How it works
Totenvis knows an estate, watches it, acts on it and evidences its
compliance. Four of those parts are built and running today, two are
being written now, and compliance is on the roadmap. This page is kept
in step with the product repository's main branch — nothing
below claims more than what's actually shipped.
Discovery
Totenvis sweeps the subnets it's pointed at over ICMP and TCP probes, harvests ARP tables, and walks SNMP where a read-only credential is available — including LLDP and CDP neighbour tables, so device-to- device links show up automatically. Every asset is stored with its IP, MAC, hostname and first/last seen times. When discovery is blocked — a device that won't answer, a missing credential — Totenvis says exactly where and proposes what would unblock it.
Topology
An interactive, force-directed map is built from what discovery finds: assets, subnets and the links between them. Zoom, pan, filter by site, VLAN or device type, and open a detail panel for anything on the map.
Remediation
Discovery gaps turn into proposals with evidence attached, and closing the loop into an action against a device is live: nothing changes until an operator approves a proposal and applies it, with the result checked on the next scan and logged to the audit trail. Today's driver covers one class of fix — re-enabling SNMP access on Meraki-managed devices, the product's first real device write; more device types and fix kinds are still on the roadmap.
Compliance
Every install will assess itself against DORA, ISO 27001 and ITIL, produce supporting documentation, and propose fixes where it falls short — with room to add further frameworks over time. Those fixes re-enter the same approve-and-schedule path as any other change, so closing a gap is a governed act with its own evidence. Totenvis assesses and evidences; it does not certify. The control catalogue and assessment engine are on the roadmap, and no compliance claim is made about the product today.
Agent
Where opening a port isn't an option, a small Totenvis agent runs on the device instead — Windows, macOS or Linux — and connects outbound only. It enrols with a single-use token, installs as a service, and reports what the device is and what it's running. Downloads carries the current build for each platform, with a one-line silent-install command; a Windows installer with an interactive wizard is being built next. Remediation on agent-covered devices will route through it.
Observability
Measurements over time arrive as OpenTelemetry, from your own collectors and from the agent, and a flow collector reads NetFlow straight from the exporters your network already has — so traffic between two assets sits beside the record of what those assets are. The collector and its storage run today; the views and queries onto them are being written now.
Change records
Approving a proposal raises a change, not an immediate action: the change carries its own assessment, approval and scheduled window, and the work executes when that window opens. The record lives in Totenvis or in the ITSM tool you already run — ServiceNow first — and every action is recorded against the change and the person who approved it.