Case study 1: Fleet compliance visibility from six disconnected systems
Six systems disagreed about the fleet. One reconciled dashboard now shows the true state of ~1,600 laptops.
Result. At any given moment, the whole IT team and management can see the true state of a ~1,600-laptop fleet: per-control coverage rates (MDM, endpoint protection, disk encryption, workspace), cross-system discrepancies, unmanaged and long-unseen devices, and hardware still assigned to departed users. The platform surfaced hundreds of previously invisible compliance gaps, each traceable to its specific control and source, and turned compliance from a three-ifs exercise into a permanently visible number with a work queue attached. Specific figures are deliberately not published; happy to discuss them in conversation.
Read the full case study
Context. Sword Health's device and identity data lived in six systems with no unified view: asset register (Snipe-IT), MDM (Kandji, JumpCloud), identity (Okta), Google Workspace, and endpoint security (SentinelOne). Compliance was checked if someone checked, if it was needed, and if there was time: manually pulling and cross-referencing exports from each system.
The problem under the problem. The sources disagreed with each other. Across ~3,400 device records, each system saw a different fleet: devices existing in the asset register but not in endpoint security, managed devices unaccounted for, devices belonging to people who had already left. Any compliance answer built on a single source was wrong by construction.
Approach.
- Established the asset register as the single source of truth and reconciled every other system against it by hardware serial, with conflicts flagged for human resolution, never silently merged
- Built a live dashboard unifying all six sources: per-device security coverage, encryption, management state, ownership, and data freshness, with every non-compliant device traceable to the specific gap and source
- Made cross-system blind spots first-class citizens: dedicated views for devices missing from each system, devices assigned to departed users, and devices unseen for 7/14/30+ days
- Delivered implementation through AI coding agents under my direction and review, with architecture decisions locked in writing before any build
Next phase (in staging, launch pending). A second-generation platform extends the same visibility from compliance into spend and lifecycle: full audit trail with exportable evidence packs for ISO/SOC-style reviews, likely-machine-swap detection (a device quiet for months while its user actively works on a replacement: unrecovered hardware made visible), and seat-level SaaS cost tracking with waste detection and renewal tracking, fed by automated directory and seat feeds. Cost findings will be published here once real data has flowed.