Ordivis Platform is in pilot operation: the first pilot customer works with it productively. Instead of promises we first show the actual state of every module, then the phases up to general availability on 1 January 2027. Your input helps set priorities: send us requests, ideas or bugs below.
Not a marketing bar but the extract from our work-package register: 1003 work packages across 53 modules, 889 of them completed — 89 % done. Each row is one module, each bar shows the real share of completed packages. The first pilot customer works with it productively – in the daily business of their IT department. Ordivis Platform becomes generally available on 1 January 2027.
The figures come straight from our project control and are regenerated with every release — including when a bar gets shorter. What comes next.
How far along it is, the bar above tells you. This is what that state looks like – not a mock-up but the running build on a real device.
An emergency manual is needed when power or network are gone – that is, exactly when reloading is no longer possible. This is why it is taken along beforehand – and every row states whether it is on the device.
Screenshots from the demo tenant on a real device. The app is not available yet and not part of the scope the pilot customer works with. Built are the offline queue, label scanning, stocktaking, knowledge base, emergency manuals, checklists and the service catalogue; push notifications and publication in the Play Store are still outstanding.
Until recently these items were listed here under “Now” or “Next”. They are finished and in the product – which is why they are no longer listed as “planned”. Details in the changelog and under All features.
BSI 200-4 & ISO 22301 in full: BIA with pre-filter, MTPD proposal, SPoF detection, response organisation, recovery playbooks, exercise and test management – including a digital crisis staff (S1–S6, crisis mode, operations log, situation map).
Protection requirements, modelling, Grundschutz check, risk analysis to BSI 200-3, reporting – plus ISO 27001:2022 as a second framework with 93 Annex A controls, statement of applicability (SoA) and certification traffic light.
Inheritance of protection requirements across the CMDB, automatic SSP generation, assessment results, continuous monitoring and POA&M tracking.
Versioned manuals including recovery plans, generated automatically from the CMDB, contracts, responsibilities and emergency organisation – as a branded PDF with an approval workflow, without maintaining anything twice.
Freely composable checklists, logged in an audit-proof manner, with templates for recovery, emergencies and on- and offboarding – triggerable from BCM, a ticket or a process.
CSAT rating after a ticket is resolved, appointment acceptance and refusal with a calendar invitation, “My devices” with fault reporting, self-disclosure and a change calendar to follow along.
The web portal as an installable progressive web app – including offline access to the BCM emergency documents for a real emergency without a network connection.
A lean collector per site or customer network, connected outbound and encrypted – without an inbound firewall rule. Findings are reviewed and adopted as CIs.
PostgreSQL metrics, signed-in users and sessions as well as the health of every service at a glance – with threshold warnings.
A tenant administration interface, a dedicated database per tenant and tenant selection at login – particularly for IT service providers. Plus a cross-tenant ticket list for groups and municipal associations: one work list across several organisations, released per tenant rather than wholesale.
Sign-in at your own identity provider – Entra ID, Keycloak or any other OIDC provider. As a broker model: the code-for-token exchange happens server-side, no secret resides in the client, PKCE is enforced. Plus tenant detection from the e-mail domain, account creation on first sign-in, mapping of groups and claims onto Ordivis roles as well as single log-out. In addition, the integrated Windows authentication (Kerberos/SPNEGO) for domain workstations. A nightly reconciliation deactivates accounts that have been locked or removed at the identity provider – even without an active session.
Draw processes directly in the product: palette, drag and drop, swim lanes, versioning and four-eyes approval – in the client and in the web portal, the result stays BPMN 2.0.
Software reconciliation from discovery, true-up balance, reclaim of unused seats, audit export and early warning for maintenance and software assurance.
TCO and straight-line depreciation, cost roll-up per cost centre and supplier as well as assignment to employees and sites.
Named ticket and CI views as well as full-text search across description, journal, CI attributes and knowledge articles (PostgreSQL FTS with ranking).
A dedicated event source “Ordivis Platform” with a binding event catalogue; which events are written is decided by the platform administration – directly connectable to SIEM/SOC.
Every application – server, client, portal, wallboard, updater and app – logs by the same rules. Location, verbosity, rotation and the scope per area are configurable in the platform administration and take effect without restarting a service; optionally as JSON for SIEM and log agents. One click turns that into an encrypted support package for the vendor’s support – without business data and without secrets.
Scan labels and NFC tags at the device, trigger actions on the move and reconcile stock via barcode/QR – offline-capable with a queue.
OAuth2 for Gmail and Microsoft 365, a send queue with retry and rate limit, loop protection, evaluation of bounce messages and mailbox monitoring.
Faults from CheckMK, PRTG, Zabbix, Nagios/Icinga or any other tool automatically become tickets – via a batch endpoint or, as a fallback, through a monitoring mailbox. Repeats land as a comment on the existing ticket instead of in a new one; the all-clear closes it again after a grace period. An active maintenance window suppresses creation, a storm brake bundles mass events into one collective ticket, flapping services are recognised as such. Severity, category and assignee come from a rule set per source; if someone has already worked on the ticket, the human takes precedence over the automation.
Warnings from the German Meteorological Service per municipality rather than by the nearest weather station: the DWD warns for warning cells, not for stations – a station in the neighbouring district could report calm weather while a warning was active for your own location. The location follows from the tenant’s postcode. Plus the official warning map with selectable warning type and zoom, precipitation radar and the forest and grassland fire index – in the client, in the web portal and on the wallboard. Whoever holds the “weather warning” role is notified when a new warning arrives.
Ordivis Toolbox, the free field assistant, feeds Ordivis Platform: scan ingest into IPAM (unconfirmed → ratified by an admin) as well as the SNMP, AD, DHCP and DNS feeds into IPAM and the CMDB.
What is being worked on right now. These four topics cover roughly half of the open work packages from the bars above; the largest remaining block is multi-channel alerting further down.
Finished and running on the device: sign-in, tickets and journal, photo attachments, offline queue, label and NFC scanning, stocktaking, the mobile dashboards as well as the knowledge base, emergency manuals, checklists and the service catalogue – the last four also without a network. In progress are hardened sign-in (OAuth2/PKCE, connection to the company account, device binding) and push notifications that jump straight to the right ticket. The app is not available yet.
Instead of typing a password: the sign-in at the client is confirmed on the registered phone. Every device gets its own key pair; the private part never leaves the hardware key store. The approval shows who, when, from which machine and from which address – and is confirmed biometrically.
Three languages are finished: German, English and, since 15 August, French as well – throughout the client, the web portal and the API messages, 5,284 strings per language in total. Notifications appear in the recipient’s language. The translation pipeline is in place, further languages join without a code change; what remains open is no longer the technology but the volume – and, for legal and ISMS terminology, the expert review.
No promise without measurement: load test with 300 concurrent users, an index and query audit based on the real query statistics as well as fine-tuning of the cleanup runs on the write-intensive tables. The result is dependable sizing figures instead of estimates.
Firmly planned for the next iterations.
Today crisis mode alerts inside the application and by e-mail; further channels are so far only stored as a contact list. Planned is alerting the crisis staff and on-call members via SMS and app push – with acknowledgement (“I am coming” / “Not available”), time-controlled escalation and a complete delivery log for the record. SMS reaches recipients even without a data connection. A voice call with keypad acknowledgement and a watchdog independent of the applicationthat still raises the alarm when the server itself fails are planned as a further stage.
Model workflows as a flowchart – configure steps, conditions and escalations visually, analogous to the BPMN editor already delivered.
A signed build, a privacy policy and a distribution path that works without a public store: managed distribution via Managed Google Play or the existing device management.
Short queries between agents directly on the ticket – separate from the journal the reporter sees.
In addition to labels and NFC: bulk capture of whole shelves and rooms with a dedicated UHF reader for taking stock of larger inventories.
After the translation pipeline, the remaining official EU languages – the interfaces have already been converted to resources throughout.
Today Ordivis reads the requirements layer of the BSI catalogue. To be added are the component definitions of the BSI as well as the official mapping tables ISO 27001 Annex A ↔ Grundschutz++ and IT-Grundschutz 2023 → Grundschutz++ – so that a requirement once fulfilled becomes visible in the other framework instead of being assessed twice.
The delivered process catalogue for public administration so far cites mainly federal law. The state-law references will be added per federal state.
Foreseen; the timing depends on prioritisation.
Sites and assets on a map – from the property down to the rack, extended on mobile with location-specific technician notes.
Book working time and installed spare parts directly to a project and cost centre while on the move.
Make readings such as temperature or humidity visible on the corresponding configuration items and use them for threshold alerts.
Hands-free ticket capture and operation for situations in which both hands are needed.
Vibration alerts on escalations and quick status changes on the wrist.
Languages written right to left additionally require a mirrored layout of the interface – hence after the official EU languages.
Larger expansion stages for the future.
Selected administration functions in the browser as well – in addition to the WinUI client.
Extensibility through plug-ins for customer-specific integrations.
The ability to work in separated network segments with later synchronisation.
Dialogue-guided support for end users with standard requests.
Coupling several CMDBs or sites into one federated overall view.
Keeping an eye on energy and sustainability metrics of the infrastructure.
Device and rack information as an overlay in the camera image directly on site.
Classify damage photos on the phone and route the ticket to the right group from the outset.
This roadmap is non-binding and serves as orientation. The order, scope and timing of features may change; there is no entitlement to implementation.
Your feedback feeds directly into our prioritisation. Whether a missing feature, an idea for improvement or a defect – write to us.