Use case 01 of 03 day one read-only
Know what your network is actually doing.
Before anyone signs off that the estate is segmented. Every rule and every flow comes back classified, with a reason attached rather than a hit count.
69%
of firewall rules are unused FireMon Insights 2.0 · 9.2m policy checksacross hybrid networks · Jun 2026
45%
have no owner or documentation Same dataset · 17% redundant or shadowed outright58%
of firewalls fail a high-severity compliance check Same dataset · 48% fail at critical severityWhat we move: those three stop being estimates. Measured on your estate, in the first read-only pass — no change window, no risk committee. Industry baselines shown, not our results.
0100 the output
Every rule, classified — with the reason.
Used, and justified
The flow exists, it maps to a declared intent, and the rule that permits it is the narrowest one that would. Nothing to do.
Used, never declared
Real traffic nobody wrote down. Each one becomes a question with an owner attached, not a line in a diff.
Declared, never used
The rule that outlived its reason. Proposed for retirement only after it has held its full observation window — never on a hit count alone.
A hit counter tells you a rule fired. It never tells you whether it should have.
Works on estates with zero Kubernetes — configuration exports and flow records are enough for the first pass.
0200 the mechanism
Three sources. One three-way compare.
Declared intent, the configuration actually in force, and the traffic actually observed — held against each other as a set operation rather than an interpretation. That is the whole of the first two weeks.
Read-only throughout. Nothing is written to the network during the audit.
e000 End.DT6 deliver
See it against your own kit.
30–60 minutes. Read-only. We compare your declared intent to what is actually running, and hand back the gap list.
Savings are computed from your own estate in the first two read-only weeks — never from our slides.