Why a Separate Orchestrator Exists
A network built from branch gateways, cloud enforcement points, and remote-user agents has a hard problem the boxes themselves cannot solve: keeping every one of them configured consistently, changing them safely, and proving what changed and when. Configure devices one at a time and the network drifts — every site ends up slightly different, every change is a manual step that can be fat-fingered, and there is no single record an auditor can read. Add a second product for security and a third for access, each with its own console, and an administrator is now reconciling three tools that disagree about what a user or a site even is.
Policy Model
Policy is authored once, at the level it belongs to (globally, per tenant, per site, or per user), and inherited downward, so the same intent applies everywhere without being retyped.
Change Control
Every change is proposed, checked, and recorded before it reaches a device, and every device reports back the configuration it is actually running, so drift is detected rather than discovered during an incident.
AVAILABLE AS
Managed Multi-Tenant Cloud Service
Self-Hosted, Including Fully Air-Gapped How COSGrid Guider Works
A branch gateway or a user is added in Guider and authenticates with a device certificate. Its configuration is delivered automatically — no site visit, no per-device setup.
Traffic-steering, firewall/web, and access rules are written at the level they belong to and inherited down the hierarchy, so one intent applies across every site without being retyped.
The change is validated and shown as a precise diff against what is running; its effect is simulated, and — if you require approval — it waits for sign-off before going live.
On commit, Guider pushes a signed configuration bundle to every affected gateway and PoP; each verifies and applies it and confirms back. Guider tracks “sent” versus “in effect.”
Per-link and per-application telemetry, SLA attainment, and faults stream back continuously. Devices report their actual running state so drift is caught and corrected, and every change is retained in an exportable audit trail.
Role in the COSGrid Architecture

COSGrid ReFleX-Edge
COSGrid MZA App Client
COSGrid SAR
ReFleX-WANCOSGrid ReFleX-Edge
It drives COSGrid ReFleX-Edge (the branch SD-WAN gateways) and COSGrid ZGrid (the SASE points of presence, formerly CloudNF Hub) over an encrypted, mutually-authenticated control channel: Guider pushes signed configuration bundles that each node verifies before applying, and each node streams telemetry and its actual running state back. Guider knows the difference between a change sent and a change in effect.
COSGrid MZA App Client
It governs COSGrid MZA App Client, the remote-user agent — the client is provisioned, given its policy, and reported on through Guider, then connects users to the nearest ZGrid PoP.
COSGrid SAR
It exchanges signals with COSGrid SAR (Security Analyser & Responder): SAR consumes the telemetry Guider’s fabric produces to baseline behaviour and detect threats, and automated responses are applied back at the enforcement points Guider controls.
ReFleX-WAN
It is the plane that makes ReFleX-WAN a solution rather than a set of boxes — and, because the same console also governs the security and access components, it is what lets COSGrid present one policy across SD-WAN, SASE, and Zero Trust access instead of three.
Key Features of COSGrid Guider
One console across SD-WAN, security, and access.
Zero-touch onboarding
Multi-tenant by design
Change management your auditor accepts
Cloud-hosted or self-hosted — including air-gapped.






