Conceptual 4SO Network scene; the globe and routes are synthetic.

NETWORK SOURCE OF TRUTH

4SO NetworkNetwork Source of Truth with Provenance & Confidence

4SO Network turns scattered network information into a machine-readable model: inventory, interfaces, L2/L3, routing, topology and history are kept with clear provenance, and inference never silently becomes fact.

InventoryTopologyL2 / L3Provenance

4SO Network components: from source evidence to derived views with provenance

  1. 1Source snapshotsInventory, configuration, topology and history; each snapshot keeps its source identity and time.
  2. 2Normalize & correlateDomain parsers turn different formats into canonical network records.
  3. 3Fact / Candidate / DerivedInference stays Candidate or Derived until corroborated; it never silently becomes Fact.
  4. 4Derived viewsL2/L3, path and forensic views are projections over source records. Solid edges are facts; dashed are candidate or derived.
01PROBLEM & OUTCOME

Product problem

A network usually has more than one “truth”.

Inventory, diagrams, configuration, routing state and operator knowledge can disagree with one another. A good single source of truth does not hide that disagreement; it keeps the provenance and confidence of each piece of data attached to the data itself.

01FRAGMENTATION

Data is scattered across many sources

Devices, interfaces, addressing, VLAN/VRF, routing and topology usually live in separate formats.

02STALE DIAGRAMS

A diagram is not always live reality

A relationship derived only from a diagram or naming must stay separate from an observed fact.

03INFERENCE

Inference must be labeled

An inferred link candidate or site/role is not promoted to a definitive authority until it is corroborated.

04FORENSICS

History matters for incidents

Knowing where data came from, and when, is essential for change and incident analysis.

02CAPABILITY SNAPSHOT

Capability overview

Network data is broken down into analyzable domains.

The goal is to turn config dumps into an operational model that supports queries, correlation and forensics.

01INVENTORY

Device Inventory

A structured model for devices and operational metadata, independent of the source format.

02INTERFACES

Interface Model

Interfaces, descriptions, bundles and their relationships to other domains.

03L2

VLAN and port-channel

An L2 model for segments, membership and aggregation.

04L3

IP and VRF

Addressing and routing context in a separate, queryable structure.

05ROUTING

Routing Facts

Static, BGP and OSPF data for path and policy analysis.

06TOPOLOGY

Topology relationships

A node/edge model carrying the source and confidence of every relationship.

07DEPENDENCIES

Service Dependencies

Network service dependencies such as DNS, time, AAA and logging in a common model.

08HISTORY

Provenance and history

Timestamps, sources and change history for analysis and forensics.

4SO

In this product, authority is not a simple boolean. Every record must keep its own source, timestamp and confidence so that correlation and automation can tell fact from inference.

03AUTHORITY MODEL

Authority model

The source matters; so does the confidence.

Instead of a flat table that treats everything as definitive truth, data is classified by its origin and extraction method.

DomainExample recordsAuthority / ConfidenceUse
InventoryDevice identity, platform/role metadata, source mappingFact within the scope of the source snapshotInventory, ownership and normalization
Interfaces / L2Interface, description, VLAN, port-channelConfiguration-derived + source timestampLink-layer analysis and aggregation
L3 / RoutingIP/subnet, VRF, static routes, BGP, OSPFObserved/config-derived recordPath, routing context and policy analysis
TopologyNode, edge, device matching, link candidateFact / Candidate / Derived with confidenceCorrelation without turning inference into truth
DependenciesDNS, time, AAA, logging relationshipsSource-owned relation or bounded inferenceService dependency analysis
HistorySnapshot identity, source history, change contextTimestamp + provenance preservedForensics and change comparison
04ARCHITECTURE

Architecture

The pipeline must preserve provenance, not erase it.

Sources are ingested separately, parsers normalize them, and the single source of truth keeps records with their provenance and confidence. Analytical views are only projections.

INPUTSInventory · Topology · Configuration · HistoryEach source has its own identity and timestamp.
↓
NORMALIZATIONParser & NormalizerConverts different formats into uniform domain records.
↓
SOTStructured network source of truthFact + provenance + confidence; inference is never automatically turned into truth.
↓
INTELLIGENCEDerived Views / Analytics / ForensicsCorrelation and analysis over source-owned records without creating a second authority.
TECH

Inference Guardrails. 4SO Network keeps an explicit distinction between what a source actually stated, what has been correlated across several sources, and what has only been inferred.

Evidence typeClassificationUsage rule
Configuration snapshotFact within the scope of that snapshotInterface, addressing, VLAN/VRF and routing facts are valid only with their own source and timestamp.
Topology/diagram sourceSource-scoped factA relationship shown in a diagram does not prove the live state of the network.
Naming / Description correlationCandidateLink/role/site inference is not promoted to definitive authority before corroboration.
Multi-source corroborationConfidence-bearing relationSupporting evidence and sources stay attached to the relation; confidence is never separated from provenance.
Derived viewProjectionSummaries, path views or analytics are built from source-owned data and do not create a second SoT.
Historical comparisonChange contextThe difference between two snapshots shows change; it does not claim the cause of an incident without additional evidence.
05LIFECYCLE

Lifecycle

Network data has a quality lifecycle too.

Until a snapshot has been parsed, classified and correlated, it is only raw input; a derived result does not take the place of a fact until it has been reviewed.

01AcquisitionAcquire
02ParsingParse
03NormalizationNormalize
04CorrelationCorrelate
05ClassificationClassify
06ReviewReview
07Derived viewProject
08History comparisonCompare
06NETWORK DATA PROFILES

Data profiles

Each network domain answers a different question.

Separating domains keeps analysis from depending on one large, ambiguous CSV.

InventoryDEVICES

Device identity and metadata.

  • Device model
  • Platform / role metadata
  • Source mapping
InterfaceLINK LAYER

Interface and aggregation detail.

  • Interfaces
  • Descriptions
  • Port-channel relationships
L2 / L3NETWORK MODEL

Segment and routing context.

  • VLAN
  • IP / subnet
  • VRF
RoutingPATH & POLICY

Routing data for path analysis.

  • Static routes
  • BGP data
  • OSPF data
TopologyRELATIONSHIPS

Nodes and edges with explicit authority.

  • Topology sources
  • Device matching
  • Link candidates
ForensicsHISTORY

Change tracking and confidence.

  • Source history
  • Last-change context
  • Provenance-aware comparison
07ACTION & WORKFLOW CONTRACT

Data and evidence flow

In 4SO Network, the core action is turning evidence into an analyzable model while preserving provenance.

Rather than treating everything as truth, the pipeline keeps source-owned facts, correlation and inference in separate stages.

01AcquireSOURCE SNAPSHOT
02ParseSTRUCTURED RECORDS
03NormalizeDOMAIN MODEL
04CorrelateMULTI-SOURCE
05ClassifyFACT / CANDIDATE
06ReviewCORROBORATE
07ProjectDERIVED VIEW
EVIDENCE CLASSIFICATION

Fact / Candidate / Derived

Every relation is stored with its own evidence type.

SOURCE SNAPSHOT
↓
EVIDENCE
CLASS
↓
FACT
CANDIDATE
DERIVED
A naming hint without corroboration is not a fact.
MULTI-SOURCE CORRELATION

Several sources, one explainable relation

Correlation does not remove source ownership.

CONFIG
INVENTORY
DIAGRAM
↓
CORRELATE + ATTACH PROVENANCE
↓
EXPLAINABLE RELATION
source identity · timestamp · confidence · supporting evidence
Conflicts between sources are preserved and do not collapse into a fabricated truth.
CORROBORATION LOOP

Candidate to fact only with evidence

Confidence and provenance remain throughout the review loop.

HINT
→
CANDIDATE
↓
REVIEW
↑
EVIDENCE
←
FACT /
UNRESOLVED
confidence changes only with traceable evidence
Absence of evidence = unresolved, not automatic confirmation or rejection.
ADDITIONAL OPERATIONAL FLOWS

Additional analytical flows

Path analysis and conflict resolution are carried out without turning a projection into an authority.

Action / FlowAdmission / PreconditionsExecution / LockSuccess CriterionFailure / Recovery
Ingest SnapshotSource identity/hash/timestamp must be knownThe parser materializes only that source's dataRecords are traceable back to their snapshot/sourceA parse failure does not overwrite the original source and does not record partial success
NormalizeSchema/domain parser for Device/Interface/L2/L3/RoutingDifferent formats are converted into the canonical domain modelIdentity and source mapping are preserved in the recordUnknown fields are not fabricated; missing data stays missing
Correlate SourcesMatch keys and provenance available on both sidesCorrelation builds the relation but does not remove source ownershipEvery relation can show its supporting evidence/sourcesConflicts between sources are not hidden and are not automatically turned into a single truth
Infer CandidateNaming/description/topology hints used only for bounded inferenceThe candidate is recorded with its confidence and inference methodCandidates are distinguishable from facts and reviewableInference does not enter definitive authority without corroboration
Review / CorroborateIndependent evidence or operator confirmation requiredThe candidate is evaluated against additional evidenceClassification/confidence are preserved with a traceNo evidence = unresolved; no fabricated rejection/confirmation
Compare / Export Safe ViewSpecific snapshots and a sensitivity policy selectedDerived view/history/report is built from existing recordsReproducible projection without creating a second SoTPublic export removes real IP/ASN/device/site/topology data; root cause is not claimed without evidence
FLOW

Core rule: Projection ≠ Authority. Summaries, path views, analytics or forensics may be built from several sources, but the original fact stays bound to its own source and timestamp.

08OPERATIONS CATALOG

Operations catalog

The operations catalog is data engineering for the network.

Ingest SnapshotIngest a new source with a defined identity and timestamp.
NormalizeConvert devices, interfaces and network constructs into uniform data structures.
CorrelateLink records from multiple sources while preserving provenance.
Classify ConfidenceSeparate fact, candidate and derived information.
Derive ViewsBuild summaries and analytical views without creating a new authority.
Compare HistoryCompare snapshots for change and incident analysis.
Review InferenceConfirm or reject proposed items with additional evidence.
Export Safe ViewDeliver a dataset or report matched to the domain and sensitivity of the information.

Turn your network into data you know how far to trust.

4SO Network is built for decisions on network data, with Provenance and Confidence as part of the model itself.

All 4SO products →