Back to vendors
I

Itential

Also known as: Itential Platform, FlowAI, Itential MCP Server, Itential Automation Platform

Visit site
Entry priceQuote onlyFull pricing detail

Agentic orchestration platform for network and infrastructure operations where AI reasons and proposes but never touches infrastructure directly — every human, workflow or agent action executes through one governed engine with RBAC, approval gates, blast-radius limits, validation, rollback and immutable audit trails.

Itential is an orchestration platform for network and infrastructure operations, built on a principle it states plainly: AI reasoning plans and decides, but AI never touches infrastructure directly. Every change — whether a person, a workflow, an ITSM ticket or an AI agent initiates it — flows through the same governed execution engine with role-based access control, approval gates, blast-radius limits, pre and post validation, rollback and immutable audit trails. It is used by Lumen, Southern California Edison, US federal agencies, global carriers and financial services firms.

The agentic layer is FlowAI. FlowAgent Builder creates role-based agents from natural-language descriptions with defined reasoning styles and toolsets; the Itential MCP Server exposes governed automations as tools any LLM can discover and invoke; and the FlowMCP Gateway calls outward to external MCP servers such as NetBox and Selector to enrich a running task. Underneath sits a deterministic Workflow Engine that executes pre-defined logic identically every time, far faster than an agent and with no token cost, and Spec-Driven Development converts a proven agent session into exactly that kind of workflow without a rebuild.

Customers choose their own model. Anthropic, OpenAI, Google, Mistral, Ollama, Azure OpenAI and AWS Bedrock are supported, with provider keys held in write-only profiles, and Itential offers a bundled model only on its two entry tiers. Work Center gives operators a human-in-the-loop queue for approvals, and the autonomy level is a customer setting rather than a vendor default.

The platform deliberately keeps no copy of customer data, federating a live view across systems of record instead. It runs as managed SaaS or self-managed on-premises, in private cloud or in customer-controlled public cloud, with data and execution remaining in the customer's environment, validated HA and multi-region DR designs, SOC 2 Type II, SSO through OpenID Connect or SAML, and a published trust center. Pricing is by tier on agent runs and workflow throughput, never by device, node or seat.

Vendor details

Canonical URL

https://www.itential.com

Category

SRE / DevOps agent

Subcategory

Agentic network and infrastructure orchestration

Funding status

Independent, headquartered in Atlanta, Georgia, co-founded in 2014 by CTO Chris Wade to accelerate network automation adoption, with its most recent Crunchbase-listed funding a convertible note. Itential reports that some of the world's largest networks run on its platform, with named customers including Southern California Edison and quantified outcomes such as enterprise activation dropping from forty five days to under one.

Company status

independent

Use cases & customers

Primary use cases

Governed AI-driven infrastructure changeNetwork and hybrid cloud orchestrationClosed loop remediation from AIOps detectionsCompliance validation and configuration drift remediation

Target customers

Enterprises with complex network infrastructureTelecom and service providersNetwork operations and NetDevOps teamsUtilities and financial services

Deployment options

SaaSOn-premises (self-managed)Private cloudCustomer-controlled public cloud

Integrations

Named integration classes span ITSM (ServiceNow, Jira), infrastructure as code (Ansible, Terraform, OpenTofu), CI/CD (GitHub, Jenkins), observability (Datadog, Splunk), AIOps (Selector, Forward Networks), secrets and vault systems, cloud providers (AWS, Azure) and multi-vendor network estates (Cisco, Juniper, Arista, Palo Alto, VMware). The Itential Gateway executes Python, Ansible and OpenTofu directly against infrastructure with secure multi-vendor connectivity, and the ServiceNow App — published in the ServiceNow App Store — pushes governed automations into the customer's ServiceNow catalog as native Flow steps. The Itential MCP Server exposes governed workflows as tools any LLM can discover and invoke, the FlowMCP Gateway calls outward to external MCP servers such as NetBox and Selector, and the FlowMCP Server manages multiple MCP instances centrally. Developer documentation is published at docs.itential.com, with public GitHub and GitLab organizations and an AWS Marketplace listing.

In practice

An AIOps platform detects a network anomaly. The detection flows through Itential's MCP Server into a governed remediation workflow that validates the fix against policy before applying it, closing the loop without a rogue change.

A network team wants agents without giving AI the keys. Itential starts agents read-only against infrastructure state, then progressively grants write access through approval gates and blast radius limits as trust builds.

An engineer troubleshooting a BGP flap kicks off a workflow that pulls device and cloud logs, invokes an LLM mid-flow to pinpoint the misconfigured peer, validates the suggested fix against policy, and applies it, cutting diagnostics time in half.

Agentic Index coverage score

11.5 / 14 capabilities · 82%

Integrations & Tool Calling Full

Itential names its integrations by class and vendor: ITSM (ServiceNow, Jira), infrastructure as code (Ansible, Terraform, OpenTofu), CI/CD (GitHub, Jenkins), observability (Datadog, Splunk), AIOps (Selector, Forward Networks), and security and vault systems, alongside cloud providers (AWS, Azure) and multi vendor network estates (Cisco, Juniper, Arista, Palo Alto, VMware).

Action is documented, not only a catalog. The Itential Gateway is a named execution engine that runs Python scripts, Ansible playbooks, OpenTofu and Terraform plans, and AI initiated actions directly against the customer's infrastructure with secure multi vendor connectivity, an authenticated action inside systems and devices Itential does not own.

The ServiceNow App, published in the ServiceNow App Store, pushes governed Itential automations into the customer's ServiceNow catalog as native Flow steps, so Itential's actions run inside another vendor's product as first class objects. Existing Ansible, Python and OpenTofu assets become governed services without rewriting.

The published counts differ: the architecture page says the platform unifies 300+ integrations into a single orchestration fabric, while the pricing and platform pages describe 1,000+ open source integrations in the Itential Marketplace. They are plausibly scoped differently, governed prebuilt connectors against the open community library, but as published they read as two counts of the same thing.

Sourceitential.com/cloud-platform/architecture, /pricing and /marketplaceread 2026-09-08

Workflow Orchestration Full

Two execution modes run side by side, and both are priced. The Workflow Engine runs pre-defined logic identically every time at a published throughput, 10 tasks per second started on Scale, 50 on Enterprise and no limit on Custom, while FlowAgents combine LLM reasoning with governed tools to solve a goal described in natural language, metered in agent sessions.

Workflow Studio is the authoring surface, a drag and drop builder with versioning and testing requiring no scripting, and Lifecycle Manager orchestrates "multi-day sequences with explicit state and full rollback" across the resource lifecycle from provisioning to retirement.

The execution involves many participants across domains.

Workflows are published as microservices through an open API to northbound systems and AI agents, so a change can be initiated by a person through the Operations Manager self service portal, an ITSM ticket in ServiceNow, a CI/CD pipeline, an AIOps detection or an external LLM through MCP, and the same governed path executes it across network, cloud, security and IT infrastructure.

Stateful orchestration tracks services with resource models that detect drift and automate lifecycle changes. This is a deterministic orchestration engine with a reasoning layer on top.

Sourceitential.com/pricing and /cloud-platform/architectureread 2026-09-08

Knowledge Grounding & RAG Partial

Agents are grounded in a live, federated view of the customer's systems rather than a stored corpus.

Federation and Unified Data Models create a unified view of resources across disparate systems so agents and workflows operate on normalized data models, with Data Transformation converting diverse formats into common JSON that people and agents can interpret across multi vendor environments.

The FlowMCP Gateway lets agents invoke external MCP tools, NetBox, Selector and Forward Networks, for intelligence enrichment during execution, and Configuration Manager adds golden templates and compliance plans as a stored reference state.

The absence of a stored corpus is by design, and Itential says so: "Itential does not create copies of data, allowing your systems of record to serve as the source of truth." There is no maintained index, graph or embeddings layer over the customer's knowledge because the platform is built not to hold one; it federates a live view and enriches per execution, which is context assembled per run.

Sourceitential.com/cloud-platform/architecture and /cloud-platform/flowairead 2026-09-08

Human Oversight & Guardrails Full

A review gate ships as a product line on every pricing tier: Work Center, a "human-in-the-loop task queue for operators" that handles approvals and inputs when agents and workflows need a person. Around it sit approval gates, blast radius limits, pre and post validation checks and rollback, which Itential states apply "equally to AI-triggered and human-initiated changes".

The architecture makes the boundary structural: "AI never touches infrastructure directly." Agents observe state, analyze conditions and propose actions, and every change flows through the orchestration engine with policy enforcement; agent proposed automations pass validation, testing and approval before production deployment.

Autonomy is a customer set dial rather than a vendor posture, from human in the loop to human on the loop, with a documented read only first adoption path. That is a review and approve surface over what the agent does, plus a reversal route, plus a configurable boundary, alongside RBAC.

Sourceitential.com/cloud-platform/architecture and /pricingread 2026-09-08

Security, Identity & Governance Full

Security covers both attestation and access. On attestation, the architecture page's compliance section invites buyers to "verify Itential's security, availability, confidentiality, and processing integrity with SOC2", naming four Trust Services Criteria, and the pricing matrix names SOC 2 Type II in the Security and Governance line on all five tiers.

Privacy is stated as GDPR and CCPA compliance, and a Trust Center is published at itential.com/trust-center, linked from the Company menu and the site footer. Access runs through single sign on (SSO) via OpenID Connect or SAML, with programmatic identity for AI agents, RBAC and GBAC, granular permissions, secrets management, approval workflows for all infrastructure changes, and encryption in transit and at rest.

The governance model is explicitly identity aware for non human actors: RBAC policies apply consistently to human users and AI agents, the MCP Server authenticates by user or agent identity, and platform policy determines execution eligibility per caller. An immutable audit trail and on premises or customer controlled deployment back this up.

Sourceitential.com/cloud-platform/architecture, /pricing and /trust-centerread 2026-09-08

Observability & Auditability Full

The audit record is scoped to the agent. Audit trails are described as immutable on every pricing tier, audit evidence is captured on every change, and every action is "traceable back to its originating AI intent", so a reviewer can reconstruct not only what happened but which agent request caused it.

The MCP Server receives, validates and translates every request before anything touches infrastructure, applying RBAC, OAuth and audit logging automatically, so the agent's inbound intent and the resulting execution are captured on the same spine. Output, telemetry and result state are captured per task.

Insights adds measurement, with activity dashboards and SLA metrics on FlowAgent and workflow activity, performance and ROI. The audit trail ships on all five tiers, while Insights dashboards begin at Scale.

Sourceitential.com/cloud-platform/architecture, /pricing and /cloud-platform/itential-mcp-serverread 2026-09-08

Memory & State Persistence Not documented

Itential documents persistent orchestration state but no agent memory. Lifecycle Manager orchestrates "multi-day sequences with explicit state and full rollback", and stateful orchestration with lifecycle intelligence tracks infrastructure services with AI enhanced resource models that detect drift and automate changes from provisioning through retirement. Both are real persistence, but the state held is the orchestration's position in a running sequence and the resource model of the customer's infrastructure, the application's own data model: deleting it deletes the service record.

The vendor's own unit of work confirms the boundary. The pricing page defines an agent run as "one full instance of the agent executing its instructions, including all reasoning and tool usage, ending in a result", a session that starts and finishes, with nothing documented carrying across to the next. Itential also states it does not create copies of data, which cuts against an agent side store by design. No memory scope, stated lifetime, retention or deletion control over agent memory, or taught preference store carried between sessions is documented.

Sourceitential.com/pricing and /cloud-platform/architectureread 2026-09-08

Deployment & Data Residency Full

Three customer environments are named in Itential's FAQ on deployment models, "on-premises, private cloud, or customer-controlled public cloud", followed by a plain commitment: "data and execution remain in your environment." The architecture page adds a self managed option for organizations that need complete control to satisfy regulatory or internal security requirements, alongside a fully managed SaaS offering.

The topologies are documented, not only the choice. Itential Validated Designs cover single server high availability, active/standby with full component redundancy tolerating a catastrophic failure, and blue/green multi region disaster recovery, with a developer architecture named separately as unsuitable for production.

The pricing matrix adds a 99.9% availability SLA and custom VPN connectivity, a dedicated private network path into regulated environments, both on the Enterprise tier. Itential names the regulatory driver itself: national governments and industry regulators placing controls on where customer data is physically located. All of this concerns where Itential itself runs, separate from the hybrid and multi cloud infrastructure it orchestrates.

Sourceitential.com/cloud-platform/architecture and /pricingread 2026-09-08

Prebuilt Agents, Templates & Packs Full

Adoptable units sit in a browsable catalog. The Itential Marketplace is an open source library of API integrations, "pre-built skills, agents, and workflows", with customers able to contribute their own. It is listed as unlimited on every one of the five pricing tiers, open source and never metered, and sits at itential.com/marketplace with a community forum alongside it and public GitHub and GitLab organizations behind it. The units are agents and workflows, not connectors alone.

A build path sits alongside it. FlowAgent Builder creates governed, purpose built agents from natural language descriptions with defined personas, scopes and toolsets; Itential Builder Skills and Spec-Driven Development generate automation from intent and convert a proven agent session into a deterministic workflow without a rebuild. Golden workflow patterns and Configuration Manager golden templates supply reusable starting points, and the ServiceNow App publishes governed automations into the customer's ServiceNow catalog.

Sourceitential.com/pricing, /marketplace and /itential-builder-skillsread 2026-09-08

Triggers & Channel Coverage Full

Itential names its trigger surface as a capability: Event Triggers and Closed-Loop Automation connects FlowAI agents to observability and AIOps platforms for event driven orchestration with autonomous remediation and human in the loop governance, so a Selector, Forward Networks, Datadog or Splunk detection starts a workflow with no operator, and the loop closes back through the same governed path.

Four further entry points are documented.

ITSM tickets in ServiceNow and Jira resolve through integration, with the ServiceNow App embedding Itential actions as native Flow steps; CI/CD pipelines in GitHub and Jenkins trigger builds and deployments; the Operations Manager self service portal lets NOC, operations and service desk staff launch and monitor automation without developer access; and external LLMs invoke platform workflows as governed tools through the MCP Server.

Itential states the shape directly: infrastructure actions can be triggered by "humans, automation systems, or intelligent agents", through workflows published as microservices on an open API. Lifecycle Manager adds time extended sequences running over multiple days.

Sourceitential.com/cloud-platform/architecture and /pricingread 2026-09-08

Model Flexibility & Routing Full

Customer model choice gets its own row on the pricing matrix: the "LLM provider" row lists "Anthropic, OpenAI, Google, Azure, Bedrock, Ollama. Bring your own model, or use Itential's." The FAQ states the mechanism.

With a customer provided LLM, the customer configures a compatible provider on an account they control and pay for, naming Anthropic, OpenAI, Google, Mistral, Ollama, Azure OpenAI and AWS Bedrock.

With the Itential provided option, available only on Essentials and Compliance, Itential includes Anthropic as a turnkey part of the subscription, while Scale, Enterprise and Custom require a customer supplied model.

The FlowAI page adds the credential surface: provider API keys are managed through LLM provider profiles, write only once saved, masked in the UI and never returned through API or export. It also states support for any LLM, SLM or open weight model, including a custom one. Named providers, a self hosted open weight option through Ollama, customer held keys in a managed credential store, and a choice set out per tier put the decision with the customer.

Sourceitential.com/pricing and /cloud-platform/flowairead 2026-09-08

APIs, SDKs & MCP Extensibility Full

Extension surfaces run in both directions. Inbound, the Itential MCP Server exposes governed automation as tools "any LLM can discover and invoke" through the same policy enforced engine, sitting between AI systems and the platform to receive, validate and translate every request, and the FlowMCP Server is its enterprise form, centrally managing multiple MCP instances through virtual MCP servers with persona based access control and multiuser authentication. Outbound, the FlowMCP Gateway invokes external MCP tools.

Behind it is a documented API estate: a developer documentation site at docs.itential.com with release notes, and an open API through which workflows are published as microservices to northbound systems.

Every API already integrated with Itential is an agent tool with no new MCP server required, every self service catalog item is automatically registered as an MCP tool, and internal APIs and automation endpoints can be registered as tools.

Around it sit public GitHub and GitLab organizations, an Itential MCP product page, Builder Skills, native git connecting the customer's own repos, a community marketplace and an AWS Marketplace listing procurable against committed AWS spend.

Sourceitential.com/cloud-platform/itential-mcp-server, docs.itential.com and /cloud-platform/flowairead 2026-09-08

Testing, Debugging & Optimization Full

Workflows are tested before deployment, with an approval gate in front of production. Workflow Studio, its own line on the pricing matrix from the Scale tier, is a drag and drop builder "with versioning and testing" for designing and testing workflows in a visual low code canvas.

The vendor states the gate explicitly: "all agent-proposed automations pass through validation, testing, and approval processes before production deployment", and human review plus guardrails ensure only validated, compliant workflows execute in live environments.

Spec-Driven Development converts a proven agent session into a deterministic workflow, so a session that has been exercised becomes the artifact that ships.

What is tested is the workflow artifact, not the agent's reasoning, and no scored comparable result, holdout, benchmark or drift score is published: a customer sees pass or fail against their own logic rather than a graded evaluation. Pre and post validation with audit evidence and rollback on each change checks whether a change installed correctly, and Insights activity dashboards are a live operations metric.

Sourceitential.com/pricing and /cloud-platform/architectureread 2026-09-08

Browser & Computer Use Not documented

No hosted or local browser, desktop session, or remote or local computer control is documented. The agent reaches infrastructure programmatically: the Itential Gateway executes Python scripts, Ansible playbooks and OpenTofu plans against devices and cloud estates over API and CLI with secure multi vendor connectivity, and every other path, MCP, the northbound open API, ITSM and CI/CD, is programmatic. Terminal and shell access are not computer use, and normalizing CLI, API and AI interfaces into governed workflows is the opposite of operating a screen.

Nothing navigates, clicks, fills or advances anything through an interface built for a person. A device CLI session is a machine protocol, not a rendered surface, so the interface changes that break screen automation do not touch an SSH session to a router or a Terraform plan. For an infrastructure orchestration platform, that is the expected shape rather than a gap.

Sourceitential.com/cloud-platform/architecture and /pricingread 2026-09-08

The Agentic Index coverage score grades every vendor Full, Partial or Not documented against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded

Recent platform changes

2026-07-21·MCP / tool calling / APIVerified

Itential launched Agentic Builder Skills on the Anthropic Claude Marketplace, bringing spec-driven development to infrastructure automation. The plugin connects Claude Code to the Itential Platform, providing 13 skills and 5 agents that translate natural-language requirements into deterministic, production-ready workflows and FlowAgents.

Bears on: MCP / tool calling / API

View source
2026-07-06·Agent capabilityVerified

Itential announced the general availability of FlowAI, an agentic harness for building and deploying AI agents alongside deterministic infrastructure automation. Released with Itential Platform 6.5, the update introduces a Work Center for centralized human-in-the-loop approvals, Itential Gateway 5.5 for dynamic external credential retrieval, and Itential Builder Skills for Claude Code to enable spec-driven development via delivery agents.

Bears on: Agent capability

View source
View all 2 changes for Itential →Tracked since Jul 2026 · Verified from public vendor sources

Pricing

Quote only

agent_runs

What is public

Complete packaging with no figures. Five named cloud tiers are listed with quantified limits: Essentials at 5,000 agent runs a month, Compliance at 10,000, and Scale, Enterprise and Custom at unlimited runs, with Workflow Engine throughput published as 10 tasks per second started on Scale, 50 on Enterprise and no limit on Custom. A side-by-side comparison table sets out which applications ship at each tier: FlowAI, Operations Manager, Work Center, Itential Gateway, ServiceNow App, Spec-Driven Development, Marketplace and Security and Governance from Essentials; Configuration Manager from Compliance; Workflow Studio, Workflow Engine and Insights from Scale; Lifecycle Manager, HA architecture with a 99.9% SLA and custom VPN connectivity from Enterprise. The stated pricing principles are explicit: no device, node, server or per-seat licensing, unlimited users at every tier, FlowAI as core rather than a paid add-on, and pricing set by adoption measured in agent runs and throughput. Subscription terms run one, two, three or five years; on-premises FlowAI is an add-on licensed per production server with no monthly run limit; and the platform is procurable through AWS Marketplace against committed AWS spend.

Billing mechanics

Presumed enterprise agreement negotiated with sales, with scope tied to infrastructure domains orchestrated, integrations connected, and automation and agent volume. Interactive product tours and an automation value calculator support evaluation, but no rates are published.

Cost watchouts

Expanding across domains, adding integrations, and scaling FlowAI agents and MCP instances may raise cost beyond an initial platform footprint.

Variable cost rationale

The metered unit is the agent session and the allowance is small at the entry tiers, so consumption tracks how much reasoning work the platform is asked to do rather than the size of the estate — explicitly not by device, node or seat. Exposure is bounded upward by the tier structure, since runs are unlimited from Scale, and is materially reduced by the documented path of converting proven agent sessions into deterministic workflows that carry no token charge. Against that, LLM token cost sits on the customer's own provider account at Scale and above and is outside the subscription entirely.

Additional watchouts

The metered unit is the agent session, and Itential defines it as one full instance of an agent executing its instructions including all reasoning and tool usage. Reasoning-heavy agents therefore consume the allowance faster than simple ones, and Essentials includes only 5,000 runs a month with Compliance at 10,000 — exceeding either does not trigger an overage but a tier upgrade, which is a cliff rather than a gradient. The vendor's own mitigation is architectural and worth taking seriously: the Workflow Engine runs deterministic logic 10x to 1,000x faster than an agent with no token charges, and Spec-Driven Development converts a proven agent session into a workflow, so mature processes can be moved off the metered path. Note also that the Itential-provided LLM is available only on Essentials and Compliance; Scale, Enterprise and Custom require a customer-supplied model, so LLM spend moves onto the buyer's own provider account at exactly the point volume grows.

Sales call required

Yes, required for paid access

Free / trial

No public free tier; demo led with interactive product tours

Key ambiguities

Every structural term is published and every number in dollars is not, which is an unusual combination: a buyer can work out exactly which tier they need and cannot estimate what it costs. The overage rule is also unusually blunt — exceeding monthly agent runs is not billed as overage but forces a move to the next tier, and Itential states it does not sell additional runs on top of a tier, so the cost curve is a staircase rather than a slope with no published step heights.

Missing data

All monetary figures. No price, band, minimum or per-tier fee is published for any of the five cloud tiers, and on-premises FlowAI licensing is stated as per production server with no rate. Professional services and Itential Academy lab environments are named as optional without cost. The step between tiers is undefined in money, which matters more here than usual because exceeding agent runs forces a tier move rather than an overage charge.

Agentic Index verified 2026-09-12

Alternatives to Itential

The closest documented capability profiles to Itential among SRE and DevOps agents tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.

  • NeuBird11.0 / 14Adds documented Memory & State Persistence
  • Doctor Droid11.5 / 14Adds documented Memory & State Persistence
  • Hyground10.5 / 14Adds documented Browser & Computer Use
  • Komodor11.5 / 14Adds documented Memory & State Persistence
  • Kubiya11.5 / 14Adds documented Memory & State Persistence
  • NudgeBee11.5 / 14Adds documented Memory & State Persistence

Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded

Head to head

Contact us

Found a vendor we missed? Have feedback on the index? We'd love to hear from you.