Every feature your CMDB needs, nothing it doesn't
A live CMDB, dependency mapping, network discovery, endpoint inventory, ITILv4 incident and change management, workflow automation, Microsoft 365 integration, and a complete audit trail. The core platform, VECTOR scanning, and ATLAS agents are in every plan, including the free tier.
IT asset tracking with dependency mapping
Every kind of IT asset modelled with purpose-built fields.
Kovira ships a comprehensive set of configuration item types covering devices, networks, WAN circuits, services, racks, locations, domains, software, licences, SLAs, vendors, contracts, people, groups, passwords, APIs, documents, incidents, and changes. Each CI type carries the fields that matter for that asset type, so you are not filling in irrelevant metadata to satisfy a generic form.
Every CI can be linked to other CIs through typed relationships, which means you can see exactly how a switch failure would ripple through your network, or which contracts are tied to which vendor, or what services depend on a particular server. The dependency map is interactive and visual, not a flat table you have to squint at.
Key capabilities
- Comprehensive set of typed asset categories
- Interactive visual dependency maps
- Typed relationships between any CI pair
- Version history on every record with one-click rollback
- Relational integrity, not spreadsheets
ITILv4-aligned incident and change management
Real ITIL incident depth: response and resolution SLAs, resolution and closure codes, watchers, parent and child links.
Before you make a change, Kovira runs a full upstream and downstream impact analysis. Pick a CI and you see every dependency, every service that could be affected, and every team that needs to know. Change approvals are gated to an independent reviewer: the person who created the change cannot approve their own work.
Incidents carry the fields ITIL practices call for: priority matrix, response and resolution SLA timers driven by per-customer policies and coverage windows, resolution category, closure code, who resolved it, watchers who get notified on updates, parent and child links for major events that group dozens of related tickets, and a postmortem document reference for major incidents. Reopens are tracked with a counter, so you can spot patterns instead of patching the symptom.
Every incident and change links back to the CIs it touches, so postmortems and audits run against current configuration rather than someone's recollection.
Key capabilities
- Response and resolution SLAs with per-customer policies
- Coverage windows per weekday, plus holiday calendars that pause the timer
- Resolution categories, closure codes, and resolved-by tracking
- Watchers, parent and child incident linking, and reopen counters
- Postmortem document references on major incidents
- Independent change approvals: the creator cannot self-approve
ITSM workflow automation
Visual builder, broad trigger surface, real action library, full execution audit.
Kovira ships a visual workflow builder for multi-step approvals, conditional branches, delayed steps, retries, and quantified checks across collections of CIs. The trigger surface covers what IT teams wire up: CI changes, incident lifecycle events, SLA events (at risk, breached, paused, resumed), scheduled intervals, manual dispatch, and incoming email when a monitored mailbox is connected.
The action library is wide enough that everyday automation stays inside the platform. Send email through a managed sender, update CIs, create incidents, transition SLA timers, call any external webhook, and run data transforms (regex extract, string operations, JSON shape) over the run scope, so later steps act on cleaned-up values rather than raw payloads. Failed actions retry on a backoff, and concurrency controls stop the same workflow firing twice on one event.
Built-in system workflows cover the notifications you expect: ticket created, ticket assigned, SLA at risk, and SLA breach all email the right people without any setup. Every run produces a per-step execution log with input, output, and error captured, so you can trace what happened and why.
Key capabilities
- Triggers: CI changes, incidents, SLA events, schedules, incoming email, manual dispatch
- Actions: send email, update CI, create incident, webhook, SLA pause/start/stop/reset, data transforms
- Data transforms: regex extract, string operations, JSON shape, applied to the run scope
- Built-in system workflows for ticket and SLA notifications, ready out of the box
- Conditional branches, quantified checks, delayed steps, retry on backoff
- Per-step execution log with input, output, and error captured
Mailbox to ticket: turn shared inboxes into a ticket pipeline
Connect a support@ mailbox and email becomes incidents, replies thread, automation kicks in.
Connect a Microsoft 365 user or shared mailbox and every new message raises an incident in Kovira. Replies from the requester or from technicians thread back onto the original incident as comments, with attachments and inline images preserved. Conversation matching uses Microsoft's native conversation identifier, standard email threading headers, and a normalised subject fallback, so threads do not split when someone strips the ticket reference from the subject line.
Access is scoped per mailbox to the minimum read permission and revocable from the Microsoft 365 admin centre at any time. There is no tenant-wide admin grant. Change notifications come in close to real time, so an email landing in the inbox produces an incident within seconds, not on a polling cycle. The incoming-mail workflow trigger then fires whatever automation you have wired up: assign by routing rules, set priority by sender domain, send an acknowledgement, populate fields from the email body, escalate, or chain into your existing approval flow.
Loop prevention is built in. Auto-replies, bounce notifications, and Kovira's own outbound mail are detected and skipped, so you do not get a feedback loop the first time someone forwards a vacation responder.
Key capabilities
- Scoped per-mailbox access, no tenant-wide admin grant required
- New mail becomes an incident within seconds, not on a polling cycle
- Native Microsoft 365 reply threading with subject fallback
- Attachments and inline images preserved on the incident
- Incoming-mail workflow trigger for routing, acknowledgements, and escalation
- Automatic loop prevention for bounces, autoresponders, and our own replies
- Mailbox count by plan: 1 on Teams, 3 on Business, 5 on MSP
Reports, dashboards, and durable scheduled delivery
Build from live operational datasets and deliver the result in the format and channel each audience needs.
Kovira's report builder works over the same tenant-scoped datasets that power the application: CIs, incidents, changes, SLAs, availability, continuity, risks, suppliers, PSA metrics, customer health, audit evidence, and more. Filter and shape the data once, save it as a report, or combine reusable reports into a dashboard.
Two scheduling surfaces cover different jobs. Saved report and dashboard schedules handle presentation-ready PDF and CSV delivery. Dataset subscriptions deliver filtered raw data as PDF, CSV, Excel, or NDJSON and can fan the same occurrence out to confirmed email recipients, a configured Slack channel, and a configured Microsoft Teams channel.
Every subscription occurrence is claimed atomically, rendered once per durable run, and recorded with per-channel outcomes, byte and row counts, and a short failure reference. Cron evaluation is timezone- and daylight-saving-aware. Lost worker responses reclaim the same run and provider idempotency key instead of silently creating a second email.
Key capabilities
- Tenant-scoped datasets spanning CMDB, ITSM, L2, governance, and PSA
- Reusable reports, resizable dashboards, SLA analytics, and PSA metrics
- PDF, CSV, Excel, and NDJSON dataset attachments
- Confirmed-recipient email gate prevents open-relay abuse
- Native Slack Block Kit and Microsoft Teams Adaptive Card previews
- Timezone-aware cron with durable claims and per-destination run history
VECTOR network scanner and ATLAS endpoint agents
Automated discovery from the network and every endpoint, with real physical topology.
Point VECTOR at a subnet and it finds the devices, maps how they connect, and keeps your CMDB current. Routers, switches, firewalls, servers, workstations, printers, and IoT all surface as CIs, with no agent required on the scanned devices.
VECTOR also pulls the Layer 2 evidence most network tools skip: LLDP and CDP adjacencies, local and remote switchports, VLAN membership, access and trunk roles, LAG membership, link speed and state, spanning-tree root and port state, and MAC presence. Optional read-only SNMP adds standards-backed chassis and software inventory, environmental sensors, PoE state, 802.1X sessions, and LACP actor, partner, and aggregator evidence. The interactive graph can isolate L2 or L3, colour by VLAN, switch between force, radial, tree, and STP layouts, and open the underlying CI without leaving topology context.
Each VECTOR publishes itself into the CMDB as a device CI when it registers. Other VECTOR instances receive that CI identity with the peer's observed endpoint and public identity keys, allowing them to recognise the scanner, establish an authenticated peer channel, measure the path between sites, and report the resulting WAN relationship back to Kovira.
ATLAS covers the endpoint side. It runs on Windows and Linux machines and reports hardware specs, installed software, and security posture, so endpoint inventory stays accurate without anyone chasing it. Both VECTOR collectors and ATLAS endpoints can be paused, resumed, or uninstalled centrally from the workspace, and heartbeats flag any agent that goes silent. Both are included in every plan, including the free tier.
Key capabilities
- Physical topology with port-level connectivity
- VLAN, trunk, LAG, link-state, and spanning-tree evidence
- SNMP inventory, sensor, PoE, 802.1X, and LACP evidence
- Dedicated L2, L3, VLAN-colour, and STP graph views
- Device-to-port presence intelligence from managed switches
- Find any device on the network instantly
- Every VECTOR publishes a linked device CI for discovery and audit
- Authenticated VECTOR-to-VECTOR discovery and WAN peering
- Hardware, software, and security posture from ATLAS endpoints
- Pause, resume, and uninstall agents centrally
- Heartbeats flag anything that goes quiet; Windows and Linux support
Same device, one record
Kovira knows when two sources are describing the same thing.
A single server can show up in a VECTOR scan, an ATLAS agent check-in, and an import from another tool. In most CMDBs, that lands as three records you have to untangle by hand.
Kovira normalises each supported strong identity before matching: serial numbers and asset tags ignore presentation case and whitespace, globally administered unicast MAC addresses use one canonical form while local, multicast, and placeholder addresses are excluded, and SSH host keys remain case-sensitive. Resolution is scoped to both tenant and customer, so a valid identifier reused by two customers cannot cross the boundary.
The uniqueness claim lives in PostgreSQL, not only in an integration handler. Concurrent VECTOR, ATLAS, Microsoft 365, or API writes cannot create two active owners for the same strong identity. A unique match attaches the new source to the canonical CI; multiple legacy owners are reported as ambiguous instead of guessed. Archive releases an identity, while restore must reacquire it. The source of every field remains visible through provenance.
Key capabilities
- Serial, asset tag, globally administered unicast MAC, and SSH host-key identity
- Tenant- and customer-scoped database uniqueness
- Race-safe under simultaneous writers
- Works across VECTOR, ATLAS, and Microsoft 365
- Ambiguity is surfaced; Kovira never guesses
- Deterministic source authority with field provenance
- Archive and restore preserve identity ownership correctly
Microsoft 365 integration
Sync users, groups, and devices from Entra ID and Intune.
If you are running Microsoft 365, Kovira can pull your users, security groups, directory roles, and managed devices straight from Entra ID and Intune. The sync runs in the background, so your CMDB stays current without anyone having to manually update records when someone joins, leaves, or gets a new laptop.
The data flows into the same CI model as everything else, which means you can see an employee, the device they are using, the groups they belong to, and the services they have access to, all in one place. Synced records are correlated with VECTOR and ATLAS data automatically.
Key capabilities
- Users, security groups, and directory roles from Entra ID
- Managed devices from Microsoft Intune
- Background sync
- Data appears as native CIs alongside other assets
- Automatic correlation with VECTOR and ATLAS data
Built-in documentation linked to your CIs
Runbooks, SOPs, postmortems, and architecture docs next to the assets they describe.
Every IT team has runbooks, standard operating procedures, and architecture documentation sitting in a shared drive somewhere, disconnected from the systems they describe. Kovira has a full document editor built in with structured content blocks: rich text, code, tables, checklists, images, callouts, and embedded diagrams.
Documents can be linked directly to CIs, so when you are looking at a server and wondering how to restart a service on it, the runbook is right there. Postmortem documents link to incidents, so the major-incident review lives next to the ticket it came from. Collaborative editing is supported with author locking, so multiple people can work on the same document without overwriting each other.
Key capabilities
- Rich document blocks for any kind of content
- Link documents directly to any CI
- Postmortem document references on major incidents
- Collaborative editing with author locking
- Version history on every document
- Structured authoring built for IT teams
Tenant isolation, role-based access control, and recycle bin
Database-level isolation, per-member RBAC overrides, and a soft-delete safety net for CIs.
Tenant isolation is enforced at every layer of Kovira. Every organisation's data is separated at the database level, and the application layer applies tenant context to every query. There are no admin backdoors, no shared tables, and no path for one tenant's data to reach another's. On the MSP plan, the same isolation extends across many client workspaces in one account: each workspace stays fully separated while technicians switch between them without logging out.
Role-based access control gives you four base levels (Owner, Admin, Editor, Viewer) plus per-member overrides for the cases that do not fit a role cleanly. A specific user can be granted a permission above their role or have one revoked below it without changing the role itself, so you can keep the model clean and still handle the contractor who needs read-only access to one workspace section.
Deleted configuration items move into a recycle bin instead of being removed outright. From there you can restore the record back to its prior state or purge it permanently when you are sure. Recycled CIs do not count against your plan’s CI limit while they sit in the bin.
Key capabilities
- Row-level security policies at the database level
- Tenant-scoped queries on every single request
- Four base RBAC roles plus per-member permission overrides
- Recycle bin with restore or permanent purge for deleted CIs
- Switch between workspaces without logging out (MSP plan)
- No shared tables, no backdoors, no data leakage
Complete audit trail for compliance
Every action logged. Always on. Cannot be disabled.
Every action that anyone takes in Kovira is logged: every CI creation, every field edit, every status change, every login, every permission check, and every workflow execution. The audit log captures who did it, what they did, when they did it, and from where. This is not optional and cannot be turned off.
For teams that need to pass compliance audits, whether that is ISO 27001 or just your own internal governance requirements, the audit trail provides the evidence you need without having to build a separate reporting system. Logs are filterable by date, user, action type, and CI, and can be exported for external review.
Key capabilities
- Who, what, when, and where for every action
- CI edits, logins, permission checks, and workflow runs
- Ready for ISO 27001 and governance audits
- Filterable by date, user, action type, and CI
- Exportable for external review
ITILv4 CMDB tool built for practice, not theory
Structured around the ITIL practices that matter most.
Kovira is structured around the ITIL practices that matter most to growing IT teams: Service Configuration Management, Change Enablement, Incident Management, Problem Management, IT Asset Management, and Service Request Management.
This is a purpose-built ITSM tool, not a generic project manager with ITIL labels added on top. The data model, the workflows, the permission structure, and the reporting are designed around how ITIL works in practice. If you are working towards ITIL maturity, or you already follow ITIL and need a CMDB tool that keeps up, Kovira is built for that.
Key capabilities
- Service Configuration Management with full CI lifecycle
- Change Enablement with impact analysis and approval workflows
- Incident Management with SLA tracking and CI linking
- IT Asset Management across every category
- Purpose-built data model, not generic project management
Complete platform map
The rest of Kovira, without the vague feature checklist
Kovira extends well beyond the headline CMDB. This catalogue is maintained against the authenticated application so public claims stay aligned with shipped product surfaces.
Service management
Operate the full lifecycle of work, service health, and improvement.
- Incidents
- Priorities, ownership, watchers, SLA timers, major-incident links, resolution, and closure.
- Problems
- Root-cause records, known errors, workarounds, linked incidents, and corrective actions.
- Changes & releases
- Impact analysis, approvals, CAB controls, blackout windows, calendars, and release coordination.
- Service requests
- A configurable request catalogue, fulfilment records, approvals, and customer-facing intake.
- SLA management
- Policies, business hours, targets, operational agreements, escalation, and breach reporting.
- Queue, dispatch & on-call
- Assignment rules, round-robin groups, skills, availability, schedules, and escalation paths.
- Customer satisfaction & CSI
- Post-resolution surveys, CSAT reporting, improvement initiatives, and tracked actions.
Configuration, discovery & resilience
Maintain an evidence-backed model of infrastructure, services, and dependencies.
- Typed CMDB
- Purpose-built CI types, custom types and fields, lifecycle states, versions, rollback, and recycle bin.
- Relationship graphs
- Typed dependencies, linked-CI views, impact direction, reverse lookups, and database-enforced endpoint integrity.
- Layer 2 topology
- LLDP and CDP adjacencies, switchports, VLANs, trunks, LAGs, STP root and port state, MAC presence, standards-backed SNMP inventory and port evidence, and L2 anomaly triage.
- VECTOR discovery
- Network scanning, chassis, software, sensor, PoE, 802.1X, LACP, port and MAC observations, scanner-as-CI publication, public peer identity, and authenticated WAN peering.
- ATLAS inventory
- Endpoint hardware, software, security posture, telemetry, check-ins, and central lifecycle control.
- Microsoft 365
- Entra ID and Intune sync, policy drift, tenant posture, permission gaps, and sync history.
- Correlation & data quality
- Tenant- and customer-scoped serial, asset-tag, globally administered unicast MAC, and SSH identity claims; deterministic source authority; ambiguity review; provenance; and quality thresholds.
- Capacity, availability & continuity
- Growth forecasts, service targets, outages, BIAs, recovery plans, drills, and compliance evidence.
Automation, insight & knowledge
Turn operational data into repeatable actions, decisions, and shared context.
- Visual workflows
- Event and schedule triggers, conditions, approvals, delays, retries, data transforms, webhooks, and execution logs.
- Reports & dashboards
- Dataset-driven reports, reusable dashboards, SLA and PSA analytics, PDF/CSV/XLSX/NDJSON exports, and durable timezone-aware delivery to confirmed email recipients, Slack, or Microsoft Teams.
- Business intelligence
- Operational summaries, trends, utilisation, margins, ageing, and configurable analytics views.
- Documents & knowledge base
- Rich documents, CI links, version history, moderation, searchable articles, and customer knowledge.
- Architecture & design
- Capabilities, architecture decisions, reference architectures, technology radar, blueprints, and test runs.
- Activity & collaboration
- Audit-backed activity, comments, mentions, optimistic editing, and realtime presence where supported.
Commercial & customer operations
Connect service delivery to customers, suppliers, projects, and financial outcomes.
- CRM
- Leads, contacts, opportunities, activities, pipelines, forecasts, and customer context.
- Quotes, agreements & invoices
- Templates, approval thresholds, signatures, revisions, agreements, billing, tax, and receipts.
- Expenses, time & parts
- Expense evidence, approvals, time entry, stock, movements, and operational costing.
- Projects & portfolio
- Projects, tasks, milestones, members, portfolio review, prioritisation, and return analysis.
- Customer onboarding
- Reusable playbooks, phased runs, assignments, progress, and customer-specific delivery.
- Supplier management
- Supplier records, performance, risk, renewals, audits, sub-processors, and service obligations.
Administration, security & governance
Control access, integrations, risk, compliance, and workspace operations.
- Members, roles & access
- Invitations, offboarding, groups, role matrices, per-member overrides, inactivity review, and access reviews.
- Authentication & provisioning
- MFA, passkeys, recovery codes, SSO policy, sessions, delegated access, and SCIM tokens.
- Integrations & developer platform
- Agent keys, public API keys, webhooks, Microsoft 365, Slack, Teams, cloud connectors, and marketplace setup.
- Security & risk
- Security incidents, policies, controls, exceptions, risks, mitigations, and evidence-linked governance.
- Compliance & audit
- Hash-chained audit events, search, exports, control mapping, evidence collection, residency, and retention controls.
- Workspace controls
- Branding, billing, usage, currency, tax, data import/export, monitored mailboxes, probes, and error operations.
Every screen, light and dark
These are real captures of the product, not mockups. Toggle any frame between light and dark, or click to enlarge.
CMDB & Assets
6 screensService delivery
5 screensAutomation
1 screenMicrosoft 365
2 screensIntelligence
3 screensGovernance
3 screensFinance & Sales
1 screenRelated
Every configuration item Kovira models
Purpose-built CI types covering devices, networks, services, racks, locations, SLAs, contracts, vendors, password vaults, and more. Each type has typed columns in the schema, dependency mapping, version history with rollback, and workflow triggers.
See every CI typeBe ready to see it in action
Kovira is launching soon. The free tier will include the full CMDB, VECTOR scanning, and ATLAS agents. Microsoft 365 sync and higher limits come with Teams and up.