Avennorth
Avennorth/Contour
03Automated Service Mapping

Contour

Service maps that build themselves.

Contour ingests Pathfinder's live discovery data and builds complete service maps without a single manual entry — then computes blast radius with a deterministic BFS algorithm so your team knows the full scope of any change or failure before it happens.

CONTOUR — SERVICE MAPAUTO-GENERATED
7 services·7 connections·live
BLAST RADIUS ACTIVE
API GatewayAuth SvcOrders API4 USRAnalyticsRedis CachePostgres DBDB Replica
Orders API — blast radius
DOMAIN IMPACT
3
services hit
16
users affected
3 / 4
blast scope
0.4s
BFS time
Zero
Manual map updates
Service maps rebuild automatically from Pathfinder's live discovery data — no diagram maintenance, ever
<2s
Blast radius computed
Deterministic BFS runs on every topology change — scope is known immediately, not estimated after the fact
4
Scope classifications
Isolated, Service, Domain, and Enterprise — each tier maps to a defined escalation protocol
Topology history retained
Every map state is bitemporal and immutable — replay any moment in the past for audits or post-incident review
The Problem

Service maps are outdated diagrams nobody trusts when it matters most.

Every team has service maps. They were accurate six months ago — before the last three migrations, the containerization project, and the team turnover. When an incident fires or a change request lands, engineers spend the first 30 minutes figuring out what's actually connected to what. Contour makes the map live: automatically rebuilt from what Pathfinder actually observes, not what someone thinks is true.

Service Awareness

Not service-aware in name.
Service-aware in reality.

Contour doesn't just know which services exist. It tracks who is using each service, at what rate, and with what patterns — then continuously pushes that live intelligence to every downstream system that depends on it. Incident response, executive reporting, compliance evidence, and architecture decisions all run on Contour's live service model.

Real usage, not just existence

Request rates and active caller counts per service — continuously updated from Pathfinder's behavioral feed, not from a polling scan.

Who is using what

Active callers are tracked at the service level. Not just 'is this service up' — but which systems are actively consuming it and at what volume.

Critical data flowing downstream

Topology, blast radius, and service state push natively to Vantage, Compass, Architect, and Trust in real time — no scheduled exports, no middleware.

Zero manual refresh cycles

Every downstream consumer sees the live map. Changes propagate the moment Pathfinder observes them — not at the next batch window.

CONTOUR — LIVE SERVICE AWARENESS MAPLIVE
Services · 4 discovered
API Gateway
2,847 req/s·12 users
94%
Orders API
DEGRADED
847 req/s·4 users
67%
Auth Service
1,124 req/s·8 users
89%
Postgres DB
3,241 req/s·0 users
100%
Downstream intelligence
Vantage
Blast radius + scope pre-computed for incident response
Compass
Topology change signal → CIO executive persona
Architect
Live dependency map updated for design validation
Trust
CI evidence refreshed for compliance posture scoring
4services mapped
24active users
8.1Kreq/s observed
4systems fed
How It Works

Four steps, end to end.

01

Subscribe to the live discovery stream

As Pathfinder confirms new CIs and relationships, they feed directly into Contour's topology model in real time. No batch imports, no scheduled syncs.

02

Build service maps automatically

Service relationships, dependency chains, load balancer and firewall layers, and certificate bindings are modeled without manual input. Maps update when the environment changes — not when someone remembers to update the diagram.

03

Compute blast radius per node

Contour runs a deterministic, cycle-safe BFS algorithm across the current topology, pre-computing impact scope for every node. Change a node — Contour already knows what breaks.

04

Store state bitemporally

Every version of every map is committed to an immutable bitemporal store. You can replay the topology as it existed at any past timestamp — for post-incident review, compliance, or audits.

Who It's For

Built for the people who own this problem.

01

Change Manager / CAB Member

Reliable blast radius data before approving changes — not estimates written by the team requesting the change.

02

Service Owner

A live map of every upstream and downstream dependency, updated automatically as the environment changes.

03

IT Operations Manager

The ability to know scope immediately when an incident fires, without spending 30 minutes reconstructing topology.

04

Platform / Infrastructure Engineer

A topology history that lets them replay what the environment looked like at any point in the past.

Why Contour

Built different.

Four capabilities you won't find assembled anywhere else.

01

Zero-touch map generation

Pathfinder discovers. Contour builds.

Service maps are generated and maintained automatically from live behavioral data. If a new service appears, it's in the map. If a dependency changes, the map changes. No manual updates, no topology diagrams, no stale Confluence pages that nobody trusts.

02

Deterministic blast-radius computation

A real algorithm. Not an estimate.

Contour's blast-radius uses a deterministic, cycle-safe breadth-first search — not a heuristic. Given the same topology, the same query always returns the same scope. This reproducibility matters for change management approval, compliance documentation, and post-incident analysis.

03

Scope classification

Isolated / Service / Domain / Enterprise.

Instead of a raw node count, Contour classifies blast radius into four levels. Isolated: single service, no downstream. Service: contained within a service boundary. Domain: multi-service, same domain. Enterprise: cross-domain impact requiring executive escalation. Each level maps to a defined response protocol.

04

Bitemporal immutable history

Replay any moment in the past.

Every topology state is stored bitemporally and immutably. You can answer: what did the service map look like the moment the P1 started? What dependencies existed before the last change window? No reconstructions, no guessing — the actual recorded state.

Competitive Comparison

How Contour stacks up.

15 capabilities across service awareness, blast radius, and platform depth.

CAPABILITY
CONTOUR
by Avennorth
ServiceNow ITOM Visibility
Dynatrace
Instana (IBM)
Service Awareness
Zero-touch map generation
Service topology rebuilt continuously from live behavioral data — no human input, no diagram maintenance, ever
Auto-built from Pathfinder's live eBPF discovery stream
MANUAL RECONCILE
NATIVE
NATIVE
Real-time usage visibility
Per-service request rates and active connection counts updated continuously — not a snapshot from a last-run scan
Per-service req rates and active connections, continuously live
NOT AVAILABLE
NATIVE
NATIVE
Active user & caller attribution
Which upstream systems and users are consuming each service at this moment — not just CI health or reachability
Active callers and users tracked per service from behavioral data
NOT AVAILABLE
DEM MODULE
SEPARATE AGENT
Service health threshold alerting
Per-service health thresholds with configured escalation paths — topology context surfaced alongside the alert, not just the metric
Health thresholds with full topology context at alert time
MONITORING
NATIVE
NATIVE
Native downstream intelligence feeds
Topology and service state pushed natively to incident, executive, and compliance systems via the GPS fabric
Feeds Vantage, Compass, Architect, Trust via GPS fabric
ITSM ONLY
API ONLY
ALERTS ONLY
Blast Radius & Change Safety
Deterministic BFS blast radius
Cycle-safe breadth-first search on live topology — same query on the same topology always produces the same result
Same topology + same query = same result, every time
HEURISTIC
IMPACT ANALYSIS
NOT AVAILABLE
4-tier scope classification
Isolated / Service / Domain / Enterprise — each tier maps to a defined escalation and communication protocol
Each tier maps to a defined escalation protocol
NOT AVAILABLE
NOT AVAILABLE
NOT AVAILABLE
Single-point-of-failure (SPOF) detection
Every blast-radius node is checked for single-point-of-failure status — so on-call knows whether to wake the architecture-on-call or the operations-on-call, not just how many CIs are connected
SPOF flag on every node — architecture-on-call vs ops-on-call
MANUAL ANALYSIS
IMPACT HINTS
NOT AVAILABLE
Pre-change CAB scoping data
Blast radius and scope available before a change request is submitted — not estimated after CAB has already approved
Pre-computed scope ready before the change is raised
MANUAL SCOPE
NOT AVAILABLE
NOT AVAILABLE
Change request CAB data injection
Blast radius classification and affected service list written into the ServiceNow change record automatically — no copy-paste from a separate tool
Blast radius written into SN change request at submission time
MANUAL INPUT
NOT AVAILABLE
NOT AVAILABLE
Platform & Data
Bitemporal immutable map history
Every topology state stored immutably — any past map state is replayable for post-incident review, audits, or compliance
Any map state replay-able at any past timestamp
AUDIT LOG ONLY
ROLLING HISTORY
ROLLING HISTORY
Native ServiceNow CI population
Discovered CIs and relationships written directly into ServiceNow CMDB / HAM / SAM via the patent-protected integration layer
Patent-protected CMDB/HAM/SAM writes — no ETL layer
NATIVE
VIA API
VIA CONNECTOR
Topology drift detection
Service relationship changes detected and surfaced automatically — topology drift logged against the last known-good state
Drift from last-known-good topology logged and surfaced
MANUAL COMPARE
PARTIAL
NOT AVAILABLE
eBPF / behavioral discovery
Kernel-level traffic capture — sees ephemeral, container, and app-layer traffic that network scanners and agents miss
Via Pathfinder — sees what scanners and agents miss
SCANNER-BASED
APP-LAYER AGENT
APP-LAYER AGENT
Cross-product intelligence chain
Topology data feeds incident response, architecture design, and executive systems natively — no export, no middleware
Native feeds to Vantage, Architect, Compass
ITSM PARTIAL
STANDALONE
STANDALONE
COVERAGE (FULL OR PARTIAL)
15 / 15
9 / 15
9 / 15
6 / 15
Full native support
Partial / manual / integration required
Not available

All third-party product names and logos are trademarks of their respective owners and are used for identification and comparison purposes only. Comparisons are based on publicly available product documentation as of 2025–26 and reflect Avennorth's good-faith assessment; they do not imply affiliation, sponsorship, or endorsement.

POWERED BY INTELLIGENCE

Indicators and intelligence,
grounded in this product.

HOW INTELLIGENCE REASONS HERE

Contour feeds live service relationship data into Intelligence, which scores dependency risk and blast radius using competing models — traffic-based, relationship-class-based, and historical incident-based. The model that survives falsification determines the service health rank.

SERVICE HEALTH
  • Service health score
  • Dependency risk index
  • Blast radius estimate
  • SLA alignment score
RELATIONSHIP INDICATORS
  • Upstream dependency count
  • Downstream exposure
  • Relationship class coverage
  • Cross-domain link health
CHANGE RISK
  • Change blast radius
  • Impacted service count
  • Recovery complexity score
  • Cascading failure index
STAKEHOLDER SIGNALS
Service Owner
Health score and SLA alignment per service
Incident Commander
Blast radius and impacted services on demand
Application Portfolio Manager
Cross-domain dependency risk
Intelligence Chain

Where Contour fits in the platform.

Contour can ingest manually imported topology data as well, but its full power comes from the live Pathfinder feed — maps that are as accurate as the discovery layer is current.

Get started

See Contour in action.

Thirty minutes. A live environment. Real findings from your own data.

Book a Demo