IT · Colleague: Ivy

Every device and licence, one live picture

BeforeQuery unifies devices from Jamf, Intune and Kandji with licences from your identity and SaaS platforms — so you know what you own, who has it, and what is drifting from policy.

Phase 2 · Q1
Capability 01

Devices, live

Read-through from Jamf Pro, Microsoft Intune, and Kandji. Every enrolled endpoint appears as an entity in the Context Graph with its serial, model, OS version, assigned user, last check-in, and compliance state. No CSV imports, no scheduled dumps — the picture is live.
grounded answer · sources
answer

Priya’s Okta lockout can be cleared via self-serve MFA challenge — no IT intervention required. If MFA fails, escalate to IT on-call.

cited from
01
IT · Okta account lockout policy
runbook · updated 4d ago
02
HR · Emergency access procedure
policy · updated 2w ago
03
Ticket #48211 · priya · resolved
past ticket · similar match
Capability 02

Licences, live

SaaS entitlement discovery across Okta, Microsoft 365, Google Workspace, Adobe, Slack, and Zylo-style discovery for the long tail. Each SKU shows total seats, used seats, cost per seat, and last-active-user timestamp. Detects orphaned seats within a day of the user's offboarding.
approvals · pending 4
unlock okta account
priya.sharma · self-serve · read-only
denyapprove
refund $128.40
stripe · ord_A4b2c · manager approval
denyapprove
revoke prod IAM role
aws · role/analyst · step-up MFA
denyapprove
reset zoom SSO
kiran.mehta · self-serve
denyapprove
Capability 03

Ownership at a glance

Who has what, from what team, since when. The Assistant can answer 'which team is paying for these 40 Photoshop seats' and 'what does Alex have out on loan' in one turn — no spreadsheet reconciliation.
context · priya.sharma
priyateamon-calloktagithubworkday
Capability 04

Compliance drift, caught early

Patch status, disk encryption, MDM check-in cadence, jailbreak detection — anything the MDM knows, we surface. Drift shows up on the Sync page grouped by team and severity, with a one-click playbook to remediate.
reports · this week
Auto-resolved
78.4%
+4.1 pt
Avg. loop time
11.4s
-2.1s
Approvals pending
12
-3
Coverage
94%
+1.2 pt
monsun
Capability 05

Reclamation on cadence

Quarterly cron scans SaaS usage. Seats unused > 60 days are surfaced to the owner with a 7-day window. Approve reassign, and the licence goes to the waiting list; deny, and it stays put. Licence spend down 15-25% is the typical first-year result.
grounded answer · sources
answer

Priya’s Okta lockout can be cleared via self-serve MFA challenge — no IT intervention required. If MFA fails, escalate to IT on-call.

cited from
01
IT · Okta account lockout policy
runbook · updated 4d ago
02
HR · Emergency access procedure
policy · updated 2w ago
03
Ticket #48211 · priya · resolved
past ticket · similar match
Capability 06

RMA + procurement wiring

New-device orders route through your procurement API (CDW, Apple Business Manager, Lenovo direct). Lost or damaged devices lock via MDM in seconds and open an RMA ticket that tracks the loaner and the replacement. Both flows ship as Phase-2 playbooks.
approvals · pending 4
unlock okta account
priya.sharma · self-serve · read-only
denyapprove
refund $128.40
stripe · ord_A4b2c · manager approval
denyapprove
revoke prod IAM role
aws · role/analyst · step-up MFA
denyapprove
reset zoom SSO
kiran.mehta · self-serve
denyapprove
The BeforeQuery method

Visibility. Reasoning. Action.

Every playbook, every action, every answer follows the same three-beat rhythm — one that keeps every write behind evidence and every decision behind policy.

01

Visibility

Read the full context — who is asking, what they own, what they can access, what breaks if we touch it. Nothing acts on incomplete signal.

02

Reasoning

Match the request to a grounded answer or a playbook. Cite the source paragraph, weigh the risk tier, and route to the correct approver where policy demands it.

03

Action

Execute the write on your systems with an audit-log id, an entity list, and a rollback path. Confirm the outcome with the requester in the same thread.

How every request flows

From ask to resolution in one loop

Six stages every request travels. What changes is how many stages policy lets the agent execute without waiting on a human.

01
Request

In Slack, email, widget, MCP, or the helpdesk. Same voice, same context.

Slack · Teams · Zendesk · Widget · MCP
02
Retrieve

Grounded lookup against your knowledge with source paragraphs held aside.

Knowledge Studio
03
Reason

Read the Context Graph — who, what they own, what breaks if we touch it.

Context Graph
04
Approve

Route to the correct approver per policy. Reversible writes gated, destructive step-up.

Approval matrix
05
Execute

Act on Okta, Stripe, Workday, GitHub, or your own systems. Logged and attributable.

Actions runtime
06
Verify

Confirm the outcome with the requester. Feed the result back into future decisions.

Feedback loop
Enterprise-grade by default

The controls your security team is going to ask about

SOC 2 Type II
audited annually
GDPR
EU data residency
HIPAA-ready
BAA available
SSO / SAML
Okta · Entra · Google
SCIM 2.0
auto-provision
Audit log
every write, traceable
Bring your key
AES-256-GCM at rest
Bring your model
Anthropic · OpenAI · self-host
Zero training
your data stays yours
Rollback
every write reversible
TLS 1.3
in transit
99.9% uptime
SLA on Enterprise

Frequently asked questions

Common questions about Asset Management

For most mid-market teams, yes — the SaaS discovery and licence reclamation flows are equivalent, with the difference that BeforeQuery also executes the reclaim. If you have a large enterprise ITAM investment, we coexist: BeforeQuery is the daily-driver operator, the ITAM stays as the system of record.
Jamf Pro, Microsoft Intune, and Kandji at launch. Addigy, AirWatch, and Mosyle via UIA or the NL integration builder. Every device becomes an entity in the Context Graph regardless of source.
Yes. The 'Lost Device → Remote Lock' playbook takes a chat request, verifies the caller's identity, calls the MDM API, and opens a follow-up RMA ticket. Median time from report to lock is under five minutes in production. Every lock event is logged.
The quarterly cron reads seat assignments and last-active timestamps from each SaaS admin API. Users inactive > 60 days get a Slack DM with a 7-day window to justify keeping the seat. On timeout or explicit decline, the API call revokes the seat and offers it to the waiting list.
Devices and Licences pages in the sidebar, Jamf + Intune + Kandji + M365 + Google + Slack integrations, the 'Lost Device', 'Reclamation', and 'Proactive Device Health' playbooks. RMA and procurement wiring follow in Phase 5 as their vendor integrations land.

Run it on BeforeQuery

Book a demo and see what Asset Management does on your own data — usually within 45 days.