Building the brain of Enterprise IT.
Some time ago, I shared how we transformed the way we manage our network infrastructure by implementing a Continuous Compliance model.
It worked so well in improving availability, costs, and time-to-market that we asked ourselves a fairly logical question:
Why not apply the same data-driven philosophy across the entire Enterprise IT ecosystem?
Today, that experiment has evolved into a platform that centralizes, governs, and connects information across virtually our entire infrastructure.
Internally, we named it Sauron — a playful reference to one of my favourite books and its “all-seeing” cross-domain visibility — and it has helped us reduce operational costs by around 30%, improve our security and stability, and, most importantly, change the way we make IT decisions.
So, how did we get here?
1. The Foundation: Turning Isolated APIs into Governed Data
The first challenge was obvious: every provider — Google, Microsoft, Atlassian, Palo Alto, telecom operators, etc. — has its own APIs, data structures, and concepts.
And almost all of them provide only a partial view of the ecosystem.
We built lightweight microservices on GCP Cloud Run to ingest data from these platforms — through polling or push, depending on each provider’s capabilities — and centralize it in BigQuery.
But centralizing data is not enough.
With Dataform, we built a transformation and governance layer that normalizes concepts and, more importantly, enriches the information with data the APIs don’t know about: costs, contracts, organizational structures, lifecycle information, and internal business rules.
One governed data layer powering analytics, automation and AI.
By connecting telemetry, inventory, users, licenses, and financial data, we can calculate TCO at different levels of granularity — from a consolidated enterprise view down to country, warehouse, department, division, provider, or user.
We no longer simply have infrastructure data.
We have business context around our infrastructure.
2. From Observability to Continuous Compliance
The next step was turning all that information into something operational.
For us, Compliance isn’t limited to regulatory or security requirements. It can be any metric we want to keep within a defined standard and express in a simple way through an SLA %.
Continuous means that this evaluation happens automatically and repeatedly, while also preserving its entire historical evolution.
We apply this model across licenses, hardware, telecommunications, infrastructure and device configurations, security, and internal knowledge.
But the individual use cases are almost secondary.
What matters is that they all follow the same pattern:
Measure → Compare → Detect deviation → Remediate → Measure again
This changes the operating model.
Instead of discovering problems when an incident happens or an audit arrives, we aim to detect them earlier while automatically maintaining the historical evidence behind them.
3. AIOps: Closing the Loop Between Data and Operations
And this is where an important distinction appears:
A dashboard nobody looks at doesn’t solve anything.
When the system detects relevant deviations, it automatically generates the required evidence and creates remediation actions in Jira Service Management.
Routine cases reach our L1 team already contextualized, allowing them to perform the physical or logical remediation without constantly involving engineering.
L2/L3 gets involved when actual analysis or design work is required.
The flow becomes:
Data → Detection → Evidence → Ticket → Remediation → Compliance
This turns Continuous Compliance into a closed-loop operational model: the data doesn’t just tell us what’s happening — it triggers actions to correct it.
4. Data Also Means Knowledge
There was, however, another type of infrastructure that we don’t usually think of as infrastructure:
our operational knowledge.
Outdated operational knowledge affects both AI and human support: an agent or technician relying on obsolete procedures can troubleshoot issues or make decisions based on information that stopped being valid months ago.
Garbage In, Garbage Out.
That’s why we brought Document & Process Freshness into the same Continuous Compliance model.
Support documentation and operational processes in Confluence enter an automated review lifecycle: once they exceed their defined validity period, a task is generated for a specialist to revalidate, update, or archive them.
A periodic digest also summarizes new procedures, updates, deprecated documents, and pending reviews.
This keeps teams (and AI) aligned while significantly reducing the risk of relying on outdated knowledge.
5. From Data to Decisions
Today, virtually every major vendor provides dashboards and, increasingly, its own AI assistants.
The problem is that each one only understands its own silo.
Google knows Google. Microsoft knows Microsoft. Palo Alto knows Palo Alto. Atlassian knows Atlassian.
But many of the questions that actually matter in Enterprise IT span all of those systems.
And that’s where centralizing and governing the data changes the game.
On top of the same platform, we built two complementary ways to leverage that information.
📊 Looker provides structured analytics and cross-filtered dashboards to explore trends, costs, inventory, compliance, and capacity.
🤖 Sauron, connected to BigQuery and our operational knowledge in Confluence through GCP Agent Platform, allows us to interact with all that information using natural language.
With RBAC (Role-Based Access Control), the agent identifies who is making the request and determines what information that person is authorized to access. These permissions are enforced in code, outside the model context: each user can only invoke authorized tools, and those tools can only access role-specific BigQuery views. The model itself cannot expand those permissions through prompting or context manipulation.
This allows us to move beyond querying isolated data and start asking questions that directly support decision-making.
The value isn’t another AI assistant.
The value is giving the assistant a governed, cross-vendor view of Enterprise IT.
Special Note: The following examples are based on real interactions with Sauron. Names, locations, IP addresses, figures and other private information have been anonymized, and the UI has been visually enhanced for readability. The underlying queries, data relationships and responses reflect the actual system.
Cross-vendor data turned into a single business answer
From executive insight down to operational context
The same governed data layer can support use cases ranging from knowledge, compliance to real-time operational troubleshooting.
Another option is to reuse Sauron’s output from longer conversations with other AI tools like Gemini in Google Slides to automatically turn data insights into executive-ready visuals.
💬 Question to Sauron: To build next year’s budget, I need the annual cost of licenses (factoring in a 20% growth rate), internet connectivity, mobile lines, support services, and the replacement of PCs older than 3 years (assuming €1,000 each). Please break down the total between CapEx and OpEx.
💬 Prompt to Gemini in Google Slides: please create a slide with the information from this interaction with my AI agent.
Turning operational data into executive-ready decisions
Or use Gemini Images to turn a previous Sauron interaction into a visual summary of what followed. The example below starts with a question I asked last year to identify security and cost-optimization initiatives. We implemented those recommendations and have tracked their impact over time through our compliance metrics.
💬 Last year question to Sauron: I need 3 initiatives to enhance security and optimize costs based on my BigQuery data.
💬 Prompt to Gemini Image: please create a colorful image with the information from this interaction with my AI agent.
From insight to action — and measurable impact
AI does not replace human judgment. Its value is in correlating the right data, structuring the problem, and giving us a stronger starting point for analysis and decision-making.
The Real Business Impact
The result goes far beyond having better dashboards.
FinOps: around 30% reduction in operational costs by identifying unused resources and making decisions based on granular TCO.
Risk & Compliance: we move from point-in-time controls to continuous, historical evidence of the actual state of our infrastructure as a whole.
Operations: deviations can be detected, contextualized, and routed for remediation before they turn into incidents.
Decision Intelligence: we can analyze technology, operations, and costs through a single data model, regardless of which vendor originally generated the information.
Ultimately, the goal was never simply to build an agent.
It was to build an intelligence layer for Enterprise IT capable of observing, connecting information, and helping us act across an increasingly distributed technology ecosystem.
What started as Continuous Compliance for networks ended up becoming something much bigger:
the brain of our Enterprise IT.
A huge thank you to: Jasper Duizendstra, remarkable GDE who collaborated with us and sparked some early ideas around the architecture; Pratibha Chaudhary, a key developer who has been there throughout every stage; and Nic0lasا Franc1aا, for giving us the space and trust to experiment and innovate.
Originally published on LinkedIn.