WeftRoute Cloud Early access · Founding design partners

Network automation your whole team can operate.

Not just the one person who writes the scripts.

A network admin with zero programming knowledge wires visual nodes into a complete operation — config backup, OS upgrade, compliance audit, VLAN and ACL provisioning — then runs it on demand, on a schedule, or straight from a monitoring alert. Dry-run diffs, approval gates and auto-rollback are on by default, because it is a production network.

Bring one multi-site workflow and one non-negotiable trust requirement — we map both in the session.

Flow Builder device-upgrade Validate Run
Network
Backup Configbackup-config
Apply Configapply-config
Upgrade Imageupgrade-image
Get Structured (YANG)structured-get
Governance
Approval Gateapproval-gate
Change Windowchange-window
Select Devices tag: branch-edge
Backup Config to Git, pre-upgrade
Upgrade Image verified, space-gated
Approval Gate waiting on you
Change Window Sat 02:00–05:00
Health Check post-change verify
Notify #net-changes
on failure → auto-rollback
InspectValidateRun

Approval Gate

The flow is paused. Nothing on the device changes while it waits.

Diff preview
+ boot system flash:EOS-4.31.2F
- boot system flash:EOS-4.29.4M
Reload not requested — image staged only
ApproveReject
Proven live
against real devices
Arista EOS Juniper Junos Nokia SR Linux Cisco IOS · IOS-XR · NX-OS + your platform, via plugin

The problem

One person scripts. Everyone else waits.

The runbook lives in someone’s head

That, and a folder of Python nobody else will touch. When they are on leave, the change waits — or someone brave does it by hand at 2am.

Every vendor is a rewrite

Arista, Junos, SR Linux and Cisco each get their own script, their own edge cases, and their own quiet way of breaking eight months later.

Nothing is provable afterwards

Who approved it? What actually changed on the box? A screenshot pasted into a ticket is not an audit trail, and the auditor knows it.

WeftRoute turns all three into one canvas your whole team can read, run, and answer for — with the credentials and the execution still inside your own environment.

The product

Low-code, end to end.

Every capability is a palette node: collect, parse, decide, change, verify, notify. Parsing uses TextFSM, regex or YANG — no AI required. Nothing falls back to “write a script for that part”.

Every arrow can branch on the previous node’s result, so a flow handles the failure path as explicitly as the happy one. Run it on demand, on a schedule, or from an external trigger — a monitoring alert, an ITSM ticket, a CI pipeline.

Operations console

Fleet health, run ledger with per-node output, compliance posture, and a “waiting on you” approvals queue.

Device manager

Probe, back up, diff and restore any device directly — the same safety rails as a flow, one device at a time.

Eleven node categories, one canvas

Network devices Servers & OS Hypervisors & VMs Databases Containers Cloud DevOps Governance Chat & service desk AI Flow logic

One flow, many domains

Open a Jira change ticket → gate on a change window → canary-upgrade one branch switch → verify the whole site still converges → close the ticket.

One graph. One audit trail. Your service desk, your switches and your servers are all first-class node categories — not integrations bolted on the side.

Safety rails

It is a production network. The rails are on by default.

You do not opt in to being careful. Every destructive capability ships behind a preview, a gate, a window and a way back.

Dry-run diff preview

See the exact config delta before anything is applied — and the approval gate shows that same diff to the person signing off.

Human approval gates

A named human clicks in the run ledger. The flow waits as long as it takes, and not one byte changes on a device while it does.

Change windows

Block or defer writes outside maintenance hours. On a routine flow like guest-WiFi PSK rotation, the window is the control — no approver needed.

Auto-rollback

A failed apply reverts to the pre-change state on its own. VM snapshots, database migrations and container updates each carry their own way back.

Reload-gated upgrades

A device is never rebooted unless you explicitly opt in. Free-space gated, image verified, downgrade-guarded, hardware-validated per platform.

Git-versioned history

Every config version committed to Git, with one-click restore — previewed first, like every other change on the platform.

AI is an accelerator, never a dependency

Describe a flow or a parser in plain English and WeftRoute generates it — validated, then saved as ordinary editable data you can read and change. Execution is deterministic with no model in the loop. The whole feature is off by default.

Templates

Twenty flows that already work.

Every one is a real, safety-railed graph you open and edit — not a blank canvas and a tutorial. Each already carries its own backup, preview, gate and rollback.

Config backup
Device upgrade
Image distribution
Inventory collection
Nightly inventory
VLAN provisioning
ACL deployment
VLAN ACL (VACL) deploy
Device onboarding
Enable event reporting
Guest WiFi PSK rotation
New branch provisioning
PCI wireless evidence
Compliance check
Linux patch window
Service restart
VM snapshot before change
DB schema migration
Container update + rollback
Cross-domain change

Vendor support

Multi-vendor by architecture, not by promise.

Transport — SSH, Telnet, NETCONF, RESTCONF, gNMI, SNMPv3, vendor HTTP APIs — is kept separate from capability behind one stable gRPC contract. A new platform is an addition, never a redesign.

PlatformFactsBackup / restoreCLIApplyOS upgradeYANG
Arista EOS running + startupdry-run + rollbackstagedall three
Juniper Junos running + candidatecandidate / commitstaged via PyEZNETCONF
Nokia SR Linux via gNMIcanonical JSONgNMI
Cisco IOS / IOS-XR / NX-OS stagedtransport-ready
Your platform A plugin scaffold maps your existing Python device code onto the contract — zero core edits.

Green marker = verified live against real hardware. Staged upgrade = image transferred and boot set; the activation reboot only happens when you pass reload explicitly.

Security & the trust boundary

We run the control plane. You keep the credentials and the runtime.

Hosted coordination should not require hosted custody. The boundary is built into where each responsibility runs — not into a policy document.

Control plane WeftRoute Cloud Graph · roles · schedules · approvals
Edge — Core DCcredentials · execution · evidence
Edge — Branch Westcredentials · execution · evidence
Edge — Branch Eastcredentials · execution · evidence
0 inbound site ports
01

Credentials never enter the SaaS

Profiles and secrets resolve only inside your Edge, at the moment local execution needs them — from your Vault, as static secrets or one-time SSH credentials and certificates.

02

Protected payloads stay local

Configurations, command output, diffs, backups, detailed inventory, query results and diagnostic evidence remain in your environment. The cloud sees workflow structure and sanitized run state.

03

The Edge dials out

No site needs an internet-facing WeftRoute port, and none accepts an inbound control-plane connection. Identity is bound to the enrolled Edge.

04

Local policy has the final say

A signed cloud instruction is not automatically safe. Your Edge revalidates capability, scope, local policy and the active change window before it touches anything.

OIDC single sign-on RBAC with per-device-group scoping Strict multi-tenant isolation Vault-backed secrets mTLS between services Append-only audit trail Prometheus metrics Opt-in OpenTelemetry tracing

Plans

Use the cloud where it helps. Keep control where it matters.

The choice is only ever we host it or you host it. Execution runs on your own setup either way, credentials never leave your environment either way, and the same flows run unchanged across both.

Air-gapped

Ships today

Everything on your own server, inside your network. Control plane, Edge and evidence never leave the estate.

  • No outbound connection of any kind
  • Images, SBOMs, licence and model artifacts import as signed media
  • Signatures and checksums re-verified inside the destination
  • Offline answers for private CA, OIDC, DNS, NTP and backups
  • Leave the network on if you want on-premise without full isolation — same appliance
Talk to us

Founding design partners

Help shape the platform your team will actually operate.

Bring one multi-site workflow and one non-negotiable trust requirement. We will map both into an early-access design session and build the flow with you.

Or email karmi.business@gmail.com directly.