Filamental for IT and networks

Trace the outage back to the decision that caused it

Monitoring tells you what is down. The ticket tells you what the user noticed. Neither tells you that the array was sized in 2024 against a forecast nobody wrote down. Filamental holds the estate and the reasoning as one thing, so the chain from symptom to cause to decision is something you click through rather than something you remember.

The picture nobody else can see

Four tools, four slices, and the part that joins them is in your head

Monitoring shows you what is down right now. The asset register shows you what exists and who signed for it. The ticket shows you the symptom a user noticed. The wiki shows you what somebody found time to write up eighteen months ago, and the diagram was accurate the week it was drawn.

What none of them holds is the chain, and the chain is the entire job. You know the login delay is storage before you have opened anything, because you know what sits behind what. That knowledge is the most valuable thing in the department and it cannot be queried, audited, handed over or backed up.

What it actually does

The diagram and the manual stop being two documents

Every switch, host, array, service, site, vendor and person is a node. The lines between them are typed and directional, and you name the types yourself, so depends on, uplinks to, brokers sessions for and managed by are different relationships rather than one grey line meaning "related". Open any node and everything joined to it is listed, in both directions. Tracing four layers down is four clicks, and tracing back up from the array to every service that would notice is the same four clicks in reverse.

Then the part a diagram cannot do. The note explaining why a thing is the way it is sits on that thing, not in a separate document that was current once. Why the array is that size. Why that VLAN exists. Why the firewall rule nobody dares remove was added, and by whom, and for what. The reasoning stops being a parallel artefact that goes stale and becomes a property of the estate itself.

And because a space is a folder of Markdown files with nothing proprietary in it, you can put the whole thing in Git. Commit it, review a change to the estate in a pull request, and get a line-by-line history of who changed which part of the documentation and when. Your infrastructure notes get the same treatment as your infrastructure code.

A worked chain, mid-investigation

Forty-second logins, four hops down, and a forecast from 2024

A 120-person accountancy practice in Bristol. One four-floor office, a hybrid Azure and on-premise estate, forty thin clients on the tax and advisory floors, and one IT manager with an outsourced provider for out-of-hours. For ten days the help desk has been taking the same call: logins that used to take eight seconds are taking over forty, and only during the nine o'clock rush.

The chain is short and it is already written down. The thin clients depend on the session broker. The broker depends on the application server. The application server depends on the array, which is at ninety-one per cent and where write latency has started climbing under load. Four hops, and the systems administrator investigating it did not have to know the estate to walk them.

The fourth hop is where the page stops being about topology. The array was sized during the 2024 refresh, against a growth forecast the IT manager put together at the time. That forecast, and every assumption inside it, exists in his memory and in one PDF from the consultant who did the refresh. The chain gets anybody to the array. Only one person in the building can say why it is eighty terabytes, and that is the sentence that belongs on the node.

The Core Switch node open in an office network space, a Cisco Catalyst 9500 typed as a Network Device. Its notes read that it is the backbone switch connecting both distribution switches, the storage array and the host cluster, and that everything east-west on the network passes through it. Below them its five relationships run out to both distribution switches, the edge firewall, the storage array and the host cluster, and the graph behind shows the same chain reaching the login latency issue and the Bristol office floors.
The same office network space with the graph on the left and Publisher on the right. The published page carries a photograph of a server rack as its cover, the Core Switch heading, and the note about east-west traffic set as a pull quote rather than as body copy. A Share button sits in the toolbar and the document is marked unsaved.
What it wants access to

Nothing. It never touches the network.

No agent to deploy, no scan range, no read-only service account, no SNMP community string, no API token and no firewall exception. It does not discover, poll or alert, and it has no opinion about your subnets because it cannot see them. It is a desktop application that reads a folder on the machine it is installed on, and it runs with the cable out.

There is no account, no sign-in and no telemetry, which is a decision rather than a setting: nothing is collected, so nothing can be requested, leaked or subpoenaed. It is a Tauri application, meaning a Rust core and the system webview rather than a bundled copy of Chrome, which is also why it starts like a native tool instead of a browser pretending to be one.

It will not monitor anything, page anyone, or tell you a disk is filling up. Keep whatever does that. This is for the layer above it, which nobody has ever sold you software for.

The people who ask for it

Everything you know, in a form somebody else can read

The provider taking the call at two in the morning has your runbook and none of your context, so the escalation costs an hour of explaining before it costs anything else. The insurer wants a current picture of the estate. The auditor wants to see that a control applies to the thing it claims to. The director signing off the refresh wants to understand the spend without a forty-minute meeting, and reading a network diagram is not a skill anybody outside this department has.

All four are the same job: taking what is in your head and putting it somewhere another person can follow. A space can be sent as a link or a single file that opens in an ordinary browser, with the structure navigable inside it and the notes attached where they belong. They install nothing and pay nothing. It is also, quietly, the strongest thing you can leave behind on the day you hand the department to somebody else.

Where you start

Four Templates ship for this work

You do not begin with a blank screen. A Template is a starting vocabulary, the kinds of thing that exist in a job and the ways they relate, so the categories are already there and already coloured when you make a space.

Included, on every plan
  • Network Topology. Device, Network Segment, Connection Point, Protocol, Service, Location. Joined by connects to, routes through, hosts, depends on and managed by.
  • Security Operations. Asset, Vulnerability, Control, Threat, Policy, Incident. Joined by mitigates, exposes, applies to, triggers and owned by.
  • Incident Response. Incident, Affected System, Action, Team, Impact, Timeline Event. Joined by triggered by, affects, resolved by, escalated to and depends on.
  • Cloud Architecture. Service, Region, Account, Network, Data Store, Resource Group. Joined by connects to, depends on, managed by, replicates to and scales with.

A starting point, not a schema you are stuck inside. Rename a category, add one, delete the ones you never use. Sixty-one Templates ship in total, and nothing stops you using more than one in a space. System Component Map and Capacity & Scaling are the two next door most often reached for.

What this costs you

No per-device pricing, and no per-seat ladder

Everything above except the sending is on the free plan, permanently, with no account and no card. Nothing here is metered by how many devices you document, which is the pricing model this category usually reaches for and the reason documenting an estate properly normally has a budget line.

Spaces are unlimited and the bridges joining them are free, so an estate becomes a handful of linked spaces rather than one impossible diagram: core network in the first, virtualisation and storage in the second, identity and cloud in the third, each holding twenty nodes and each one click from the others. That is close to how you would draw it on a whiteboard regardless.

The paid tier is $120 a year and buys exactly one thing: handing a space to somebody who does not have Filamental. For most departments that is the audit, the insurance renewal, the board paper and the handover, which is a handful of times a year and worth the money on the first one.

Asked before downloading

Six straight answers

Does Filamental discover my network automatically?

No, and that is deliberate. There is no agent to deploy, no scanning range to configure, no read-only service account to create and nothing that touches your network at all. You describe the estate yourself, which is slower to start and is the reason the result is worth reading: a discovery tool inventories what answers a probe, and the thing you actually need written down is why the estate is the shape it is.

How is this different from a CMDB or a Visio diagram?

A CMDB records that a configuration item exists and who owns it. A Visio diagram is accurate the week it is drawn. Neither holds the reasoning, so the answer to why a device was sized the way it was still lives in somebody's memory. In Filamental the note explaining a decision sits on the device itself rather than in a separate document, and the dependencies are walkable in both directions, so tracing a symptom to a cause is clicking rather than remembering.

Can I keep my network documentation in version control?

Yes. Every node is a Markdown file with YAML frontmatter in an ordinary folder on your disk, so a space is a repository like any other. Commit it, branch it, diff it, review a change to the estate in a pull request, and get a line-by-line history of who changed which part of the documentation and when. Nothing about the format is proprietary.

Does Filamental send anything to a server?

No. There is no account, no sign-in and no telemetry of any kind, which is a deliberate product decision rather than a setting. It is a desktop application for Windows, macOS and Linux that reads files on your own disk, and it works with the network cable out. The only outbound request it ever makes is the update check, and that carries nothing about your data.

Can I hand the map to an MSP or an auditor who does not have Filamental?

Yes, and it is the one thing the paid tier buys. Publisher turns a space into a document you send as a link or a single HTML file, and it opens in an ordinary browser with the graph navigable inside it. Whoever receives it installs nothing, signs up for nothing and pays nothing. That is $120 a year for you, and it is the only paid feature.

What does Filamental cost for a small IT team?

The Personal plan is free permanently, with no account and no card. Spaces are unlimited and the bridge nodes joining them do not count against anything, so an estate becomes a few linked spaces rather than one enormous one: core network in the first, virtualisation and storage in the second, identity and cloud in the third. Each holds twenty nodes. The paid tier is $120 a year and buys sending a space to somebody who does not have Filamental.

Start with the thing that is broken

Open Network Topology and put in the chain you are debugging today

One incident is enough to find out whether this suits how you work. Free, no account, no card, and nothing on your network either way.

Version
0.3.36
Platforms
Win / macOS / Linux
Personal
Free, permanent
Professional
$120 / year