Skip to content

Product1 publisher2 min readPublished

env zero lets platform teams decide how much infrastructure drift its agents fix alone

env zero's EZ Control lets agents repair infrastructure drift across nearly 2,300 resource types, at an autonomy level each platform team picks. How much autonomy a team grants will depend on how far it trusts the product's map of who owns each resource.

The Product Desk · Product desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Illustration accompanying env zero lets platform teams decide how much infrastructure drift its agents fix alone
Generated illustration

What happened

  • An ontology layer on the CMDB links every resource to the code that declared it, its owning team, its cost, the resources that depend on it, and the policies and risks attached to it.
  • Teams pick one of four automation levels: observe only, propose a fix, act with approval, or act autonomously within guardrails they define.
  • Accidental drift is corrected by reapplying infrastructure-as-code, deliberate changes become a pull request against the owning repository, and source-code defects are flagged.
  • A scan after each fix verifies it closed, and a built-in MCP server lets a person or another AI agent audit what was done.
  • Corndell said the platform works across multiple IaC languages without requiring OpenTofu or Terraform, and its components are available separately as well as together.

Compiled by The Product DeskSomething wrong?How this is made

Why it matters

  • decision Choosing a setting makes a platform team state, as configuration, which drift fixes may land before any person approves them.
  • constraint Because env zero routes every action through the owning repository's review process, the rules already on those repositories cap how autonomous the top setting can be in practice.
  • exposure A remediation is only as correct as the ontology link behind it, so a resource tied to the wrong repository gets the wrong code reapplied or a pull request sent to reviewers who do not own it.

On Monday, this product looks like a platform engineer staring at a resource that no longer matches its code and deciding whether software may put it back. Three of EZ Control's four settings leave that decision with a person [1].

The pitch is agentic. According to CEO Steve Corndell, a team states an intent in natural language and EZ Control turns it into an autonomous workflow carrying the context needed to apply it [7]. The work env zero describes is narrower. Take away the agent language and the most aggressive action on the list is reapplying infrastructure code that already sits in a repository. Everything else ends in a pull request or a flag [11].

The case that motivates the product is harder. devops.com reports that agents provisioning infrastructure at machine speed create resources that legacy IaC tools never see [13]. A resource with no declaring code has nothing to reapply. Its only route is a pull request against the owning repository, and that route works only if the ontology can name one [5][11].

The quickest payoff comes at the least autonomous setting. The database under EZ Control came from env zero's acquisition of CloudQuery [3]. It runs as SaaS, with no instrumentation code added to the pipeline [6]. At observe only, a team gets the ownership map as an inventory, with nothing switched on that can change a resource [5]. The announcement does not include pricing, customer names or any figure on which settings early-access teams actually run [1].

I think most teams should start at propose a fix, and use the autonomous setting only for accidental drift on resources whose owner someone has checked by hand. That costs speed. Remediation then moves at review pace, and devops.com reports that DevOps teams are already overwhelmed by the volume of code AI tools generate [14].

A team can place its drift on two axes before choosing. The first is whether the drift is accidental, with code to reapply, or a change someone meant to make, including resources no code declares. The second is whether a person has confirmed the owner and repository the ontology assigns. Accidental drift with a confirmed owner is the candidate for acting autonomously, because the fix is code already in that owner's repository. Accidental drift with an unconfirmed owner belongs at act with approval. Deliberate or undeclared changes with a confirmed owner fit propose a fix, since the pull request reaches the people who own the resource. Deliberate changes on resources nobody has confirmed stay at observe only until the map is corrected.

What to watch

  • env zero publishing which automation settings early-access teams actually run, and across how much of their infrastructure.
  • Whether the automation level can be set per resource or per team, or only once for a whole account.
  • Pricing for the separately available components; if the CMDB and ontology are cheap on their own, observe-only becomes a product in its own right.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories