The Cross Family / CrossConnect / Add-on modules

CrossConnect add-on modules

Ten questions your network can already answer.

CrossConnect collects the estate once. These modules read that same collection and each answers one question properly, so you are not buying a second tool and a second agent to get an answer the network already contains. Turn on the one you need. Leave the other nine off.

The problem

Every question buys another tool.

Somebody asks whether the research network is really cut off. That is a segmentation product. The auditor wants evidence packs, and that is a compliance product. Facilities want to know which rooms get used, so somebody prices up occupancy sensors. Each purchase arrives with its own agent, its own login, its own idea of what a device is, and its own answer to a question the others were never asked.

The awkward part is that your network already knew. The switch that carries the traffic can see whether the enclave is reachable. The port that powers the camera knows whether the camera answered. The thing missing was never the data. It was somebody willing to work it out and show the arithmetic.

Security, audit and risk

For the people who have to prove something to somebody else.

Provable segmentation

Faraday

Prove the secure area cannot be reached.

An auditor asks you to show that the research network is cut off from the guest Wi-Fi. Most teams answer by looking for a way in and not finding one, which proves only that they stopped looking. Faraday works out whether any way in exists at all, names the exact rule if one does, and prints the proof.

Faraday in CrossConnect: seal state sealed, segmentation integrity 100 percent, three of three controls passing, three zones proven, and the enclave definition it proposed from what CrossConnect already discovered.

What you get. A seal state, the zones proven, and a certificate an auditor accepts, re-proven on demand rather than at audit time.

Why the name. A Faraday cage is a sealed box that nothing gets through. That is the question this module answers about one part of your network.

Audit evidence packs

Notary

One pack the auditor accepts.

Audits run on screenshots, spreadsheets and somebody's memory of what was true in March. Notary builds a timestamped, control-by-control evidence pack from live records across nine built-in frameworks, works each result out from real evidence, and exports the whole thing as one document.

Notary in CrossConnect, building a control-by-control audit evidence pack from live records.

What you get. Audit week collapses into one export. The score is worked out from evidence instead of asserted, so the pack survives being questioned.

Why the name. A notary does not vouch for you. They witness and timestamp what was true at that moment, which is what this produces.

Risk review

Wargame

The findings that would actually cost you.

A findings list treats every problem as equal, so it gets worked through from the top by whoever has time, and the one that would take a broadcast off air sits at number 94. Wargame puts segmentation gaps and fragile media paths on one page with the evidence behind each, and keeps published industry figures carefully to one side of your own.

Wargame in CrossConnect, ranking segmentation gaps and fragile media paths with the evidence behind each.

What you get. A review a board will sit through, where the ranking comes from your estate and the money figures are labeled as somebody else's.

Why the name. A wargame is where you walk through how something fails before it does, with everyone in the room.

Unmanaged device discovery

Silhouette

The devices you never touched, found anyway.

Your inventory lists what somebody put in it. Silhouette finds the rest by the outline they press into the equipment around them, and pins each one to the exact port that sees it. Astronomers find unseen planets by watching a star wobble; the planet is invisible, its pull is not.

Silhouette in CrossConnect, listing unmanaged devices found by their effect on neighboring equipment, each pinned to a switch port.

What you get. The gap between what you manage and what is plugged in, with a port number against each one so somebody can go and look.

Why the name. You never see the device. You see the shape it casts on the equipment either side of it, and that outline is enough.

Operations and support

For the people who get called when it stops working.

Network or application

Flow Assurance

Is it the network, or is it the app?

The application team says the network is slow. The network team says the network is fine. Both are reading their own dashboard and neither can see the other's. Flow Assurance starts from the traffic that did move, names the application, finds the equipment carrying it, and says whether that equipment is healthy right now.

Flow Assurance in CrossConnect, naming the application from observed traffic and reporting the health of the equipment carrying it.

What you get. The finger-pointing meeting ends with evidence instead of seniority, and the team that is not at fault gets their afternoon back.

Why the name. It watches the flows of traffic that already crossed your network and gives you assurance about them. The name is the job.

AV endpoint visibility

Iris

Every camera, display and codec, on a real port.

Network tools call AV equipment an unknown device. AV platforms know the equipment intimately and have never heard of a switch. Iris holds both halves at once: what the equipment is, whether it answered, and the exact port and power behind it.

Iris in CrossConnect, listing AV endpoints with identity, status, and the switch port and power behind each.

What you get. The camera in room 214 stops working and you know in one screen whether it is the camera, the port or the power, without walking to the room.

Why the name. The iris is the part of a camera that opens to let the picture in. The module started with cameras and grew to the rest of the estate.

Facilities and property

For the people who pay for the building.

Building occupancy

Sense

Which rooms are in use, with no sensors bought.

Occupancy projects usually start with a purchase order for sensors, a cabling schedule and a privacy conversation. Sense works out room use, AV activity and energy draw from switch signals your network already produces. No cameras, and nothing new on a wall.

Sense in CrossConnect, showing room occupancy and energy worked out from switch signals already collected.

What you get. An answer to how much of the building actually gets used, in time for the lease conversation, without a capital project first.

Why the name. Building sensors are the usual answer to this question. The point of the module is that you already have some.

Facilities operations

Cleaning

Clean the rooms people used.

An event finishes at four, two hundred people walk out of the ballroom, and the next booking is at six. Nobody tells the cleaning crew, because there was never a way to. Cleaning watches how busy each space got, raises a job when a crowd forms and breaks up, and skips the scheduled pass on rooms nobody entered.

Cleaning in CrossConnect, raising cleaning jobs from observed occupancy and reporting the scheduled passes it skipped.

What you get. Crews sent where the crowd was, scheduled passes skipped on rooms nobody entered, and the hours saved reported rather than claimed.

Why the name. It does what it says. Some modules here carry a codename. This one did not need one.

Venues and specialist estates

For networks carrying equipment most IT tools have never met.

Lighting control visibility

Luminaire

See the lighting network, change nothing.

Lighting runs across your network on protocols most IT teams have never met, so when a bank of fixtures goes dark ten minutes before doors, nobody can say whether it is the fixtures or the network. Luminaire finds the lighting nodes, reads what they are carrying, and shows the switch port each one is plugged into, while sending no lighting commands at all.

Luminaire in CrossConnect, mapping lighting control nodes to the switch port behind each one.

What you get. The lighting network on the same map as everything else, and a straight answer about which side of the wall the fault is on.

Why the name. A luminaire is the fixture itself, the thing in the ceiling. This is the network underneath all of them.

Training equipment discovery

Windup

The pitching machines are on your network.

A modern pitching machine is a computer that throws a baseball. It is bought by a coaching department, plugged in by whoever was there, and never reaches the asset register. Windup identifies the pitching systems on your network, shows the switch port each one is on, and files it in your equipment list.

Windup in CrossConnect, identifying networked pitching systems with the evidence behind each and the switch port it sits on.

What you get. Training equipment on the register with the evidence behind each identification, before somebody discovers it during an audit.

Why the name. The windup is the motion before the pitch. This finds the machines that throw them.

What every module has in common

The modules differ in what they answer. They do not differ in how they behave, and the rules below are the same ones CrossConnect itself follows.

  • They read, and never write. No module sends a command to a device. Luminaire watches a lighting network without sending a lighting command. This is a property of the code, not a setting you can turn off.
  • They run on data you already collected. A module is a new question, not a new agent, a new appliance or a second pass across your network.
  • They say which parts are measured and which are reasoned. A value read from a device and a value worked out from other values are labeled differently, and you can always see which you are looking at.
  • They show where each answer came from. Every number opens onto the records behind it, which is what makes the answers survive being challenged by somebody who did not want to hear them.
  • They work alone. Turn on one. The other nine stay off and cost you nothing.

There is a brief for each one.

Two or three pages per module: the problem it solves, what it produces, what it will not tell you, and how it reaches the answer. Ask for one by name, or for the set.