HOW OLLANDI WORKS

From live infrastructure state to verified defense.

Ollandi monitors infrastructure through DIPs, reasons across domain evidence, validates response actions, and preserves a complete incident record.

One system for the complete defense loop: see the change, understand the threat, control the response, and verify the outcome.

01 · MONITOR

Build a current, cross-domain state.

Cloud, Identity, Runtime, Network, Endpoint, On-premises, and ATM DIPs normalize live evidence into assets, identities, dependencies, timelines, and policy objects with provenance preserved.

  • Domain monitoring through DIPs
  • Entity and dependency state
  • Change history and source provenance
SignalsAssetsIdentityChange
OLLANDI PLANECurrent infrastructure context
UnderstandDecideProve
02 · INTERPRET

Turn sequences into threat hypotheses.

Ollandi tests legitimate operations, drift, misconfiguration, and malicious activity as competing explanations. Operators see supporting evidence, conflicting evidence, confidence, and affected scope.

  • Intent-level threat hypotheses
  • Confidence and refuting evidence
  • Service and infrastructure consequence
OPERATING DECISIONContext complete
ConditionService dependency changed
ConsequenceTwo customer paths exposed
AuthorityOperations approval required
NextPrepare bounded intervention
Evidence attached
03 · RESPOND AND VERIFY

Validate the action before execution.

Candidate actions are checked against policy, confidence, blast radius, service dependency, reversibility, and required approval. Ollandi verifies the result and generates the evidence bundle.

  • Classed and reversible-first actions
  • Human approval for high-impact action
  • Post-action verification and evidence
BEFORECondition developing
ApproveExecuteVerify
AFTERService state confirmed
EVALUATE OLLANDI ON A REAL INCIDENT

Connect the relevant DIPs.
Run observation-only. Prove the response.