A network engineering team replaced manual, device-by-device changes with governed, auditable orchestration built to operate inside strict OT segmentation and compliance requirements, turning IOS upgrades, VM provisioning, and BGP changes into repeatable workflows without opening new security exposure.
Manual, error-prone network changes across a segmented OT environment, with no orchestration layer built to operate inside the team’s security and compliance boundaries.
Itential orchestrated IOS upgrades, VM provisioning, and BGP configuration management into governed, auditable workflows built to run inside the team’s existing segmentation and change control requirements.
Manual, multi-hour network changes now run in minutes, with every action logged and governed, cutting risk exposure while freeing the team to focus on higher-value work.
The network engineering team at a major oil and gas company runs a complex infrastructure spanning multiple regions and thousands of devices supporting critical business operations. The tools to manage it well were already in place: NetBox as the source of truth, SolarWinds for monitoring, ServiceNow for change management, GitLab for version control, vSphere for virtualization, but nothing orchestrated across them. Every iOS upgrade, every VM request, every BGP change meant an engineer stitching those systems together by hand.
The environment made the stakes higher than most. As a critical infrastructure operator, the team’s OT networks run under strict segmentation requirements: no persistent external connections, tightly scoped access, every integration justified on its own merits.
That posture isn’t caution for its own sake. It’s how critical infrastructure networks have to be built. A compromised or mismanaged connection into a control network doesn’t just risk downtime; it risks a safety event, a regulatory finding, or a production outage with consequences well beyond the network team. Any platform brought into this environment had to operate inside the same segmentation and change control standards, industry frameworks like IEC 62443 and the team’s own management-of-change process, that already governed everything else on the network. Fully governed and fully auditable wasn’t a nice-to-have. It was the baseline requirement.
Secrets management was where that gap showed up most concretely, and where the risk was hardest to ignore. Credentials were managed out of local instances of a password vault kept on shared jump boxes, workable when the team had a handful of devices to touch, but never built for a fleet in the thousands, and not the kind of setup a security team wants sitting in front of OT infrastructure.
A shared jump box with locally stored credentials is exactly the sort of soft target that becomes a pivot point into more sensitive parts of the network if it’s ever compromised. “It’s not an automation-friendly way of doing it,” as one team member put it, and the same manual pattern ran through everything else that touched the network: upgrade pre-checks run by hand against multiple systems before every change, and virtual machine requests that moved through GitLab, Terraform, and a change board with a person in the loop at every handoff.
The team’s technology stack was already in place. What it lacked was a platform to orchestrate across it without asking the security team for new exceptions.
Any orchestration layer here had to clear two bars at once: connect the systems the team already ran, and do it without loosening the segmentation and change control the environment demands. Itential cleared both.
Itential connected directly into NetBox, SolarWinds, ServiceNow, GitLab, Cisco, and vSphere and orchestrated across them, rather than asking the team to consolidate onto a new set of tools.
Every workflow was designed to operate inside the team’s existing OT segmentation and change control requirements, including standards like IEC 62443 and formal management-of-change, rather than asking for new exceptions to reach the network.
Every workflow runs the same way every time: pre-checks, validation, and post-checks built into the sequence, replacing tribal knowledge with an orchestrated, auditable process.
Every orchestrated action is logged and traceable: who touched a device, when, and under what approval, turning routine changes into evidence a compliance review or audit can actually use, rather than something the team has to reconstruct after the fact.
Orchestrated workflows are surfaced directly in the team’s ServiceNow instance, so requesters can kick off an IOS upgrade, a VM request, or a BGP change from the same catalog they already use for change management. No new portal, no new place to go.
The platform runs on a full HA architecture, a three-node etcd cluster and three-node MongoDB configuration, built to support production-scale orchestration, not a lightweight scripting layer.
With three workflows orchestrated, the team has a foundation to extend the same model across its full device infrastructure and take on new use cases as they come up.
The team built its orchestration layer around three high-friction workflows, tying its existing systems together into governed, repeatable processes rather than one-off scripts. Every workflow was designed to run inside the boundaries already in place: no new external connections, no changes to how OT segmentation worked, and credentials pulled through the same governed access model instead of a new one.
Command templates handle CLI interaction, a transformation engine handles data manipulation, and configuration management runs automated backups and diffs underneath all three: the connective tissue that turns individual automations into an orchestrated operating model, without asking the security team to trust anything new.
Pre-checks on CPU, memory, and disk space, device health pulled from SolarWinds, software versions retrieved from NetBox, the upgrade itself with built-in validation, and post-upgrade verification are now sequenced and orchestrated as a single workflow, not a per-device checklist an engineer runs by hand.
Virtual machine provisioning is orchestrated end-to-end across GitLab and Terraform, moving a request from submission through change approval to deployment with retry logic and error handling built directly into the workflow.
Configuration backup, Jinja2 template-based rendering, deployment, and validation of both BGP and routing tables on data center routers are now coordinated as one orchestrated sequence instead of a manual, router-by-router change.
Orchestrating its highest-friction workflows changed more than the time on the clock. It changed how the team operates, and how much risk it carries while doing it:
Together, these gains reframe network operations from a set of individual scripts into a governed, repeatable orchestration model: the difference between fixing today’s bottleneck and building the platform that absorbs tomorrow’s, without ever loosening the security posture the environment demands.
The team’s next chapter isn’t just more workflows. It’s a different way of running them, without loosening the governance the environment requires. With iOS upgrades, VM vending, and BGP management proven out as orchestrated, governed processes, the team is now exploring how FlowAgents and Itential’s FlowAI capabilities could sit on top of that same orchestration layer: letting engineers describe an intent in natural language and have it reasoned through and executed against the workflows, integrations, and guardrails already running in production, rather than building each new automation by hand.
It’s a natural next step rather than a new platform decision. The orchestration layer already in place, the same command templates, transformation logic, and validated integrations across NetBox, SolarWinds, GitLab, vSphere, and ServiceNow, becomes the trusted execution layer an agent reasons over, with every action still governed, auditable, and scoped inside the same OT segmentation and compliance boundaries the team already requires for production changes. Agentic doesn’t mean less governed. In an environment like this, it can’t.
See how Itential connects AI reasoning to governed execution across your entire infrastructure.