Ninja Labz blog
We Built Five Globes and Forgot Four of Them
Ontology Ops, or how I discovered what I own by asking a machine to read my notes.
Every organisation has an asset register. It is a spreadsheet, it is colour-coded, and it is a photograph of a tide. You know this. I wrote a book about it. I then went and did exactly the same thing, at scale, on my own estate, which I suppose makes me the control group.
Here is how I found out.
Over the last year I have built a security platform. Several, actually, which is the problem. Threat intelligence, a SIEM, attribution engines, sensors, a lab, films, a newspaper. It runs on two servers. It is maintained by me and a team of AI engineers who do not sleep, do not forget, and do not, it turns out, remember either, because nobody asked them to.
So one night I asked one of them a simple question. What have we actually built?
It read everything. Every repository. Every note. Every scheduled job on both servers. Every public page, which it checked by visiting. It came back about eleven minutes later with a graph.
566 things. 1,120 connections between them.
247 live. 163 behind a login. 48 useful documents that exist only on my laptop, which is the enterprise equivalent of the strategy deck saved to someone’s desktop by someone who has since left. 39 things decommissioned. 15 retired. 21 things that were built and never deployed. 17 ideas.
And then the bit that made me put the tea down.
Five globes. Five rule generators. At least ten daily briefs. Four separate ways of collecting social media.
I did not decide to build five globes. Nobody decides to build five globes. You build one globe, it is lovely, you move on, and six weeks later a different part of you, with the wounded confidence of the genuinely innocent, builds another globe. Nobody told the second globe about the first globe, because the last time anyone told anyone anything it needed a change advisory board, and I am the change advisory board, and I was busy building a globe.
Maureen from Governance, Risk and Compliance would like it noted that this is not a failure of engineering. It is a failure of memory. She is right. She is always right. It is her least endearing quality.
What Ontology Ops actually is
It is a map of everything, stored as a graph, kept honest by the thing that builds it.
Every node is a real thing: an app, a feature, an agent, a data feed, a public page, a film, a domain, a script, a document, an idea. Each one carries the things a CMDB always promises and never has:
- Status, and not just “live”: gated, parked, decommissioned, retired, local-only, built-but-never-deployed, idea. The difference between decommissioned and stopped appearing in the register is, as every incident report eventually admits, the entire incident.
- Where it lives. Not “the platform team”. The actual place.
- Why it matters, in one line. If nobody can write the line, that is also information.
- Evidence. Where the claim came from. A map without evidence is a rumour with a legend.
And the edges are the point. This feeds that. This depends on that. This runs on that box. This was superseded by that. This produces that page. You can stand on any node and walk. What breaks if this box dies? What did we already build that does this? What is exposed at this domain? One hop, not one workshop.
Niko, our resident AI, summarised the first draft as “a comprehensive, multi-dimensional asset intelligence capability with strong strategic alignment”, and recommended a steering group. We declined. The steering group is how it starts.
The forgotten gems
The most useful page it produced was not the map. It was the list of things I had built, liked, and lost.
Twenty-two of them. Finished writing nobody published. A tool whose download link had been quietly returning 404. An experiment whose headline result was wrong but whose side results were better than most things I have shipped on purpose. A leaderboard where AI agents fought each other and were ranked like chess players, which I had genuinely forgotten existed, which is not a sentence anyone should be able to say about a leaderboard where AI agents fight each other.
It also sorted them. Some gems are safe to talk about. Some need a decision first: publishing some kinds of work early can destroy your ability to protect it, and some need somebody else’s permission. A map that knows what not to say is worth more than one that knows everything.
From tomorrow, the safe ones go in the paper. One a day, in a section called From the vault. The newspaper my AI writes every morning now also reminds me, in public, of what I forgot. I have outsourced my conscience to a cron job, and the cron job is punctual.
Why we did it (the honest version)
Because in one night of building, this is what the map would have caught:
- A public page, our Threat Theatre, had been quietly sending every anonymous visitor to a login screen for four days. A hardening change upstream made one of its data calls private, and the page’s error handling did the rest. Nothing failed. Every check was green. Every dashboard is green until the precise moment a dashboard would have helped.
- Our deep-reading AI had read every item it was given, faithfully, and then used seven per cent of what it read, because its notes were being cut off mid-sentence and discarded without complaint. It had done the work. The work had not arrived.
- Eleven apps held a live key to a paid AI service. Seven of them did not need it that week. Finding the eleven took a scan; deciding which seven took minutes rather than a meeting, because for once we knew what each app was for.
None of these were hacks. None of them would have shown up in a penetration test. All of them were the gap between what we believed we had and what we had. That gap is where most incidents live. It is also, reliably, on a Friday.
Why it’s a great idea for enterprises
Your organisation already has four of these. It has a CMDB, an asset inventory, a service catalogue and an architecture repository, and they disagree with each other in ways that would be charming if they were not load-bearing. Each was accurate on the day of the audit, by a person who also wanted to go home.
Ontology Ops is different in three ways, and none of them is the technology.
- It is built by reading, not by asking. Nobody fills in a form. The source of truth is the code, the configuration, the schedules and the notes, which are the only documents in any organisation that are updated by people who have to live with them.
- It is a graph, not a list. Lists answer “what do we have”. Graphs answer “what happens if”, which is the only question anyone asks at 2am.
- It is maintained by the same hands that change the estate. When we build something, the map is updated in the same breath: the perimeter graph went in the day it was built, and the switch-offs were marked the morning they happened. Making that automatic is the next job. The map is not a project. It is a side effect of doing the work properly, which is the only kind of documentation that has ever survived contact with a reorganisation.
And there is the quiet commercial point. Five globes is five times the build cost, five times the maintenance and five times the attack surface for one globe’s worth of value. Every enterprise is paying for its five globes. Most of them are paying for them on different budget codes, which is how you know they are enterprise globes.
The limits, because this crowd will find them anyway
It is a first draft. It knows what the code says, not what the code does under load. It described login-gated features rather than using them. It will be wrong in places, and the fix is the same as for any map: someone walks the ground and corrects it. The difference is that correcting it takes one command, and it keeps the receipts.
It also contains things no attacker should see: where everything lives, what is unfinished, what is switched off. So it sits behind the owner’s login and nobody else’s. An estate map is the most useful document you own. It is also the most useful document an adversary could find. Treat it like both.
Everything is probably fine.
We now have a graph of exactly how probably, and five globes to look at it on.
ScottG · Ninja Labz · ninjalabz.io
Every morning at 06:00 UK an AI reads every threat-intel item from the last 24 hours and writes the paper, with receipts.
Read Probably Fine Daily