Monitoring, not control
There is a temptation, once a tool can see everything, to let it start touching things too. If it already knows a rack is overheating, why not let it throttle the cooling? If it can see a firewall misbehaving, why not let it push a rule? Stratum draws a hard line here, on purpose: it monitors and advises. It does not control.
Stratum does not power-cycle devices, change cooling setpoints, edit firewall policy, or perform autonomous remediation. It is read-oriented by design. It observes, alerts, reports, and, where useful, suggests where an operator should look next. The action stays with the human.
Why keep the line
A monitoring system that can change the environment it watches is a much larger risk surface. It needs write access to critical infrastructure, and a bug or a bad inference can now cause an outage instead of just mislabeling one. Keeping Stratum on the observe side of that line makes it something IT and security teams can actually approve: it reads, it does not reach in.
It also keeps the trust model simple. Remote probes push telemetry into the core, but probe credentials are scoped to exactly that. They are not operator logins, and they cannot read dashboards or change configuration. Every credential does one narrow job.
Advisory, with guardrails
Optional advisory logic can summarize conditions and point you toward what deserves attention first. That is guidance, not automation. It never crosses into acting on the environment. The same discipline carries into Delta, our upcoming data-center layer for power, cooling, and rack analytics: more insight into the hardest part of the room, still firmly monitoring and advisory only.
Knowing what is happening is valuable on its own. It does not require handing a machine the keys to your infrastructure.
Want the detail on the security posture? The setup guide covers it, or get in touch.