Configure identity, targets, and connections
Enroll the endpoint agents you need, configure the operational connections in scope, and verify each connection before a workflow depends on it.
For small teams carrying a large estate
When infrastructure, endpoints, or security need attention, GAEZLA exposes the usable API surface across your configured estate so a small team can investigate, build configuration as code, and execute through governed paths. The evidence is retained for later review and audit.
Configured connections expose the operational capabilities each workflow can use.
More hosts, more clouds, more obligations, same people. Your tools tell you something is wrong. Finding out why, fixing it, and proving it happened are all still manual, and all still yours.
How it works
Enroll the endpoint agents you need, configure the operational connections in scope, and verify each connection before a workflow depends on it.
Resolve a concrete target, search the operation-level specifications exposed by its configured connections, and retrieve exact schemas before reading current state.
Dispatch managed playbooks through queues, schedules, or routines. Investigation mutations use a separate evidence-backed proposal with approval and policy-required step-up.
Capabilities
Connect the systems you already run, then use the capabilities each workflow needs without rebuilding context between tools.
Build a case from the connected sources relevant to the question.
A case can search operation-level API specifications, retrieve schemas, query typed read capabilities, inspect configured repositories, and retain the resulting evidence, hypotheses, findings, diagrams, and transcript.
Dispatch signed, scoped work and retain its queue state and output.
Enrolled endpoint agents authenticate independently, poll for assigned work, verify signed workloads, and return status, logs, and metadata. Schedules and routines are separate managed paths.
Configure an operator-selected provider and models for assisted work.
Configured models can assist investigation, alert qualification, adapter drafting, and other named workflows. External mutation from an investigation uses a separate evidence-backed proposal and approval path.
Connect supported operational systems by capability and scope.
Supported systems expose a common operation-search, schema, and invocation pattern through MCP. Available reads, mutation lanes, permissions, and target scope remain specific to each configured connection.
Bootstrap a known local runtime and manage optional apps.
The bootstrap path installs the base runtime and deployment controller. Operators can configure, install, reconcile, expose, and inspect optional apps; additional runtimes can use the same packaging and lifecycle model.
Review asset ownership and analyze utilization where metrics are configured.
Filter assets by ownership state, manage ownership validation, and inspect its email history. Rightsizing uses a configured monitoring source and operator-selected AI model to analyze utilization.
Qualify incoming signals and track routed delivery.
Alert routing accepts configured webhook sources, qualifies signals, records routing and delivery state, and exposes review and feedback. Alerts and the operational calendar remain distinct surfaces.
Inspect scanner findings and run supported hardening workflows.
Managed scanner assets, scan state, and findings retain source provenance. Supported hardening profiles keep checks, evidence, remediation, and verification in a separate workflow record.
Maintain framework records and scheduled evidence work.
Framework workspaces hold answers, gaps, documents, and applicability decisions. Calendar series create dated occurrences where operators attach notes, evidence, artifacts, owners, and framework links.
Request temporary access to configured eligible targets.
Access requests use configured identity mappings, eligible targets, approvers, durations, readiness checks, and policy-required step-up. This does not remove privileges managed outside the platform.
Author, preview, and govern custom graph ingestion shapes.
Create and edit adapters, dry-run a preview without persistence, or draft one with AI assistance. Adapter mutations use durable proposals with permission, evidence, approval, and optional step-up checks.
Configuration as code
Read an existing configuration and convert it to code, or design a new configuration from the schemas exposed by connected systems. The retained result can be a governed repository change rather than a one-off console session.
Semantic retrieval with lexical fallback finds the relevant operation; schema lookup supplies parameters, request bodies, and safety hints.
Use target-aware read capabilities plus existing repository files and history instead of designing from assumptions.
Create complete IaC or configuration files from what already exists or from a new operator-defined design.
A configured repository can receive a durable proposal; the PR opens only after operator approval and execution.
Why the name
GAEZLA comes from the Old Norse word gæzla: keeping, guardianship, or guard. We write æ as ae and keep the historic z—a fitting name for an AI SRE that watches over an estate, works out what changed, and helps its operators act with control.
The difference
Evidence collection uses read capabilities. Managed endpoint work has its own definitions and queue records, while an external investigation mutation requires a separately governed proposal.
A common MCP surface exposes operation discovery, schemas, live reads, repository context, and eligible actions across the configured estate.
Investigation, execution, alerts, scanner findings, hardening, compliance, assets, and temporary access are available together while preserving their distinct records.
Trust model
Human access, agent identity, workload signing, secret resolution, proposals, and execution are separate controls with explicit records.
Dashboard access uses configured human identity and role checks; machine execution uses separate agent identities.
Each enrolled agent authenticates independently, polls for assigned work, verifies signed workloads, and returns status and logs.
Eligible external reads can run directly; a write is never treated the same way. A proposed change declares current evidence, scope, risk, safeguards, and rollback before approval and any required step-up.
Sensitive values can use encrypted platform storage or a configured external secret connection. The selected path remains visible to operators.
Before you ask
The product has connection surfaces across infrastructure, cloud, identity, monitoring, repositories, and security telemetry. Exact capability depends on the configured connection and scope.
Managed workloads are scoped, signed, queued, verified by the assigned agent, and reported with status and output. Schedules and routines follow their configured controls.
Connect the systems and targets you want in scope, configure identity, and add any local apps the workflow needs. The appliance bootstrap provides the managed base runtime.
Half an hour, your own stack, no slide deck.
See it on your stackPlans
Start with the core operating path, then add broader automation, security, compliance, and access controls.
Bring one real operational problem and see how GAEZLA investigates it, proposes the next step, and keeps the result reviewable.