COSGrid Guider

SD-WAN and SASE Orchestrator

SD-WAN, NGFW, and encrypted tunnels in one vCPE — deployed anywhere, across any transport.

COSGrid Guider

Why a Separate Orchestrator Exists

A network built from branch gateways, cloud enforcement points, and remote-user agents has a hard problem the boxes themselves cannot solve: keeping every one of them configured consistently, changing them safely, and proving what changed and when. Configure devices one at a time and the network drifts — every site ends up slightly different, every change is a manual step that can be fat-fingered, and there is no single record an auditor can read. Add a second product for security and a third for access, each with its own console, and an administrator is now reconciling three tools that disagree about what a user or a site even is.

Policy Model

Policy is authored once, at the level it belongs to (globally, per tenant, per site, or per user), and inherited downward, so the same intent applies everywhere without being retyped.

Change Control

Every change is proposed, checked, and recorded before it reaches a device, and every device reports back the configuration it is actually running, so drift is detected rather than discovered during an incident.

AVAILABLE AS

Managed Multi-Tenant Cloud Service Managed Multi-Tenant Cloud Service
|
Self-Hosted, Including Fully Air-Gapped Self-Hosted, Including Fully Air-Gapped

How COSGrid Guider Works

Onboard
Onboard
Author policy once
Author policy once
 Review and simulate
 Review and simulate
Distribute and confirm
Distribute and confirm
Monitor, detect drift, and record
Monitor, detect drift, and record
Onboard 01
Secure onboarding.

A branch gateway or a user is added in Guider and authenticates with a device certificate. Its configuration is delivered automatically — no site visit, no per-device setup.

Role in the COSGrid Architecture

COSGrid Guider
COSGrid Guider
COSGrid ReFleX-EdgeCOSGrid ReFleX-Edge
COSGrid MZA App ClientCOSGrid MZA App Client
COSGrid SARCOSGrid SAR
ReFleX-WANReFleX-WAN

COSGrid ReFleX-Edge

It drives COSGrid ReFleX-Edge (the branch SD-WAN gateways) and COSGrid ZGrid (the SASE points of presence, formerly CloudNF Hub) over an encrypted, mutually-authenticated control channel: Guider pushes signed configuration bundles that each node verifies before applying, and each node streams telemetry and its actual running state back. Guider knows the difference between a change sent and a change in effect.

COSGrid MZA App Client

It governs COSGrid MZA App Client, the remote-user agent — the client is provisioned, given its policy, and reported on through Guider, then connects users to the nearest ZGrid PoP.

COSGrid SAR

It exchanges signals with COSGrid SAR (Security Analyser & Responder): SAR consumes the telemetry Guider’s fabric produces to baseline behaviour and detect threats, and automated responses are applied back at the enforcement points Guider controls.

ReFleX-WAN

It is the plane that makes ReFleX-WAN a solution rather than a set of boxes — and, because the same console also governs the security and access components, it is what lets COSGrid present one policy across SD-WAN, SASE, and Zero Trust access instead of three.

Key Features of COSGrid Guider

One console across SD-WAN, security, and access.
Provision branches, steer application traffic, apply firewall and web policy, and govern Zero Trust access from a single place — instead of reconciling separate products that each hold a different idea of what a site or a user is. Policy is hierarchical: authored once at the global, tenant, site, or user level and inherited downward, with overrides explicit and visible in the diff.
Zero-touch onboarding
A new ReFleX-Edge appliance or remote user is added in Guider and comes online without an engineer on site and without per-device CLI. The device authenticates, pulls its configuration, and joins the network automatically — opening a branch becomes a shipping task, not a networking project.
Multi-tenant by design
Manage many organisations from one console with strict separation between them — built for MSPs, system integrators, and groups running multiple entities. Each tenant sees only its own network; operators see all of them, with per-tenant SLA and health reporting.
Change management your auditor accepts
Every change is a proposal until it is committed: Guider checks it, shows exactly what will differ from what is running, simulates its effect, and — where you require it — routes it for approval before anything is pushed. Every commit is recorded in an append-only, tamper-evident audit trail, and any change can be rolled back. Devices continuously report their running state, so configuration drift is flagged and corrected rather than found during an outage.
Cloud-hosted or self-hosted — including air-gapped.
Run Guider as a managed multi-tenant cloud service, or entirely inside your own environment, including fully air-gapped, when a vendor-operated control plane is not acceptable. Same policy model, same console, either way. This is a qualification gate the cloud-only SASE platforms cannot clear.

Technical specifications

Capability
Deployment models
Managed node types
Multi-tenancy
Authentication
Authorisation
Programmatic access
Change management
Audit
Monitoring
Control channel
Integrations
AI-assisted policy guidance
Support
Managed multi-tenant cloud (SaaS); self-hosted on customer infrastructure; fully air-gapped (all GA)
ReFleX-Edge gateways, ZGrid PoPs, MZA App Client endpoints
Hierarchical: global → tenant → site → user, with strict inter-tenant isolation
SSO via SAML / OIDC; MFA; optional hardware-key for privileged admins
Role-based access control with separation of duties (author ≠ approver) for regulated tenants
Open, standards-based interfaces for automation and infrastructure-as-code
Candidate/commit model, pre-commit simulation, approval workflow, one-click rollback
Append-only, tamper-evident change log; exportable to SIEM
Per-link and per-application metrics, SLA attainment, real-time fault management
Encrypted, mutually-authenticated; signed configuration bundles verified by each node
SSO/IdP; SIEM export; ITSM
On the roadmap

How Does It Work?

See how the product eases out to solution.

Contact Us