EDEdmund Dionisio

MacDaddy module / compliance

Comply-FI

Discover access points, classify interface policy drift, preview exact remediation, and make every approved change verifiable and reversible.

MacDaddy modulePolicy · Jobs · RollbackDesigned + built by Edmund Dionisio
01 / Problem

A “non-compliant” label is not enough evidence for a change.

Access-point discovery and setup had to be repeated across a large campus environment. I wanted to automate both finding the APs and checking the switch-port configuration, but I did not want a fleet scan to become permission for a fleet-wide write.

Comply-FI separates classification from authorization to change. It collects evidence, classifies uncertainty explicitly, creates a fresh preview, captures rollback state, applies through the shared MacDaddy guard, and verifies the result before saving.

The rail that shaped the tool

Discovery can be broad; permission to change must stay narrow. Missing neighbor evidence, stale state, an unsafe interface, or a busy switch all stop the write path instead of becoming warnings an operator can click past.

ClassifyCompliant, drifted, incomplete, unreachable, or stale
PreviewCurrent evidence beside exact proposed commands
RecoverSnapshot, apply, read-back, history, rollback
02 / Workflow

Classification stays read-only until a fresh decision point.

Discover AP neighbors

Resolve scope from inventory and collect neighbor, interface, VLAN, mode, status, and policy evidence.

Classify with uncertainty

Keep incomplete and unreachable results distinct from genuinely compliant or non-compliant ports.

Generate a fresh preview

Re-read the candidate before showing exact, allowlisted remediation commands.

Acquire the write lease

Recheck permission and safety, capture rollback state, and prevent overlapping switch writes.

Apply, verify, then save

Read back live state; persist only verified work and retain the decision trail.

03 / Safety model

Uncertainty blocks the write path.

Infrastructure protectionTrunks and infrastructure-looking neighbors remain outside remediation scope.
Fresh evidenceApply does not inherit trust from an old scan or preview.
Command validationProposed configuration must fit the server-side policy.
Per-switch leaseConcurrent jobs cannot interleave writes on the same device.
Durable recoveryRollback capture and write-job state survive beyond one browser view.
Scheduled permission checkUnattended work revalidates the current user authorization.
04 / Evidence

Discovery, classification, policy, and remediation remain separate decisions.

05 / Decisions

Save only what the device proves.

01

Incomplete is a first-class state

Missing evidence does not collapse into “non-compliant” and cannot silently authorize remediation.

02

Verification gates persistence

The workflow saves configuration only after the live read-back matches the intended policy.

03

Reuse the platform guard

Comply-FI does not own a parallel SSH write path; it inherits MacDaddy's lease, command scope, rollback, verification, and audit controls.

06 / Lessons

Compliance is evidence plus time.

A port can be compliant when scanned and unsafe to change later. Treating evidence freshness, job health, cooldown, permission, and write ownership as part of the compliance decision made the workflow more honest.

  • Policy is environment-specific and must be approved before production use.
  • Current module behavior supersedes the older standalone implementation.
  • Public examples use dummy switches and APs; no employer inventory is published.