Big News: Kosli’s achieves Series A milestone with Deutsche Bank as an investor - Read the announcement
New: Kosli Answers is here! AI-powered insights for compliance and security. Learn more →

CLOUD · Infrastructure change and drift detection

Control IaC pipelines.
Detect clickops and off-pipeline changes.

Kosli records every infrastructure change as evidence, so clickops and drift are flagged as non-compliance, with a provable history of your infrastructure.

Kosli turns infrastructure as code into change evidence. <br/>Track pipelines, statefiles and drift, continuously.

Kosli infrastructure change and drift detection diagram

Before

Infrastructure is meant to change only through an approved process, but people work around it. Skipping approvals, changing things by hand. Drift goes unnoticed until something breaks or an audit exposes it.

After

Every IaC change your pipeline makes is recorded as it happens. Anything that arrives another way has no provenance behind it, and the environment says so.

Governance Infrastructure

Infrastructure designed for cloud change and drift detection.

Governance Engineering applied to your infrastructure. Every infrastructure change is recorded, controls are automated with policy-as-code, producing a full audit trail and governance insight.

Record

Every infrastructure change recorded as a verifiable fact.

terraform-apply: attested

statefile: fingerprinted

actor: ci-pipeline

change: attributed

Control

Controls run as code, enforced automatically.

policy: pipeline-only:v2

clickops: alerted

drift: detected

exceptions: 1 justified

Prove

Compliance proven from a continuous record.

desired-vs-actual: reconciled

account-history: complete

as-of: any date

report: export

Improve

Infrastructure change insights from governance data.

clickops-rate: trending down

drift-hotspots: 2

governed-coverage: 87%

exceptions: recorded

Record every infrastructure change

Track and evaluate every change to infrastructure, whether from the pipeline, the laptop, or clickops.

  • Pipeline or out-of-band. A change your pipeline made carries its attestations. A change made around it carries none.
  • Plan, apply, and statefile. Every run records what it did and what it produced, fingerprinted and tied to the commit it came from.
  • Agents attributed too. When an agent runs Terraform, the change carries its identity like any other actor's.

Detect drift and clickops

Kosli snapshots statefiles as artifacts, detects missing provenance, and reports non-compliant changes.

  • Non-compliance you can action. A compliance transition fires Actions and webhooks, so the finding lands in Slack or your SIEM rather than in a log nobody reads.
  • Clickops detection. A detector runs plan against the last applied commit, so console and CLI changes surface on the next check instead of at the next incident.
  • Continuous drift status. The compliance status remains until the next successful apply, so one alert is enough and nobody drowns in repeats.

An audit trail for the infrastructure, not just the apps

Application changes get governed. Infrastructure changes get trusted.

  • One standard for apps and infrastructure. The same record, the same controls, and the same reporting for both.
  • Declared against actual, automatically. Prove your infrastructure matched what your IaC declared, on any day you are asked.
  • Coverage you can see. Know which parts of your infrastructure are governed and where coverage is thin.
Customers

Trusted in the most demanding environments.

Recording infrastructure change across large distributed architectures

Read the case studies
Kosli addresses the specific needs of software development teams that operate in highly regulated industries. We are delighted to partner and collaborate with Kosli to drive our vision of a highly efficient, transparent, and secure software development lifecycle.
Martin Reeves, Engineering Platforms and Practice Lead Deutsche Bank
Kosli has been a great partner — not just for the product, but for the end-to-end thinking around building well-governed processes.
Sean Langton, CIO Abu Dhabi Commercial Bank
Frequently asked

Questions you might be asking.

Still curious? Talk to us →

  • Terraform already detects drift.

    It detects the drift it can see. An apply made outside CI is invisible to it, and where plan does find drift, the result is output in a CI log nobody keeps. Kosli makes it evidence, in an append-only record with compliance state and history.

  • Does this replace our IaC tooling?

    No. Terraform, your pipelines, and your cloud accounts stay as they are. Kosli records and governs the changes they make, and the ones made around them.

  • What about console changes during an incident?

    That's what break-glass paths are for. The change is recorded, attributed, and justified. The emergency is in the record instead of being the gap in it.

Get started

Find out what changed
outside the pipeline.

Connect your infrastructure and see every change, and how it was made, from the first snapshot.

Watch it work, end to end

See the platform enterprise teams use to automate governance across build, release, and runtime.

Kosli in action