 ITSM platform — ServiceNow or Jira
- ✓Multi-cloud inventory — read-only
- ✓Full Foundation Platform
- ✓Service Catalog + Stack Framework
- ✓Policy-as-code enforcement
- ✓Zero Trust identity & JIT access
- ○AI & AIOps module
- ○Kubernetes automation
Growth
Multi-cloud, full ITSM, Kubernetes and tag governance. The recommended entry point for enterprises with an active cloud programme.
- ✓3 public clouds
- ✓ServiceNow + Jira integration
- ✓Kubernetes inventory & automation — EKS, AKS, GKE
- ✓ElasticSearch telemetry integration
- ✓Tag Registry & metadata governance
- ✓Full Foundation Platform
- ✓BYO automation ingestion
- +AI & AIOps module — add-on
Enterprise
All clouds, private and on-prem, full database automation, Vault/KMS and Splunk. Built for regulated multi-cloud enterprises at scale.
- ✓All 4 public clouds + private / on-prem
- ✓Full Kubernetes automation — OpenShift, RKE2, managed K8s
- ✓Database inventory & automation
- ✓HashiCorp Vault & cloud KMS integration
- ✓Splunk observability integration
- ✓Advanced RBAC & multi-tenant isolation
- ✓Full Foundation Platform
- +AI & AIOps module — add-on
Site License
Unrestricted integrations, industry compliance packs, AI included and dedicated advisory. For enterprises operating at global scale.
- ✓Unrestricted integrations — no connector limits
- ✓Compliance packs — PCI-DSS, HIPAA, FedRAMP
- ✓AI & AIOps module included
- ✓Dedicated Technical Advisory Manager
- ✓Private AI deployment for regulated industries
- ✓Custom compliance automation workflows
- ✓Everything in Enterprise
- ✓Mission Critical support included
✓ included + available as add-on ○ not included
Tier comparison
| Capability | Starter | Growth | Enterprise | Site License |
|---|---|---|---|---|
| Public clouds | 1 | 3 | All 4 + private/on-prem | Unrestricted |
| Kubernetes automation | Inventory only | EKS / AKS / GKE | OpenShift, RKE2, managed | Unrestricted |
| ITSM integration | 1 platform | ServiceNow + Jira | ServiceNow + Jira | Unrestricted |
| Database automation | — | — | Included | Included |
| Vault / KMS integration | — | — | Included | Included |
| Observability | — | ElasticSearch | Elastic + Splunk | Unrestricted |
| Tag Registry governance | — | Included | Included | Included |
| AI & AIOps module | — | Add-on | Add-on | Included |
| Compliance packs | — | — | — | PCI-DSS, HIPAA, FedRAMP |
| Private AI deployment | — | — | — | Included |
| Dedicated advisory | — | — | — | Technical Advisory Manager |
Built by us. Delivered by us.
The engineers who wrote the connector framework write your connector. No partner hand-off, no gap between what was scoped and what gets built. Standalone engagements or multi-phase programmes, scoped to your environment.
Foundation Onboarding
Platform deployment and configuration so your environment is production-ready from day one.
- Platform deployment and infrastructure configuration
- Enterprise IdP and SSO integration
- RBAC design and role hierarchy mapping
- Initial Service Catalog build and template publishing
- Automation connector configuration and validation
Automation Library Migration
Move an existing automation estate into the governed catalog — at scale, without a rewrite. Hundreds of playbooks, modules and pipelines rationalised, deduplicated and published as versioned catalog items.
- Discovery and inventory of the existing estate across repos, runners and shared drives
- Deduplication and rationalisation — the four playbooks that do the same thing become one
- Parameterisation and input validation for every migrated artifact
- Ansible, Terraform, PowerShell, Bash and CI pipeline ingestion
- Execution boundary and policy attachment applied at ingestion
- Cutover plan and parallel-run validation before the old path is retired
Custom Integration Engineering
Connectors for the systems that make your environment yours. If it has an API, an agent or a database, it can become a governed catalog target.
- Custom connector development against the platform integration SDK
- Legacy and in-house system integration — mainframe, proprietary ITSM, internal CMDBs
- Inventory schema extension for resource types unique to your estate
- Bi-directional sync design with conflict and reconciliation handling
- Connector test harness, versioning and upgrade path
- Handover documentation so your team can maintain or extend it
Complex Automation Development
Multi-system, stateful workflows that no single engine handles cleanly — the ones currently living in a runbook nobody wants to own.
- Multi-engine Stack authoring with dependency sequencing and conditional branching
- Long-running and stateful workflows with checkpointing and safe resume
- Cross-system orchestration spanning cloud, Kubernetes, database and network tiers
- Failure-path and compensating-action design — what happens at step 7 of 9
- Approval topology and policy gate design for high-blast-radius operations
- Load and failure testing before production promotion
Custom Agent Development
Purpose-built agents for your domain, operating inside the same policy boundary as everything else.
- Domain-specific agent design — your runbooks, your terminology, your escalation rules
- MCP server development exposing your internal systems as agent-callable tools
- RAG corpus construction from your architecture docs, runbooks and post-incident reviews
- LangGraph workflow authoring for multi-step reasoning and tool use
- Model selection and tuning — Claude, Bedrock, OpenAI, watsonx or a private model
- Agent evaluation harness with regression tests against known scenarios
AI & AIOps Enablement
Operationalise the agentic layer — telemetry normalisation through agent configuration and diagnostic playbooks.
- Telemetry normalisation and AI data lake configuration
- Diagnostic playbook development and catalog publishing
- Elastic, Splunk and Datadog observability pipeline integration
- Agent tuning for RCA, anomaly detection and NLQ workflows
- Agentic workflow design for SRE and operations use cases
Compliance Sprint
Configure and validate against regulated-industry frameworks, cutting audit preparation and manual evidence gathering.
- CIS benchmark automation and configuration validation
- CNAPP posture workflow development and catalog delivery
- FedRAMP, HIPAA and PCI-DSS pack configuration
- Evidence collection automation for audit readiness
- Continuous compliance validation pipeline setup
Managed Platform Operations
Ongoing operation of the control plane, for teams who want the capability without the headcount.
- Platform upgrades, patching and connector maintenance
- Catalog curation and template lifecycle management
- Policy pack maintenance as your compliance obligations change
- Quarterly automation health and cost governance review
- Named technical contact and escalation path
Who this is built for
Primary — regulated enterprise
Financial services, healthcare, government and energy. Typically 3+ cloud accounts, 5+ Kubernetes clusters, 50+ database instances, with live compliance obligations.
Secondary — mid-market modernisation
Organisations accelerating cloud transformation, rationalising fragmented automation toolchains, or consolidating infrastructure estates post-M&A.
Deployment model fit
Customer-managed for air-gapped or sovereign environments. SaaS for teams minimising operational overhead. Hybrid for an isolated data plane with a managed control plane.
Tell us your footprint. We will tell you the tier.
Cloud accounts, Kubernetes clusters, ITSM platform and deployment preference is enough for a tier recommendation and services scope — back to you within one business day.
30 minutes · tailored to your stack · no slideware