Capabilities
Capabilities
KEEP is intentionally conservative when classifying capabilities. A capability is only marked Validated after it has been proven in the environment that matters for that capability. Capabilities marked Evaluation are fully implemented and available today but are still gathering real-world validation through the Founding Evaluator Program.
Every capability below is labeled Validated, Evaluation, Planned, or Unknown.
Validated means proven in the environment that matters for it — real hardware or a live deployment for hardware-dependent capabilities, real persisted data through the intended workflow for software-only ones.
Evaluation means fully implemented and usable today, but not yet proven in a real target environment. This is exactly what the Founding Evaluator Program exists to validate.
Planned means designed, scaffolded, or partially built, but not yet usable end-to-end.
Unknown is used only where the evidence itself is insufficient to classify.
Network & Device Discovery
- Automated network discoveryValidated Capability
Scans a client network to identify devices and services, tuned to avoid disrupting live traffic on production networks. (Source: KEEP architecture documentation)
- Passive device discoveryValidated Capability
Identifies devices present on a network segment without actively probing them. (Source: KEEP architecture documentation)
- Docker container and topology discoveryValidated Capability
Identifies containers running on a Docker host and maps the network relationships between them. (Source: KEEP architecture documentation)
Connectivity & Infrastructure
- Self-hosted secure tunnel networkingValidated Capability
Provides a self-hosted, encrypted tunnel connecting each Spoke to its Hub, without relying on a third-party VPN provider. (Source: KEEP architecture documentation)
Device Health & Power Monitoring
- NUT UPS monitoringValidated Capability
Tracks battery status, runtime, and power events for UPS hardware polled via Network UPS Tools (NUT). (Source: KEEP architecture documentation)
- APC/SNMP UPS monitoringEvaluation Capability
Tracks APC UPS status via SNMP trap ingestion, including on-battery and low-battery events. (Source: KEEP architecture documentation)
- Temperature monitoringPlanned Capability
Monitors server and network-closet temperature via supported sensors. (Source: KEEP architecture documentation)
- Printer monitoringEvaluation Capability
Tracks toner, paper, and error states on networked printers. (Source: KEEP architecture documentation)
- Storage and disk monitoringEvaluation Capability
Tracks disk health and capacity on supported Windows devices. (Source: KEEP architecture documentation)
- Unauthorized device detection on switch portsEvaluation Capability
Flags a device connecting to a previously idle switch port. (Source: KEEP architecture documentation)
- Uptime Kuma availability monitoringEvaluation Capability
Tracks uptime and availability for monitored services and devices via an integrated availability-monitoring instance. (Source: KEEP architecture documentation)
Compliance & Security Tracking
- Antivirus compliance trackingValidated Capability
Tracks AV coverage and definition currency across monitored devices. (Source: KEEP architecture documentation)
- Patch and end-of-life exposure reportingValidated Capability
Classifies devices by patch and operating-system support status, including Windows end-of-life exposure. (Source: KEEP architecture documentation)
- Identity conflict detectionValidated Capability
Cross-references directory and endpoint activity to surface stale accounts and related identity mismatches. (Source: KEEP architecture documentation)
- Vulnerability scanningEvaluation Capability
Runs network vulnerability scans and links findings to incident tracking for remediation evidence. (Source: KEEP architecture documentation)
Asset & License Management
- Hardware asset registerValidated Capability
Tracks hardware inventory, warranty, and end-of-life dates, flagging coverage gaps. (Source: KEEP architecture documentation)
- Software license and agreement trackingValidated Capability
Tracks license seat utilization and vendor agreement expiration with configurable advance alerts. (Source: KEEP architecture documentation)
- Device decommission recordsValidated Capability
Produces a signed record of asset removal, including data sanitization method and sign-off. (Source: KEEP architecture documentation)
- Repair vs. replace decision supportEvaluation Capability
Compares incident repair cost against replacement cost to support hardware lifecycle decisions. (Source: KEEP architecture documentation)
Incident Management & Reporting
- Incident detection and alertingValidated Capability
Opens and tracks incidents from device conditions, with escalation and response logging. (Source: KEEP architecture documentation)
- SLA trackingValidated Capability
Tracks response and resolution deadlines against configurable per-client service targets. (Source: KEEP architecture documentation)
- Compliance and operational reportingValidated Capability
Produces recurring reports, including site assessment, quarterly compliance, and end-of-life exposure reports, with reports available to support relevant IT general control evidence. (Source: KEEP architecture documentation)
- Knowledge baseValidated Capability
Captures resolution guidance tied to specific device conditions, drawn from prior incident work. (Source: KEEP architecture documentation)
- SOX IT general controls reportingEvaluation Capability
Maps vulnerability management, endpoint protection, access monitoring, and change control activity to SOX IT general control categories. (Source: KEEP architecture documentation)
- Merlin AI device diagnosisEvaluation Capability
Reviews a device's open incidents, work log, and event history to produce a plain-English diagnosis. Analysis only — it does not take action. (Source: Merlin architecture documentation)
- Onboarding Scan AnalysisEvaluation Capability
Reviews a new client's onboarding vulnerability scan results and produces a prioritized remediation brief before the client is accepted. (Source: Merlin architecture documentation)
- Incident CoordinationEvaluation Capability
Reads an incident's full thread and device state to suggest next steps, synthesize status for a Director, and prompt technicians who haven't logged an update. (Source: Merlin architecture documentation)
Notifications & Integrations
- Chat notificationsEvaluation Capability
Sends incident and SLA-breach notifications to a configured team chat channel. (Source: KEEP architecture documentation)
- Professional Services Automation (PSA) integrationEvaluation Capability
Pushes qualifying incidents to a connected PSA platform. (Source: KEEP architecture documentation)
- Cloud-managed network integrationEvaluation Capability
Reads device and connectivity status from a cloud-managed network platform. (Source: KEEP architecture documentation)
- Browser-based remote accessEvaluation Capability
Opens an authenticated remote session (RDP, SSH, or VNC) to a monitored device directly from the browser. (Source: KEEP architecture documentation)
For how sign-in, multi-factor authentication, and trust boundaries work, see Security & Data Ownership. For the architecture behind these capabilities, see How KEEP Works.
Continue to Evaluate KEEP
For what evaluating KEEP actually involves, start to finish, see Evaluate KEEP.