Infrastructure AI-readiness

Your infrastructure can't talk to AI. Yet.

OneIQ ICG is an infrastructure context gateway with an MCP interface that connects fragmented infrastructure data, unlocks secure AI access, and turns raw telemetry into governed, answer-shaped insight.

Giving IT Infrastructure a Voice

AI QUERY
AI
Thinking...
ANSWER
Here is your total infrastructure cost per business unit.
Business UnitTotal Cost (USD)
Finance$4.32M
Retail Operations$7.81M
Engineering$6.24M
IT Services$5.17M
Human Resources$1.23M
✓ Query completed10:24 AM
OneIQ
OneIQ ICG
COMPUTE
4,212 hosts
VIRTUAL
38,904 VMs
STORAGE
1,377 LUNs
NETWORK
210k flows
CLOUD
multi-region

Works with your existing stack

VMware Nutanix AHV Hyper-V AWS Azure Kubernetes Red Hat OpenShift Windows Linux Physical / bare metal

AI-enabled infrastructure

Infrastructure didn’t see AI coming either.

Three compounding problems sit between the infrastructure estate and the AI factory everyone is racing to build. Each one alone would stall the project. Together, they make it impossible - without a translation layer purpose-built to solve all three.

Problem 01

The translation problem

AI needs structured, answer-shaped context. Infrastructure produces raw, vendor-specific telemetry. Without translation, answering "which hosts are at risk?" means dumping tens of thousands of tokens into a model - slow, expensive, and inaccurate.

OneIQ ICG answer Normalise & Enrich - one unified model, costed and decision-ready before it reaches any agent.
Problem 02

The fragmentation problem

Every hypervisor vendor ships monitoring for its own platform and nothing beyond it. Physical racks have no API at all. Most estates run multiple hypervisors, cloud, and bare metal at once - and no single vendor's tooling sees past its own corner.

OneIQ ICG answer One agentless collector across every platform, any combination, simultaneously.
Problem 03

The governance problem

No security team will approve unrestricted AI access to a production estate. Without scoped, read-only, customer-controlled zones, the pilot stalls in security review - and that's where these projects quietly die.

OneIQ ICG answer Agent Zones - each AI service sees exactly what it needs and nothing more. Read-only. Auditable. Security-team friendly.

Agent Zones

Governance over what AI can see.

An Agent Zone scopes an agentic service to exactly the infrastructure it needs — so any LLM or copilot gets a governed, answer-shaped conversation instead of unrestricted estate access.

Read-only Customer-controlled Named & scoped Auditable
See Use Cases →
Agent Zone 01
Patch & inventory bot · All Windows machines
sees: 3,480 Windows hosts
eos_hosts: 189
critical_cve: 34 hosts
blind to: Linux fleet, app data, cost figures
scope: all Windows machines only · read-only · ~600 tokens
Agent Zone 02
VM ops copilot · Nutanix cluster
sees: 1 Nutanix AHV cluster, 96 VMs
at_risk_hosts: 2
headroom: 18% (30d ↓)
blind to: other hypervisors, other clusters
scope: Nutanix cluster only · read-only · ~600 tokens
Agent Zone 03
Capacity planner · HW + VM scoping
sees: 1 rack — hosts and their VMs
hw_hosts: 12
vms_hosted: 214
blind to: other racks, storage arrays, network fabric
scope: rack-scoped, HW+VM layer only · read-only · ~600 tokens
Agent Zone 04
Anonymous agent zone · benchmarking
sees: de-identified estate metrics only
hosts_covered: 4,212 (anonymized)
identifiers_removed: hostnames, IPs, owners
blind to: any identifying detail, credentials, live telemetry
scope: fully anonymized, aggregated only · read-only · ~600 tokens

AI security, not an afterthought

Built so the security team says yes.

Every architectural choice in OneIQ ICG answers the questions a security team asks before an AI pilot gets anywhere near production infrastructure.

Scope limiting

Bounded by design, not by policy

Every Agent Zone is a named, customer-approved boundary - read-only, tied to a specific cluster, fleet, or estate slice. An agent can't query outside its assigned zone because there's no broader estate for it to reach. Every query is logged and auditable end-to-end.

Anti-Prompt Injection

Nothing to inject into

OneIQ ICG never hands an agent raw, unstructured telemetry to parse - the surface where injected instructions typically hide. It resolves each query against governed data first and returns a structured, answer-shaped response. Even a manipulated request still can't reach infrastructure, credentials, or actions outside its zone.

Prevents Hallucinations

Answers computed, not guessed

OneIQ ICG resolves capacity, cost, and lifecycle questions with its own enrichment logic against real infrastructure data before the answer reaches the model. The AI's job is to phrase a verified result, not invent one from incomplete context - every figure traces back to source telemetry.

See how Agent Zones work →

Token cost is a real line item

Every AI call costs money. Unscoped agents burn most of it.

When an AI agent has no context layer, it reads the entire estate to answer a single question - thousands of hosts, hundreds of thousands of metric rows, tens of thousands of event records. That is a lot of tokens per call, multiplied by every agent, every workflow, every day. OneIQ ICG's Agent Zones scope each call to exactly what the question needs. Same answer, a fraction of the tokens.

Illustrative example - not a benchmark
Point an agent at the raw estate
hosts: 4,212 records...
vm_inventory: 38,904 rows...
metrics.cpu.5m: [88,91,84,...]
storage.luns: 1,377 entries...
net.flows: 210,440 lines...
events.raw: 96,500...
... everything, unscoped ...
~38,000 tokens / call
Ungoverned and over-reaching. The model burns its budget hunting the whole estate for the one thing that matters.
Far fewer
tokens per call
Point it at an Agent Zone
Zone: "Capacity risk - Prod"
at_risk_hosts: 3
headroom: 11% (90d ↓)
top_driver: mem on node-7
recommended_action: rebalance
scope: prod only · read-only
 
~600 tokens / call
Scoped, enriched, governed. An answer-shaped response - tokens go to reasoning, not searching.

Representative figures, for illustration. Actual results depend on the zone and the question.

Pay for reasoning, not for search

OneIQ SQL Offload Engine resolves structured queries inline, behind OneIQ ICG - trained specifically for the ICG schema and its supported query patterns.

OneIQ SQL Offload Engine

What it actually does

It exposes intelligence, not data.

OneIQ reads what's already in the environment, normalizes it into one model, and enriches it with the libraries your customer doesn't have - so the answer is "do this," not "here's a spreadsheet."

Reads

Any estate, agentlessly

Virtual, HCI, cloud, bare metal, storage - from existing collectors or the customer's own telemetry. Nothing installed on target systems, no attack surface added.

Enriches

Raw telemetry into decisions

Cross-referenced with lifecycle, hardware age, software support and pricing intelligence that OneIQ maintains - turning records into costed, decision-ready answers.

Governs

Scoped to what AI may see

Agent Zones bound each agentic service to exactly the infrastructure it needs - read-only, customer-controlled. The thing a security team can actually approve.

Who it's for

Two ways in. One platform underneath.

OneIQ ICG serves two distinct audiences. Technology Advisors use it to make clients' infrastructure AI-ready and build recurring intelligence services. IT teams use it to get continuous visibility and connect their estate to AI on their own terms.

Technology Advisors

VARs, SIs & MSPs

Walk into any client account — regardless of what's in the rack — and make it AI-ready. Assessment Factory generates seller-branded AI reports from free assessments. OneIQ ICG turns it into a recurring managed intelligence layer.

  • Free infrastructure assessments as a door-opener
  • Seller-branded AI Studio reports at scale
  • OneIQ ICG per customer environment — subscription
  • OEM-neutral across every hypervisor, cloud, and bare metal

Technology Advisor program →

IT Teams

Infrastructure & ops owners

Get continuous visibility across your entire estate for free with Infrastructure Pulse. Then connect it to AI — on your terms, in your environment, with your security team's approval.

  • Free continuous telemetry — Infrastructure Pulse*
  • Assess your estate: lifecycle, capacity, cloud-readiness
  • OneIQ ICG deploys inside your environment — no data leaves
  • Governed Agent Zones — scoped, read-only, auditable

For IT teams →

Built to be trusted

Governed access, enterprise-grade.

The reason a customer's security team says yes instead of stalling for a quarter.

Review our Security
ISO/IEC 27001 certified (BSI)
Agentless - no attack surface added
AES-256, zero-trust over HTTPS
Per-customer encrypted boundary
Secure workspaces - data stays put

Trusted by leading technology advisors & IT teams

Working with OneIQ means we can optimize ThinkAgile solutions based on each customer’s unique business and workload requirements.
Shekhar Mishra Lenovo
With everyone having shared application and IT infrastructure insights, OneIQ workspaces have made teamwork as easy as it should be.
Ben Russell The Barcode Warehouse
We use OneIQ to nurture trust, by giving our clients complete transparency into our Hybrid IT recommendations.
Helen Gidney Softcat

See it live on infrastructure you choose.

Pick any environment — virtual, HCI, physical, cloud, or a mix. We'll deploy a governed Agent Zone and show you exactly what an AI sees. No prep, no project, no commitment.

Technology Advisors → IT Teams →