Automated network discovery & sensing
Scout continuously scans your subnets using ICMP, ARP, and SNMP to detect active
hosts, infer device types, and populate your IP twin without manual entry. Run it
on a schedule or trigger it on-demand after a provisioning event.
When to use
Day-one onboarding, post-change verification, or any time your twin might lag
behind your real network state.
Read the guide → Vendor data translation & migration
The Polyglot reads exports from Infoblox, BlueCat, phpIPAM, and a growing list
of DDI vendors, then maps every object - prefix, address, DNS zone, DHCP scope -
to the open-standards schema OmniTwin uses internally. No custom scripts needed.
When to use
Migrating from a legacy platform, consolidating data from multiple sources,
or bootstrapping a new twin from an existing export.
Read the guide → Auto drift detection
Truth Seeker continuously compares the state recorded in your twin against what
Scout observes on the live network. When they diverge - a stale record, an
undocumented host, a changed assignment - it flags the drift and its severity.
When to use
Enable it continuously on any environment where unauthorized or undocumented
changes are a compliance or operational risk.
Read the guide → Pre-flight simulation
Before any change touches the network, The Safety Net runs it against a simulation
of your twin - checking for conflicts, overlap, scope exhaustion, and zone
delegation issues. Changes that fail simulation are blocked from reaching production.
When to use
Any planned change to DNS zones, DHCP scopes, or IP allocations - especially
in environments with change approval workflows.
Read the guide → Auto-planning for network changes
The Architect takes stated intent - "I need a /24 for the new data center pod,
routable from the management VLAN" - and proposes an allocation plan: subnets,
VLAN IDs, DNS zones, DHCP scope boundaries. It works within your existing topology
and policy constraints.
When to use
New site buildouts, data center expansions, cloud VPC designs, or any
greenfield addressing work where manual planning is slow and error-prone.
Read the guide → Full closed-loop automation
Once a change is planned (by The Architect or by a human), The Hands stages the
execution. The Closer finalizes it - pushing approved changes end-to-end across
DNS, DHCP, and IPAM with full audit trail and rollback capability if something
goes wrong post-apply.
When to use
High-velocity environments where human-in-the-loop execution is the bottleneck,
and where a full audit trail and rollback capability are non-negotiable.
Read the guide → DNS / DHCP telemetry & anomaly detection
The Signal continuously parses DNS query volume spikes, DHCP pool exhaustion rates,
and rogue DHCP server behaviour across your graph. IPAM shows you static subnets.
The Signal watches the dynamic, live DDI traffic moving through them in real time.
When to use
Triggered when a DHCP scope reaches 85% capacity, or on anomalous DNS tunneling
behaviour. Use it where dynamic traffic patterns, not static records, are what
actually breaks.
Read the guide → DCIM physical layout planning
Rack Master takes a physical hardware manifest (say 12x Dell PowerEdge R760 and 2x
Cisco Nexus 9300) and optimises patch panel wiring, rack unit placement, and power
phase balancing directly in the visual canvas.
When to use
On demand when provisioning new rack space, in place of manual drag-and-drop
DCIM planning.
Read the guide → Compliance & zero-trust governance
The Audit scans the topology graph for orphan IP records, unallocated active ports,
expired TLS certificates on DNS endpoints, and dual-homed devices violating
isolation boundaries.
When to use
As a weekly scheduled audit, or as a pre-compliance check ahead of SOC 2 or
ISO 27001 review. Orphan addresses sitting open on public-facing subnets are
exactly what gets flagged.
Read the guide →