Deterministic public demo Read only
Meraki-first operations · managed private deployment

Five alerts.One likely root.

Tower connects topology, client paths, events, and configuration history so your team can see who is affected, isolate the likely root, and prepare a guarded response—without replacing Dashboard.

INCIDENT PATHFIN-LT-024→AP-FL1-04→ACCESS-SW-04
Read-only by defaultCredentials stay server-sideSynthetic public snapshot
INCIDENT / HQ-2407 / SYNTHETICAP-FL1-04 OFFLINE
TTOWERDEMO
14:32:08 EDT
Devices online22 / 274 alerting · 1 offline
Active alerts51 critical
Clients online63 / 707 affected
WAN uplinks2 / 2healthy
INTERNETHQ · MX95CORE-SW-01ACCESS-SW-04AP-03CAM-12MACBOOKAP-FL1-04
FIXED SYNTHETIC SNAPSHOT · HQ CAMPUS
Deterministic demo evidence loadedSwitch views above · Open demo for full investigation
HQ CAMPUS27devices70clients2 / 2WAN healthy
READ ONLY5 ACTIVE ALERTS1 LIKELY ROOT
One deterministic incident

Don't count alerts.
Follow the failure path.

Tower turns the same fixed evidence in the public demo into one investigation—from the first unreachable AP to the likely root and the guarded next action.

00
Alert

Five alerts. One incident.

AP-FL1-04 stops reporting. Seven client sessions are affected, while both WAN uplinks remain healthy. Tower starts with what shares a path.

  • AP-FL1-04 OFFLINE
  • 5 ACTIVE ALERTS
  • 63 / 70 CLIENTS ONLINE
01
Topology

The red node is only the beginning.

Trace Maya Chen’s FIN-LT-024 through AP-FL1-04, ACCESS-SW-04, and the healthy HQ-MX-EDGE. The break appears before the gateway.

  • FIN-LT-024 → AP-FL1-04
  • → ACCESS-SW-04
  • → HQ-MX-EDGE · HEALTHY
02
Likely root

A change 12 minutes earlier narrows the search.

ACCESS-SW-04 advertises native VLAN 120 while CORE-SW-01 port 12 expects VLAN 10. Tower places that change beside the downstream DHCP and AP failures.

  • 14 CLIENTS · 2 APS · 1 SERVICE
  • 14:19 · PORT 47 · VLAN 10 → 120
  • CORRELATION · NOT PROOF OF CAUSE
03
Action gate

Prepare the fix. Keep the human gate.

Tower keeps observation read-only, validates allowlisted parameters, shows the affected scope before confirmation, and records every authorized result.

  • MODE · READ ONLY
  • PARAMETERS · VALIDATED
  • ACTION GATED · NO CHANGE MADE
Open the full connection path in Tower →
Meraki at the core. Add context only where it changes the answer.
MERAKIMICROSOFT AZUREENTRA + INTUNEVERKADAADPFRESHSERVICE
Meraki at the core

Add context only where it changes the answer.

Network evidence comes first. Azure, identity, endpoints, cameras, and service workflows dock into the same operational picture when they explain impact or sharpen the next action.

NETWORK OPERATIONS

Every site. Every path. One map.

2D, 3D, and geographic topology; client paths; ports; VLANs; DHCP; firmware; Wi-Fi evidence; and live tools.

23 best-practice checksMulti-site rankingConfig snapshots
CLOUD + APPLICATIONS

Map the service, not just the VM.

Connect Azure resources, line-of-business applications, dependencies, SSO state, reachability, and the site-to-site VPN.

ERFleet ERPCritical business serviceHEALTHY
VMerp-app-01Azure VM · East USRUNNING
DBerp-sql-prodSQL · 34 msONLINE
PEOPLE + ENDPOINTS

Start with the person, not the MAC address.

Join network clients to Intune devices, Entra identities, onboarding state, and the exact AP or switch port they use.

MC
Maya ChenFIN-LT-024 · connection affected
GUIDED RESPONSE

Prepare the action. Keep the gate.

Attach the evidence, validate the expected parameters, show the affected scope, and wait for explicit human confirmation.

PROPOSED RESPONSE · ACCESS-SW-04Restore port 47 native VLANGATED
66%
  • Incident evidence attached
  • Parameters validated
  • NEXT · Human confirmation
Managed single-tenant deployment

Private by architecture.
Predictable by default.

The incident stays inside your boundary. Tower keeps credentials in the private service, starts in read-only mode, and makes every authorized write deliberate and inspectable.

Review the architecture with us →
01 / USER BOUNDARYYOUR BROWSEREntra sign-in · TLS
HTTPS
02 / PRIVATE SERVICETOWERServer-side credentials · policy gates · auditREAD ONLY
API
03 / SYSTEMS OF RECORDMERAKI · AZURE · IDENTITYScoped connections · attributed evidence
Managed private deployment · no credentials delivered to browser code

Credentials stay server-side

API keys and tokens are held by the private Tower service and never delivered to browser code.

PRIVATE BOUNDARY

Read-only by default

Observation works without enabling changes. Write capabilities remain explicitly armed and authorized.

SAFE BASELINE

Every action has a gate

Allowlisted parameters, strict validation, blast-radius confirmation, and per-action results.

VALIDATE + CONFIRM

History you can inspect

Who, what, when, parameters, and outcome are captured for every attempted configuration action.

INSPECTABLE HISTORY
Launch pricing

Price the estate, not the operator seats.

Start with a managed private deployment. Scale by sites and modules as Tower proves value inside your environment.

CORE

Network clarity

For a lean team standardizing a distributed Meraki estate.

From$499/ month
Up to 10 managed sites
  • Live topology + client paths
  • Issues, ports, VLAN + DHCP analysis
  • 23-check site audit
  • Reports + config history
Request Core
PLATFORM

Hybrid IT control plane

For organizations connecting network, cloud, identity, and people ops.

Custom
Designed around your estate
  • Everything in Operations
  • Azure + business-app mapping
  • People + endpoint context
  • Onboarding and offboarding modules
Design a Platform pilot

Core and Operations are approved launch rates for managed, single-tenant deployments. Onboarding is quoted after technical validation, and no discounts are preapproved. Final scope is recorded in a separate order form.

Straight answers

Questions your security and infrastructure teams will ask.

Is Tower a replacement for the Meraki dashboard?+

No. Tower is the operational layer above it: topology-aware diagnosis, cross-system context, change correlation, and guided workflows. The dashboard remains the source of truth.

How is Tower deployed today?+

As a managed, single-tenant deployment for your organization, typically behind your existing Entra sign-in and TLS boundary. We are intentionally not presenting the current product as a shared multi-tenant service.

Where do our API credentials live?+

In the private Tower deployment, server-side. They are masked in settings and never delivered to the browser. We review the deployment boundary with your team during the pilot.

Can Tower make changes to our network?+

Only when you explicitly enable it. Tower is read-only by default. Authorized actions are allowlisted, validated server-side, confirmed with their blast radius, and written to the audit history.

What happens when an integration is unavailable?+

Tower reports the missing source as unknown. It does not turn an API failure into a green zero, a fake all-clear, or an invented connection.

Is the Wi-Fi view an RF survey?+

No—and Tower says so. Signal color uses measured client RSSI/SNR; radius is a propagation model based on transmit power and environment. A physical survey remains authoritative.

Private pilot

Bring the incident your team dreads.

We'll map one real failure path, review your deployment boundary, and scope a private pilot around your environment—not a canned dashboard tour.

0130-minute discovery02Architecture + data review03Scoped private pilot