AssetHandler
CMDB and Cloud Reconciliation Queue
Matches discovered resources and devices to configuration items and turns every gap into an owned decision: create, retire, merge or assign.
Works with AdapterCloud, FluidGrids
Industry solution
Know what you run, what it costs, and who fixes it when it breaks
Inventory, CMDB, licenses, cloud spend, patching and on-call, joined up for infrastructure teams and managed service providers.

The problem
The estate lives in several clouds, a colocation cage, dozens of SaaS admin panels and a CMDB nobody trusts. Every question about cost, ownership or blast radius starts days of spreadsheet archaeology.
Many infrastructure teams now run across more than one public cloud, several Kubernetes clusters, a colocation or on-prem footprint and a long tail of SaaS tenants. Each has its own console, its own identity model and its own bill. The inventory is a spreadsheet exported last quarter, and the CMDB was accurate the week it was loaded. When a change goes wrong, the first half hour of the incident is spent working out what depends on what.
Spend and licensing have drifted out of IT's hands. Engineers create resources in minutes, teams buy SaaS on corporate cards, and renewals roll over on notice periods nobody tracked. FinOps practitioners chase untagged spend line by line, and software asset managers rebuild an effective license position by hand every time a vendor sends an audit letter.
Managed service providers carry all of this multiplied by every client, usually on fixed-fee contracts with thin margins. Their engineers switch between client estates all day, patch windows stack up after every critical advisory, and the quarterly business review is assembled from five exports the night before. The individual tools are rarely the problem; the gaps between them are.
Head of infrastructure or platform
One live inventory and dependency map across clouds, clusters and on-prem, so change risk and ownership are answers rather than guesses.
MSP service delivery director
Forty client estates run with one operating model, clean separation between clients, and SLAs and hours visible per client.
FinOps lead or cloud cost owner
Spend attributed to resources and owners, untagged cost shrinking, and a month-end showback that budget holders accept.
IT and software asset manager
A CMDB that matches reality, a license position ready before the true-up, and seats reclaimed soon after a leaver exits.
SRE or on-call engineer
Runbooks that find you at 3 a.m., a safe way to pull in a senior engineer, and patch windows that do not end in pages.
IT security and compliance lead
Shadow IT found before it holds sensitive data, drift and waivers with a reason on record, and one audit trail across tools.
A day in the life
Nadia's team looks after about forty client estates: three public clouds between them, two colocation cages, hundreds of Windows and Linux servers and more SaaS tenants than anyone has counted. Her engineers are good. What wears them down is the space between systems: discovery that disagrees with the CMDB, the license spreadsheet, the cloud bill nobody can explain, and the runbook that lives in a former colleague's head. This is one ordinary week.
Monday, 07:40
Kestrel Bay takes over Larkspur Freight's estate today. The previous provider's handover sheet lists 212 servers and two cloud accounts. By mid-morning the team has found a third account paying for a forgotten analytics cluster, and a database server the CMDB marks Operational that was switched off in the spring. Nobody can say which applications depend on the storage array due for replacement next month.
How this is solved: A CMDB and inventory that match what is actually runningMonday, 14:10
Fernhall Legal forwards a letter from its productivity-suite vendor asking for a license count within thirty days. The same afternoon its finance lead sends an expense export with fourteen recurring SaaS charges IT has never seen. One of them is a file-sharing tool holding client documents, and three people who left in July still hold paid seats in it.
How this is solved: Licenses, renewals and shadow IT with one owner eachTuesday, 09:05
Calloway Dental Group's finance director emails a screenshot: the August cloud invoice is well above July's. A large share of the spend carries no cost-center tag, shared networking is split by a formula nobody remembers, and the question on the call is simple and awkward: which team caused this, and was it the MSP's change?
How this is solved: Cloud spend attributed to the teams and clients who drive itWednesday, 21:30
A critical advisory for a widely used Linux library landed on Tuesday, and every client wants it closed before the weekend. The team has a change window from 22:00 to 02:00 for about 300 Linux servers across nine clients, each of which approves its own change. The plan is a spreadsheet, approvals sit in nine email threads, and the second wave stalls when a server rejects the patch because someone hand-edited its configuration last month.
How this is solved: Patch windows that follow an approved plan, wave by waveThursday, 03:12
Larkspur's order API starts timing out. The on-call engineer, Tomasz, is in his second week and has never worked on this estate. The runbook exists somewhere in a shared drive. He needs to know what sits behind the API, whether last night's patch touched it, and how to get a senior engineer onto the same terminal without passing credentials around in chat.
How this is solved: On-call that starts with the runbook and the dependency mapFriday, 16:00
Quillon Parts, a client for six years, has its quarterly business review on Monday. Nadia needs hours used against the support block, SLA performance, incidents and changes, cloud spend against budget, and the warranties and support contracts expiring next quarter. In past quarters an account manager spent a day stitching five exports into slides, and the client still asked where the numbers came from.
How this is solved: Client service reviews built from the record, not the night beforeNone of this is exotic. It is the normal texture of running infrastructure for other people. The idea behind the solution is that each of these moments starts from the same governed picture of the estate, and each product hands the next one something concrete instead of another spreadsheet.
Challenges and how they are solved
Each challenge shows the problem as it happens, how the products are designed to hand work to each other, and the concepts that illustrate it. Share any challenge on its own.
Challenge 1 of 6
An MSP onboards a new client, or an infrastructure team inherits an acquisition. The handover documentation is a spreadsheet from the previous provider, and discovery soon turns up cloud accounts nobody listed and servers the CMDB still shows as live long after they were switched off. Configuration items have no owners, dependencies were never recorded, and nobody can say what relies on the storage or network gear due for replacement. Every change, incident and audit that follows inherits the uncertainty.
Changes are approved against a CMDB that is wrong, incidents start with guesswork about dependencies, and orphaned resources keep billing for months.
AdapterCloud is designed to connect to each cloud account, cluster and on-prem target and keep a unified resource inventory and dependency topology current through discovery and reconcile runs. AssetHandler's own network discovery jobs cover on-prem subnets, so both sources feed the same queue. AssetHandler stays the system of record for configuration items, owners, hardware lifecycle and change history. The two are designed to meet in a reconciliation queue: each discovered resource is matched against a configuration item, and each mismatch becomes a decision to create, retire or merge a CI, or to assign an owner, with AdapterCloud's topology showing what still depends on it. FluidGrids can route unowned items to the owning team as tasks and re-run the check on a schedule.
Designed to give every change, incident and audit a CMDB that reflects the running estate, with each correction attributed to a named person.
AssetHandler
Matches discovered resources and devices to configuration items and turns every gap into an owned decision: create, retire, merge or assign.
Works with AdapterCloud, FluidGrids
AdapterCloud
Supplies the live cloud side of the comparison: every discovered resource across every connection, with state, region, tags, cost and last-seen time.
AdapterCloud
Shows what depends on the storage array or database in question, so retiring or replacing a configuration item is checked against real dependencies first.
Challenge 2 of 6
Vendor audit letters arrive with short deadlines, finance keeps finding recurring SaaS charges IT never approved, and leavers keep paid seats, and sometimes access to sensitive files, until someone notices at renewal. The effective license position is rebuilt by hand for every audit, nobody owns the tools teams bought on corporate cards, and notice periods pass unseen, so unwanted renewals lock in for another year.
Over- and under-licensing both cost money, unsanctioned tools hold sensitive data outside IT's controls, and leavers keep access and seats long after they exit.
Subscriber Bot is designed to be the system of record for recurring relationships: it brings SaaS subscriptions, renewal dates, notice periods, payment instruments and invoices into one portfolio, and is designed to surface unrecognized recurring spend as shadow-IT candidates for review. AssetHandler holds the installed-software and entitlement side, comparing seats purchased with seats used to produce a license position for the true-up. When a reviewer sanctions a tool in Subscriber Bot, it is designed to be registered in AssetHandler's software register with an owner and an entitlement count. When someone leaves, FluidGrids can run the offboarding workflow that removes access and hands the freed seats back to Subscriber Bot for a downgrade or cancellation before the notice period closes.
Designed to give IT one owner for every paid tool, a license position ready before the vendor asks, and seats reclaimed within days of a leaver's exit.
Subscriber Bot
Queues unrecognized recurring charges with owner, users, renewal date and data risk, then routes each one to sanction, consolidate or cancel.
Works with AssetHandler, FluidGrids
AssetHandler
Compares entitlements with seat usage per title, so the answer to a vendor audit is a report rather than a week of reconciliation.
Challenge 3 of 6
The month closes and a budget holder, or an MSP client's finance director, asks why the cloud invoice jumped. A large share of spend carries no cost-center tag, shared networking and platform costs are split by a formula nobody remembers, and last quarter's rightsizing list was never actioned because no one owned the resources on it. The FinOps analyst exports billing data into a spreadsheet to answer the only question that matters: which team drove this, and was it a change someone made on purpose?
Budget holders dispute allocations they cannot trace, untagged spend keeps growing, and savings conversations stall because nobody owns the resource.
AdapterCloud ingests cost records against the same resources it discovers, so spend sits on the topology rather than on a service line, and a tagging policy is designed to flag resources missing a cost-center tag as violations with owners. Its showback view is designed to allocate spend to cost centers or clients by tag, split shared costs by a stated rule and keep unallocated spend visible as its own line. A FluidGrids workflow then pushes the published allocation into BigConsole data sinks on a schedule, where each budget holder is designed to see only their own slice and ask what changed, with the answer citing the resource and period behind it.
Designed so every budget holder sees spend they can trace to a resource, and untagged spend becomes a shrinking queue rather than a monthly argument.
AdapterCloud
Allocates the month's spend to cost centers or clients by tag, shows the shared-cost rule, and keeps untagged spend visible with a queue to fix it.
Works with BigConsole, FluidGrids
AdapterCloud
Ties each cost record to the resource it came from, and is designed to flag run-rate jumps so an anomaly arrives with its owner and dependents attached.
FluidGrids
Ends the monthly allocation workflow in a data sink node, so the numbers land in BigConsole on a schedule instead of in an email attachment.
Challenge 4 of 6
A critical advisory lands and every client or business unit wants it closed within days. The change window is a few hours overnight, the scope is hundreds of servers, the plan lives in a spreadsheet and approvals sit in separate email threads. Servers that were hand-edited months ago reject the patch mid-wave, and by the early hours nobody is sure which servers are done, which rebooted and which need rolling back, so the change record says one thing and the estate another.
Windows overrun, change records stop matching what was actually done, and configuration drift turns routine patching into an outage risk.
AssetHandler holds one change request per client: scope as configuration items, risk, window and each reviewer's approval. Before the window opens, AdapterCloud's drift records show which servers have diverged from their desired configuration, so they are fixed or excluded first. VibeControls is designed to run the approved changes as ordered waves on servers where its agent is installed, pilot first and then broad, using pre-approved Vibe Deck actions and Vibe Calendar scheduled tasks, pausing the next wave when failures pass a threshold and logging every command. Wave results are designed to be written back to each AssetHandler change request, and FluidGrids can raise follow-up tasks for servers that were skipped or rolled back.
Designed so a patch night ends with change records that match reality: which servers were patched, skipped or rolled back, by whom and when.
VibeControls
Runs the approved changes as pilot and broad waves across agents, with per-server status, a failure threshold that pauses the next wave and a link to each client's change record.
Works with AssetHandler, AdapterCloud
AdapterCloud
Lists servers whose observed configuration differs from desired state before the window opens, so drift is fixed or excluded instead of found mid-wave.
Challenge 5 of 6
In the middle of the night a customer-facing service starts failing, and the engineer on call is new to that estate. The runbook is somewhere in a shared drive, monitoring shows the symptom but not the dependencies, and nobody can say quickly whether last night's change touched the database behind it. Pulling in a senior engineer means sharing a screen over a call or passing credentials around in chat, and the fix rarely makes it back into the runbook for the next person.
Engaging the right person takes too long, newer engineers escalate by default, and credential sharing mid-incident leaves no clean audit trail.
Botlit is designed to run an on-call assistant in the team's chat channel, grounded in the runbooks and known-error articles AssetHandler keeps in Botlit knowledge bases, answering with the passages it used and saying plainly when nothing matches. AdapterCloud's topology shows what sits behind the failing service and which of those resources changed or drifted recently. When the engineer needs help, VibeControls shares the live terminal session with a senior colleague through an expiring link with a clear viewer or interactive role, so nobody hands over passwords. Botlit can trigger a FluidGrids workflow that opens the incident record in AssetHandler, and the eventual fix goes back into the runbook.
Designed to put a newer engineer in front of the right runbook, the right dependencies and the right colleague within minutes, with every step on the audit trail.
Botlit
Answers the on-call engineer from the team's runbooks and known errors, and is designed to show the passages it used and to say so when nothing matches.
AdapterCloud
Shows the database, cluster and network path behind the failing service, with drifted edges highlighted, so the first question already has an answer.
VibeControls
Brings a senior colleague into the same terminal through an expiring link with a visible handover of control, instead of shared credentials.
AssetHandler
Holds the incident record the workflow opens, with priority, SLA flag and owner, so the fix and the runbook update land on one record.
Challenge 6 of 6
Every quarter each client expects a business review: hours used against the support agreement, SLA performance, incidents and changes, cloud spend against budget, and the hardware and contracts reaching end of life. Each figure lives in a different tool, so account managers lose a day per client stitching exports into slides, and clients still ask where the numbers came from and how their data is kept apart from other clients'.
Review prep eats senior time, figures are challenged because they cannot be traced, and scope creep on fixed-fee contracts goes unnoticed until renewal.
TimeCampus captures engineers' time against client projects with an hour budget, for example a 400-hour support block set up as a project budget, with consent and without surveillance. AdapterCloud provides the client's cloud spend and open policy violations, and AssetHandler provides incidents and changes with their SLA results, plus the warranties and support contracts expiring next quarter. FluidGrids workflows are designed to pull each of these into BigConsole data sinks, where one review console template is stamped out per client and is designed so each console reads only that client's rows. The account manager shares a read-only link or exports the pack, and every figure names the product it came from.
Designed to turn review prep from a day of exports into a check of one console per client, with figures the client can trace to their source.
BigConsole
One review console per client from a shared template: hours against budget, SLA, incidents, cloud spend and lifecycle, each tile naming its source.
Works with TimeCampus, AssetHandler, AdapterCloud
TimeCampus
Keeps tracked hours per client project with a regenerable share link, so the client can see hours used between reviews.
How it fits together
Discovery feeds the record, the record gates change, change and response feed the numbers, and the numbers go back to the people who own them. Each step is one product doing one job and handing the next a concrete item.
To AssetHandler: Resources with no matching configuration item are designed to go to the CMDB reconciliation queue.
To AssetHandler: Sanctioned tools are designed to be registered as software assets with an owner and an entitlement count.
To VibeControls: An approved change request is designed to become a wave plan.
To AssetHandler: Wave results are designed to be written back to the change record; skipped servers and rollbacks go to FluidGrids for follow-up tasks.
To FluidGrids: A request to open an incident record in AssetHandler and notify the owning team.
To FluidGrids: Monthly hours per client project, designed to feed the reporting workflow.
To BigConsole: Governed data sinks for cost allocation, service performance and client hours.
Step 1 of 8: Discover and cost the estate
Products in this solution
Estate inventory, topology, drift and cloud cost
Is designed to connect cloud accounts, clusters, on-prem and SaaS targets into one inventory and dependency graph, with policies, drift records and cost records attached to the same resources. It is the live picture the other products work from.
CMDB, change records and software licenses
The system of record for configuration items, hardware lifecycle, incidents, problems, changes and software entitlements, with network discovery jobs for on-prem subnets. It holds the ownership and history that cloud discovery alone cannot supply.
SaaS portfolio, renewals and shadow IT
Treats every subscription, license and contract as a relationship with a plan, renewal date, notice period and invoices, and is designed to surface recurring spend that IT did not know about.
Fleet operations, runbooks and shared sessions
Agents installed on servers run pre-approved Vibe Deck actions and Vibe Calendar jobs, Plan mode puts AI-proposed work behind a human review, and terminal sessions can be shared through expiring links, all under one audit log.
Workflows and data feeds between products
Visual workflows route mismatches, offboarding steps and follow-up tasks between products, and data sink nodes push allocations, tickets and hours into BigConsole on a schedule.
On-call and service desk assistant
Governed agents in the team's chat channels are designed to answer from runbooks and known errors with cited passages, and can trigger workflows such as opening an incident record.
Showback and client review consoles
Console templates are stamped out per budget holder or per client, fed by governed data sinks, with sharing controls and row separation designed so each viewer sees only their own slice.
Time against client projects
Captures engineers' time against client projects with an hour budget, with consent and without surveillance, keeps team load visible only in aggregate, and gives each client a share link to their hours.
All eight products run on Burdenoff Workspaces: one sign-on, role-based access, one audit trail and one bill. Each client estate lives in its own workspace, so access and audit stay separate, while the MSP's operations workspace is designed to give engineers a cross-client view of assigned work.
Concept gallery
15 concepts from 8 products. Each one links to its own page on the product's website, and every view has a link you can share.
AssetHandler
Matches discovered resources and devices to configuration items and turns every gap into an owned decision: create, retire, merge or assign.
Works with AdapterCloud, FluidGrids
AdapterCloud
Supplies the live cloud side of the comparison: every discovered resource across every connection, with state, region, tags, cost and last-seen time.
AdapterCloud
Shows what depends on the storage array or database in question, so retiring or replacing a configuration item is checked against real dependencies first.
Subscriber Bot
Queues unrecognized recurring charges with owner, users, renewal date and data risk, then routes each one to sanction, consolidate or cancel.
Works with AssetHandler, FluidGrids
AssetHandler
Compares entitlements with seat usage per title, so the answer to a vendor audit is a report rather than a week of reconciliation.
AdapterCloud
Allocates the month's spend to cost centers or clients by tag, shows the shared-cost rule, and keeps untagged spend visible with a queue to fix it.
Works with BigConsole, FluidGrids
AdapterCloud
Ties each cost record to the resource it came from, and is designed to flag run-rate jumps so an anomaly arrives with its owner and dependents attached.
FluidGrids
Ends the monthly allocation workflow in a data sink node, so the numbers land in BigConsole on a schedule instead of in an email attachment.
VibeControls
Runs the approved changes as pilot and broad waves across agents, with per-server status, a failure threshold that pauses the next wave and a link to each client's change record.
Works with AssetHandler, AdapterCloud
AdapterCloud
Lists servers whose observed configuration differs from desired state before the window opens, so drift is fixed or excluded instead of found mid-wave.
Botlit
Answers the on-call engineer from the team's runbooks and known errors, and is designed to show the passages it used and to say so when nothing matches.
VibeControls
Brings a senior colleague into the same terminal through an expiring link with a visible handover of control, instead of shared credentials.
AssetHandler
Holds the incident record the workflow opens, with priority, SLA flag and owner, so the fix and the runbook update land on one record.
BigConsole
One review console per client from a shared template: hours against budget, SLA, incidents, cloud spend and lifecycle, each tile naming its source.
Works with TimeCampus, AssetHandler, AdapterCloud
TimeCampus
Keeps tracked hours per client project with a regenerable share link, so the client can see hours used between reviews.
Pitch kit
Infrastructure teams and MSPs lose their week in the gaps between tools: discovery that disagrees with the CMDB, licenses in spreadsheets, cloud bills nobody can explain, patch plans in email and runbooks nobody can find at 3 a.m. Burdenoff brings eight products together on one governed picture of the estate, so each of those moments starts from the same record and hands the next team something concrete.
Questions
Not necessarily. The solution is designed to sit alongside the tools you already run. AdapterCloud models other systems through adapters, and FluidGrids workflows can move data between Burdenoff products and external systems through connectors, webhooks and an API. Many teams would start with one gap, such as CMDB reconciliation or SaaS renewals, and extend from there.
Each client estate lives in its own workspace, so access and audit stay separate. Every Burdenoff product is workspace-scoped, with role-based access on every operation and one audit trail. The MSP's own operations workspace is designed to give engineers a cross-client view of work they are assigned to, such as a patch night, and the BigConsole review template is designed to be stamped out per client so each console reads only that client's rows.
The products are pre-launch or early, and this page describes a solution concept. Several surfaces shown here, including the CMDB reconciliation queue, cloud showback, patch waves and the client review console, are proposed designs. The integrations the products document are FluidGrids data sinks feeding BigConsole and Botlit agents querying dashboards and triggering workflows, and those are still being completed; the other hand-offs describe how the products are designed to work together.
The design keeps people in charge of consequential actions. Botlit is designed to answer with cited sources and say when nothing matches; VibeControls can require a human-approved plan before AI-proposed commands run; Subscriber Bot agents are designed to propose renewals and cancellations for a person to approve. Every action runs under a named identity and lands in the audit trail.
No. TimeCampus is built to be privacy-first: it captures work context with consent rather than surveillance, and team views are aggregate. For an MSP the useful output is hours against client projects and a team-level view of load, not a record of what each person does minute by minute.
Wherever the pain is sharpest. Teams with an untrusted CMDB often start with AdapterCloud discovery reconciled against AssetHandler. Teams facing a vendor audit or a heavy renewal season start with Subscriber Bot and AssetHandler licenses. MSPs often start with client review consoles, which grow richer as each other product is connected.
Related domains
Challenges solved
A solution concept for B2B software companies: eight Burdenoff products that link what sales promises, what engineering ships, what customers ask in-app and who may churn.
Challenges solved
A solution concept for security operations centers, intelligence analysts and multi-agency teams that combines eight Burdenoff products, from fusion to partner release.
Challenges solved
A solution concept for carriers, ISPs and network operators: trace outages, keep sites powered, send qualified crews, catch network-driven churn and contain compromised routers.
Tell us about your setup. We will walk you through the products involved and scope a pilot around the challenge that hurts most.
This is a solution concept: it shows how Burdenoff products are designed to work together in this industry. The images are illustrations of the concepts, not screenshots of the actual products, and every name and figure in them is sample data.