Solutions / Governance & Platform

The guardrails your platform needs, without starting from scratch

Your platform team builds the guardrails once. Developers and AI assistants work inside them without asking, and every request gets checked before the resource exists. It all runs where you decide.

Platform & DevOps

Stop being the ticket queue. Four-layer authorisation, SSO, an audit trail, and a runner you control or the CI you already have.

Developers

The guardrails are inside the golden path, so you don’t read the policy to comply with it.

Executives

Self-hosted, air-gapped or sovereign cloud, European by design. Nothing here is taken on faith.

Why

Access, audit and where it runs, settled before the resource exists

Your platform team shouldn’t hand-build every environment and then police it afterwards. Set the rules once and they hold for every request, from a person or an assistant. Developers stop waiting on you. The organisation gets delivery that’s compliant on arrival, not checked after the fact.

Without it

Audit as archaeology

Policy is a document, enforcement is a review, and the finding arrives a quarter after the resource did. Rights are copied from whoever left last.

Signs it’s your problem

  • A compliance finding names a resource nobody approved
  • Access rights are inherited from the last person who had the job
  • An AI assistant has the same rights as its user, everywhere, unobserved
Cycloid

With Cycloid

Ask first, every time

Forms validates every submission. Approval gates run before a deployment. Every Action, from a person or an assistant, passes the same four-layer authorisation chain and lands in the audit trail.

What changes

  • A non-compliant resource is refused before it exists
  • An assistant can be scoped tighter than its user, read-only or no destroy
  • One record answers the auditor, and everyone else

The trade-off · speed vs compliance · guardrails before the resource keep both

What

Eight features that make the guardrails

Each has a page of its own. Here’s what it does, how, and who it’s for.

Self-hosted, air-gapped, sovereign

Deploys where your data has to stay, on a hyperscaler, a private cloud or fully disconnected, with licence validation that works offline.

Self-hosted first, European by design, ISO 27001 certified, open formats. TerraCognita and InfraMap are open source.

Cycloid instance administration console for a self-hosted install, showing active seats against the licence, resources, deployments this month, usage per workspace and the anonymous telemetry switch.

Built for

Executives

Platform & DevOps

Customisable portal

Shapes the sidebar, resource pages, dashboards and branding for a tenant, a team or one person.
Platform engineers set resource tabs per Blueprint, admins set the sidebar and brand colours, team leads their own sections.
 
Appearance settings in Cycloid for setting a workspace's primary and accent brand colours, with contrast checks on light and dark pages, a derived chart palette and a live preview of the portal in both modes.

Built for

Platform & DevOps

Developers

Org modelling & SSO

Maps teams, roles and Resource Groups onto your org, with isolated tenants for MSPs.

SSO through Entra ID, Okta, Keycloak or any OIDC or SAML 2.0 IdP, with SCIM.

Cycloid SSO configuration for an OIDC identity provider, mapping directory groups such as cycloid-admins and cycloid-developers to roles and teams applied at sign-in.

Built for

Platform & DevOps

Executives

Four-layer authorisation

Runs every decision through four layers, ReBAC, RBAC, ABAC and approval. All four must say yes.

Built on OpenFGA. An assistant can be held tighter than its user at the tool layer.

Diagram of Cycloid's four authorisation layers evaluated in order: ReBAC for visibility, RBAC for permitted actions, ABAC for conditions and approval for sign-off, before an action is allowed.

Built for

Platform & DevOps

Executives

Plugins

Adds providers, data sources and widgets, official or your own, switched on per tenant.

Written in TypeScript and run in isolation. Install from the marketplace, a private registry or a tarball for air-gapped sites.

Cycloid plugins catalog with 14 enabled and 22 available plugins, starting with cloud providers AWS, Kubernetes, Azure, Google Cloud, VMware vSphere, Scaleway and OVHcloud, then GitHub and GitLab.

Built for

Platform & DevOps

Developers

Native runner, or your CI

Executes Actions where you decide: the Native Runner inside your environment, or your existing CI.

The Native Runner runs across clouds and on-prem, or hand execution to GitHub Actions, GitLab CI, Jenkins or Azure DevOps.

Runs tab of a managed database in Cycloid, listing backup, failover, scale and credential-rotation runs with their status, who triggered them and whether they ran on the native runner, GitHub or GitLab.

Built for

Platform & DevOps

Developers

Environment types & naming rules

Predefines the environment types every Form, Blueprint and promotion picks from, and checks every new name at creation.
Each type carries a default policy, such as approval on production. Naming rules apply per kind, per Blueprint or tenant-wide, and the closest rule wins.
Cycloid audit log listing 67 workspace events over 30 days, each with its actor, target, changed values and an allowed or denied result, plus an activity chart of denials.

Built for

Executives

Platform & DevOps

Audit log

Records every request, approval, Action and its outcome, with who or which assistant triggered it and under which authorisation.

Written by the platform as the Action runs, not a log sent from elsewhere. One request ID traces a change end to end.

Cycloid audit log listing 67 workspace events over 30 days, each with its actor, target, changed values and an allowed or denied result, plus an activity chart of denials.

Built for

Executives

Platform & DevOps

Bring the change that needs three sign-offs

In twenty minutes we’ll show you the guardrail that replaces them, on a self-hosted instance if that’s how you’d run it.