Hackathon project · Team Ctrl+AI

Agentic Network Operations for MSPs

An AI orchestration layer that runs live network operations across every customer, every vendor, from natural language — with per-customer isolation and MCP-driven control over the real device APIs.

Multi-LLM Gemini · OpenAI · Claude Multi-vendor FortiGate · Cisco · Juniper · Huawei Multi-tenant per-customer isolation
See how it works Get in touch
reference architecture — request path
Geminireasoning
OpenAIreasoning
Claudereasoning
model-agnostic LLM layer
Agentic Orchestrationintent → plan → action → verify
tenant context · policy · guardrails
MCP Serverstool interface per capability
Tenant Aisolated creds
Tenant Bisolated creds
Tenant Cisolated creds
FortiGate
Cisco
Juniper
Huawei
live device & controller APIs
The MSP reality

One team, dozens of customers, every vendor at once

Managed service providers carry the operational load of many independent networks. The work is repetitive, the context-switching is constant, and the tooling rarely spans vendors cleanly.

01 / scale

Context-switching tax

Every customer has its own topology, credentials, and change windows. Engineers rebuild mental context on each ticket, and that time doesn't scale with headcount.

02 / vendors

No common interface

FortiGate, Cisco, Juniper and Huawei each speak a different CLI and API dialect. Cross-vendor work means cross-vendor expertise, per engineer, per shift.

03 / manual ops

Repetitive by hand

Reading state, correlating logs, drafting changes, validating them — the same motions repeated across every tenant, mostly typed by hand under time pressure.

The platform

An agent that operates the network, not just talks about it

Requests arrive in plain language. The orchestration layer resolves the tenant, builds a plan, and executes it against the real device APIs through MCP — then verifies the result before reporting back.

intent

Natural-language in

"Show blocked sessions on Customer B's edge firewall" or "add this address object to the guest policy" — no CLI syntax, no per-vendor recall.

action

Real API execution

The agent calls the actual FortiOS / vendor REST interfaces via MCP tools — reading state and making scoped changes, not producing config it can't apply.

verify

Check before it reports

Plan, act, then confirm the resulting state matches intent. The loop closes on verification rather than on a generated answer.

What it does

Operational surface

Capabilities span the day-to-day of network operations, delivered through MCP tool interfaces the agent can compose.

Configuration & policy

Read and modify firewall policy, address objects, interfaces and routing through scoped, auditable operations.

  • policy CRUD
  • address objects
  • interfaces
  • routing

Troubleshooting

Pull live state, correlate logs and sessions, and walk a structured diagnosis instead of a blank CLI prompt.

  • session state
  • log queries
  • interface status
  • connectivity checks

Observability & ChatOps

Surface metrics and alerts where the team already works, and drive investigations from chat.

  • Grafana
  • Webex
  • alert triage
  • metric queries

Workflow & ticketing

Tie operational actions to the systems of record so work is tracked, not lost in a chat window.

  • ClickUp
  • GitLab
  • Gmail
Coverage

Vendors & integrations

Live vendor support today, with an MCP integration surface that already reaches the surrounding operational tooling.

Network vendors

FortiGate / FortiOSlive
Ciscolive
Juniperlive
Huaweilive

MCP integration surface

FortiGateGrafanaWebex ClickUpGitLabGmail

Each integration is exposed as an MCP tool interface, so the agent composes across observability, ChatOps, ticketing and source control in a single workflow.

Model-agnostic

No lock-in at the reasoning layer

The platform treats the language model as a swappable component. Route by capability, cost, or availability without rewriting the operational logic underneath.

google

Gemini

Available as a reasoning backend in the same orchestration path.

openai

OpenAI

Interchangeable at the model layer, selected per workload.

anthropic

Claude

First-class support alongside the others, no privileged path.

Built for MSPs

Per-customer isolation

Every tenant is a boundary. Credentials, context and scope stay bound to the customer they belong to, so an action for one network can't reach another.

Isolated per-customer credentials and connection context
Operations scoped to a single tenant at execution time
No shared credential surface across customer networks
Tenant resolved up front, before any action is planned
Origin

From a hackathon build to a multi-vendor platform

Started as a single-vendor FortiGate automation concept and grew into a multi-LLM, multi-vendor, multi-tenant operations platform for managed service providers.

3
LLM providers, interchangeable
4
network vendors live
6
MCP integrations
1:N
team to tenants, isolated

Want to see it run?

Reach out to Team Ctrl+AI for a walkthrough of the platform and the architecture behind it.