Identity & SSO
Who is this human, and what can they touch?Users, groups, OUs, enable/disable/reset.
Adobe Admin Console control plane via the User Management API (UMAPI) — users, user groups, group membership, identity types, and full snapshot/diff/apply round-trip for the resources most worth versioning.
CIAM users, tenants, rules, log streams.
Users, roles, keys, sessions — live, not Terraform-managed.
MFA tokens, bypass codes, device trust events.
Users, groups, hosts, HBAC/sudo rules.
Users, groups, OUs, suspend/unsuspend/sign-out everywhere.
Directory + device-bound identity for SMB IT.
Self-hosted OIDC/SAML realm + user ops.
Security awareness users, groups, phishing and training campaigns.
Generic LDAP search and group membership lookups.
Azure AD users, groups, sign-ins, enable/disable, revoke sessions.
find/list users + groups, suspend / unsuspend, reset MFA, reset password.
Users, apps, MFA, role management.
Ping Identity users, environments, apps, MFA.
Endpoints & MDM
Mostly absent from Terraform. Huge for IT.Apple Business Manager — org device pool and MDM server assignments via the AxM API. Auths with an ES256 client-assertion JWT (business.api scope). Read-only: device-assignment writes (orgDeviceActivities) are not wired yet.
EDR hosts, detections, network containment.
Machines, alerts, isolate/release, AV scans.
MDM devices, policies, app deployments, lock/wipe.
Mac fleet inventory, smart groups, policies, lock + wipe MDM cmds.
Apple MDM: blueprints, devices, library items, MDM commands.
Devices, compliance, wipe / retire / sync / locate / reboot.
Apple MDM: devices, lock / wipe / restart / send-command.
Endpoint agents, threats, isolation on demand.
Endpoints, alerts, isolation, scans.
Assets, vulnerabilities, scans (Nessus cloud).
XDR endpoints, detections, isolate/restore.
Cross-platform device management at scale.
Networking
What's plugged in and reachable, right now?Switches, VLANs, interfaces, LAGs.
Hosted zones + records as the API sees them right now.
Gateways, access rules, NAT, session publish.
Interfaces, VLANs, routes, ACLs via RESTCONF.
Interfaces, VLANs, VRFs, BGP peers via NX-API.
DNS policies, destinations, identities, domain intelligence.
Zones, DNS records — search and dump as the API sees them.
EXOS/Switch Engine ports, VLANs, stacks.
Virtual servers, pools, nodes, iRules.
Policies, address objects, live sessions.
Interfaces, routes, security policies, commit/rollback.
Live MAC/IP lookup, switch port VLAN moves, network/device search.
Interfaces, firewall rules, DHCP leases, wireless.
DCIM/IPAM source of truth — sites, racks, IPs, devices.
PAN-OS policies, address objects, commits.
Nodes, QEMU VMs, LXC containers, lifecycle ops.
Tailnet devices + keys; delete, expire-key, retag in one shot.
Zero-trust resources + groups; modern VPN replacement.
Comprehensive control plane: networks, WLANs, firewall, port-forwards, devices, clients — 13 state kinds.
Hosts, VMs, datastores, snapshots, power ops.
URL policies, firewall rules, users — Zscaler Internet Access.
Comms & Incident
Where humans coordinate when things break.Guilds, channels, roles, audit log.
Teams, channels, members — read-only org-wide audit.
Alerts, teams, who's on-call right now.
Show on-call, find user, list services + incidents.
find user, list channels + users — workspace audit at a glance.
Components, incidents, scheduled maintenances.
Users, meetings, license assignment / revocation.
Code & DevOps
Source of truth for everything that ships.Issues, projects, transitions, assignment, comments.
Inventories, job templates, launches.
Workspaces, repositories, branch restrictions.
Nodes, cookbooks, environments, runs.
Org-wide find user, list repos + members, read repo metadata.
Groups, projects, members, deploy tokens.
Issues, teams, projects, cycles via GraphQL.
Nodes, environments, recent reports.
Observability
What's healthy, what's screaming.Monitors, downtimes, users — schedule + cancel downtime live.
Hosts, problems, dashboards, alerting profiles.
Elasticsearch indices, users, roles, ILM.
Dashboards, alerts, datasources, folders.
Datasets, triggers, boards, columns.
Alerts, dashboards, users, entities.
Projects, items, teams, deploys.
Projects, issues, members, alerts.
Saved searches, indexes, users.
Collectors, monitors, dashboards.
Agents, alerts, rules — open-source SIEM/XDR.
Secrets & Config
The keys to the kingdom — audited live.SaaS / Business
Tools the whole company touches.Spaces, pages, users, restrictions.
Contacts, users, teams, integrations, audit log.
Flags, members, environments, kill-switch toggles.
Workspaces, pages, databases, users.
Incidents, change requests, users, CIs.
Roles, warehouses, users, grants — live audit.
Customers, subscriptions, charges via live API.
Tickets, users, groups, triggers.
Don't see your system?
Each module is ~200 lines of Python plus a manifest. Adding a new one is a single PR. Open an issue with the system you want, or send a PR — the contributor guide is in the repo.