Everything, wrapped around your network

SurroundNet is more than a CMDB. It layers cost, accountability, governance, planning, change, and procurement onto the infrastructure that runs your business — one source of truth, top to bottom.

Who it's for

One network? A network of networks? An MSP?

However your world is shaped, SurroundNet fits it — one organization, a parent overseeing many, or a managed-service practice looking after dozens. One platform, with the boundaries kept clean.

  • One network — a single, isolated environment for your estate.
  • A network of networks — parent organizations with child orgs and multiple instances, rolled up under one roof.
  • Managed service provider — run many customer tenants from a single fleet console.
  • Row-level data isolation keeps every organization strictly separated.
  • Consented managed support — customers grant and revoke your access on their terms.
  • Usage-based metering and billing across the fleet.
Cost of ownership

Total cost of operations and ownership

Know what every asset really costs — to buy, to run, and to replace. SurroundNet ties price, depreciation, and contracts to the assets themselves, so total cost of ownership is a number you can actually see.

  • Every configuration item attributed to a financial account.
  • Replacement cost from catalog MSRP; actual cost from what you last paid.
  • Depreciation calculated from real actuals, not guesses.
  • Contracts, support coverage, and warranties tracked against the assets they cover.
  • CAPEX vs OPEX treatment on the work that builds and maintains assets.
  • Cost rolls up by account, cost centre, project, and portfolio.
Ownership & accountability

Total ownership and accountability

Every asset, service, and decision has a name attached. SurroundNet closes the loop from the person who logs in to the service they own and the approvals they sign.

  • Services mapped to their owners, teams, and contacts.
  • Role-based access control down to page and function level.
  • Approvals recorded with who, when, and on what basis.
  • Full audit trail across changes, approvals, and access.
  • Delegation and alternate approvers for coverage.
  • Accountability from login → person → service → sign-off.
Lifecycle governance

Total process lifecycle governance

The disciplines that keep infrastructure trustworthy — built around the real assets, not bolted-on spreadsheets.

  • SOPs, runbooks, DRPs, and lessons-learned linked to the assets they govern.
  • SLAs with breach tracking and template-driven escalation ladders.
  • Fault and incident management tied to affected infrastructure.
  • Compliance rules and findings surfaced against the estate.
  • Work orders with test results and definition-of-done closure gates.
  • Ownership and stewardship controls on the documents that matter.
Planning & projects

Total planning and project management

Plan the work, fund it, and watch it land — with budgets and portfolios that see all the way down to the invoice line.

  • Budgets → portfolios (nestable) → projects → WBS, in one hierarchy.
  • Committed and actual spend rolled up from real POs and invoices.
  • Project governance: test plans, DRP, lessons-learned, affected users & services.
  • WBS templates so new projects start structured.
  • Health signals — budget vs committed vs actual — at every level.
  • Cascading drill-down from a portfolio to a single receipt.
Change & cost control

Total change management and cost control

Change with confidence. Every change is planned, approved, scheduled, and costed — and the money is controlled before it's spent.

  • Guided change lifecycle with approvals and post-implementation review.
  • Maintenance and outage windows scheduled straight from the change.
  • Change → project → work order → WBS linkage in one thread.
  • Threshold- and role-based approval routing with cascading sign-off.
  • Committed spend checked against budget before it's incurred.
  • An emergency-change path for when speed matters.
Procurement

Total procurement cycle

From purchase order to received asset to paid invoice — the whole cycle, matched and traceable at the line level.

  • Purchase orders with line-level project and WBS attribution.
  • Goods receipt and true three-way match: ordered ↔ received ↔ invoiced.
  • Invoice-line matching with variance flags.
  • SKU and BOM catalog with pricing history.
  • Received serial numbers registered as tracked assets, ready for discovery.
  • Customer AR invoicing and MSP charge-back.
Continuous improvement

Process maturity through continuous feedback and improvement

The platform improves the way your operation should — a closed loop from feedback to backlog to shipped improvement.

  • In-app feedback capture from the people doing the work.
  • A backlog pipeline that turns feedback into planned work.
  • Release notes that record what shipped and why.
  • Feedback → backlog → release, linked end to end.
  • Executive dashboard with KPIs, trends, and drill-down.
  • A measurable maturity loop — not a one-time deployment.
The right deployment

The right deployment

Run SurroundNet where your security posture requires — in the cloud, on your own metal, or fully disconnected.

  • Azure SaaS, on-premises, or fully air-gapped and isolated.
  • Signed, per-CI licensing tied to your organization.
  • Secure by design — Key Vault secrets, managed identity, passwordless data access.
  • White-label and OEM branding for partners.
  • Scales by configuration-item count as your estate grows.
  • Data residency and isolation on your terms.
The source of truth

The source of truth

It all rests on one accurate, living record of everything on your network — discovered automatically and kept current.

  • Complete CI inventory across every device and service class.
  • Built-in network scanning (NativeScan) and SNMP walks — devices, interfaces, and CDP/LLDP topology.
  • Imports from Cisco DNA Center, Prime, and SolarWinds, merged safely with what's already known.
  • A lightweight connector for segmented, remote, or customer networks.
  • Endpoint-on-port and wireless-client mapping — know what's plugged in where.
  • IPAM, VLANs, VRFs, and network zones with exposure reporting.
  • Relationships and dependencies for real blast-radius analysis.
  • Unmanaged and rogue-device detection for shadow-IT review.

See it on your own infrastructure

A working demo, tailored to how your organization actually runs.

Request a demo