MSP and Telco · Distributed · Multi-Tenant

Distributed Network Operations for MSPs and Large Operators

rConfig Vector gives MSPs, telcos and large enterprises a modern, distributed network control platform for managing thousands of devices across many customers and regions.

Centralise control, keep customers isolated and run configuration backups and more at scale.

data flow · 1 manager · N collectorsoutbound tls
CENTRAL CONTROLrConfig Vector Serverapi/agentsync · jobs · logs · settingsHOLDS INTENT · SOURCE OF TRUTHOUTBOUND TLS ONLYVECTOR AGENTParis10.42.0.0/16sshsnmphttpLinuxpar1par2par3par4LOCAL DEVICE FLEETVECTOR AGENTDublin10.77.0.0/16sshsnmphttpLinuxdub1dub2dub3dub4LOCAL DEVICE FLEETVECTOR AGENTNew York10.10.0.0/16sshsnmphttpWindowsnyc1nyc2nyc3nyc4LOCAL DEVICE FLEET…N
Distributed

Deploy lightweight Vector collectors into customer sites, POPs and regions.

Multi-tenant

Each tenant gets isolated inventories, jobs and an audit history.

Scalable

Stateless, horizontally scalable engines you deploy per customer, per region, or per network zone.

WHY VECTOR

Why MSPs and Large Operators
Choose rConfig Vector

Vector's multi-tenant architecture is a distributed network control platform where one deployment serves several isolated networks at once. Each tenant has its own devices, jobs, audit trail and access scope.

  1. Collect at every site without a server at every site

    Once an estate spans dozens of customer sites or regions, a single NCM instance runs out of road. Backups crawl across the WAN, every site needs its own firewall exception back to the core, and the fallback is a full server per customer with its own patching, licensing and inventory. The tooling ends up as fragmented as the networks it was meant to consolidate.

    Deploy lightweight Vector collectors into customer sites, POPs and regions. Run backups, checks, and scripts next to the devices, not across the WAN, to keep things resilient and predictable. Each site runs the rConfig Vector Agent, the distributed Go collector.

    Meet the rConfig Vector Agent
    WHERE COLLECTORS RUN
    • Customer sites
    • Branches
    • POPs
    • Regional data centres
    • Network zones behind firewalls
  2. One central manager for scheduling, search and automation

    Distributing collection usually means distributing control as well. Schedules live on one box, credentials on another, and a customer question about what changed last Tuesday turns into a tour of every site's tooling. Reports get stitched together by hand, and standards drift because there is no single place to set them.

    Use one central manager to search, report and prove compliance across every customer. Standardise policies once and reuse them everywhere while keeping your network story consistent for audits and QBRs. One central UI and API to manage tenants, policies, jobs, and compliance.

    LIVES IN THE CENTRAL MANAGER
    • Tenants and policies
    • Job scheduling
    • Inventory and history
    • Global search and reporting
    • Audit trails
  3. Tenant isolation with delegated access

    Shared tooling across customers is a standing audit risk. A single flat inventory means one engineer can see every customer, a mistaken filter shows one customer another's devices, and giving a customer any access at all means giving them everything. Most MSPs answer by never giving customers access, then fielding the same report requests every month.

    Segment customers, regions or business units with clear boundaries and RBAC. Each tenant gets isolated inventories, jobs and an audit history, and your NOC keeps one console for the whole estate. Give your NOC global visibility while granting customers scoped access to their own devices, reports and compliance status.

    PER TENANT
    • Isolated device inventory
    • Own jobs and policies
    • Own audit history
    • Scoped customer access
    • Hierarchical RBAC across the NOC
  4. High availability into the thousands of devices

    Scale exposes single points of failure. One collector host goes down and a whole region misses its backup window, while the central server becomes the one machine nobody dares to patch. Growth then means a hardware conversation every time a new customer signs, rather than a capacity one.

    The Vector central manager supports active or warm-standby HA pairs with shared storage for inventory, audit history, and policies. Collectors are stateless and horizontally scalable, so you can run multiple collectors per tenant or per region behind health checks. Job state is persisted centrally, so a failed collector hands work off to a peer rather than losing scheduled backups.

    BUILT FOR SCALE
    • Active or warm-standby HA pairs
    • Stateless, horizontally scalable collectors
    • Multiple collectors per tenant or region
    • Health-checked collector pools
    • Peer hand-off of failed jobs
ARCHITECTURE

A Modern Control Plane with
Collectors Wherever You Need Them

rConfig Vector separates the control plane from execution. The central manager sets the rules; collectors handle work where the devices live, giving you low-latency distributed network control platform and clear governance at MSP scale.

  1. TIER 1

    Central Manager

    One central UI and API to manage tenants, policies, jobs, and compliance. Inventory, history, and audit trails live here, giving your NOC and engineering team a trusted source of truth.

    • Tenants
    • Policies
    • Jobs
    • Compliance
    • Inventory
    • History
    • Audit trails
  2. TIER 2

    rConfig Vector Agent collectors

    Stateless, horizontally scalable engines you deploy per customer, per region, or per network zone. They handle backups, config retrieval, command execution, and policy checks close to the devices.

    • Backups
    • Config retrieval
    • Command execution
    • Policy checks
  3. TIER 3

    Devices and services

    Routers, switches, firewalls, CPEs, GPON/FTTH kit, DC networks, wireless, IoT, and OT. Vector gives you one consistent way to back up, validate, and report on configuration state for all of them.

    • Routers
    • Switches
    • Firewalls
    • CPEs
    • GPON/FTTH
    • DC networks
    • Wireless
    • IoT
    • OT

Built to keep MSPs and customers safe

Vector is self-hosted and designed for regulated environments. You control where collectors run, which networks they can see, and how credentials are managed. Each site runs the rConfig Vector Agent, the distributed Go collector. Tight RBAC, tenant isolation, and full audit data make it easier to answer hard questions from security, regulators, and customers.

DEPLOYMENT FLEXIBILITY
  • Deploy central manager on-prem or in private cloud
  • Run collectors in DCs, branches, POPs, or customer sites
  • Support for HA patterns and regional failover designs
  • No SaaS dependency. Data stays inside your own perimeter.
IN PRACTICE

How rConfig Vector is
Used in Production Today

Vector is built for operators that live in the real world: SLAs, audits, outages and growth. These are the patterns we see most often across our MSP, telco and enterprise customers.

TRUSTED WORLDWIDE
  • SNCF
  • Siemens Energy
  • Equans
  • Bacardi
  • JCDecaux
  • Assurant
  • CVS Health
  • Singtel
  • Royal London
  • P&G
  • Motorola
  • Jysk
PROOF
“We used to joke that our automation was held together with zip ties and prayers. rConfig V8 changed that. Multi-site support, proper parallel jobs, fault tolerance, we finally have an NCM platform we don’t have to babysit. Retiring the legacy stuff felt amazing.”
Marcus HaleEnterprise Network Architect
AROUND VECTOR

Above Vector,
and in front of it.

Enterprise

Operate at your scale

Support complex infrastructure with architecture and expertise tailored to your environment.

Explore Enterprise

Vector Prism

The front-office layer

Give every customer their own branded, MFA-secured portal scoped to their devices. Tags map to teams, teams map to customers, and the whole thing runs on your own infrastructure. A separate product on the same stack, priced by customer count and branding requirements.

Explore Vector Prism
FAQ

rConfig Vector, Frequently Asked Questions

Everything you need to know about running rConfig Vector as a shared service, from architecture and tenancy to pricing, onboarding and regulation.

What is rConfig Vector and who is it for?

rConfig Vector is a distributed, multi-tenant Network Configuration Management (NCM) platform designed for Managed Service Providers (MSPs), telcos, and large enterprises that operate many networks across different customers, regions, or business units. It combines the full NCM feature set of rConfig V8 Pro with a three-tier architecture that separates the central control plane from the collectors that run close to devices. Vector is ideal if you manage dozens of customers, multiple network zones, or geographically distributed environments and need standardised configuration backups, compliance, and change control without losing per-tenant isolation or control. Explore Vector use cases

How is rConfig Vector different from rConfig V8 Pro?

rConfig V8 Pro is a powerful, single-instance NCM platform suited to organisations that want one deployment for up to 1,000 devices. It provides automated backups, search, diff, rollback, compliance checks, RBAC, and integrations. All from a single control plane. rConfig Vector takes that same core feature set and extends it for MSP and operator use cases. It introduces a central manager with support for multiple tenants, distributed Vector collectors, tenant-by-tenant isolation, hierarchical RBAC, and global policies that can be reused across customers and regions. Vector is the right choice when you need to run NCM as a shared service across many environments. See what’s included from V8 Pro

Can rConfig Vector help us replace tools like Oxidized, RANCID, CatTools or homegrown scripts?

Yes. Many Vector deployments start as a consolidation project: replacing a mixture of Oxidized, RANCID, Kiwi CatTools, Ansible and Python scripts, or legacy NCM add-ons from other platforms. Instead of maintaining separate pipelines and cron jobs per customer or network, Vector gives you a centralised inventory, policy engine and audit trail across all environments, while still allowing you to run jobs close to devices via the rConfig Vector Agent at every site. You can migrate in stages, moving customers or regions to Vector one at a time while preserving your existing automation, then gradually standardising on Vector’s APIs, compliance engine and workflows for new services.

Is rConfig Vector suitable for NIS2, DORA, and other regulatory frameworks?

rConfig Vector is self-hosted and designed to support operators working under NIS2 compliance, DORA compliance, ISO 27001, CIS, and similar regulatory frameworks. It helps you demonstrate control over configuration, backups, change workflows, and access, which are all expected elements of modern operational resilience and cyber-security regimes. Because Vector’s central manager and collectors run in your own environment, you can align deployment with data residency, sovereignty, and segmentation requirements. Per-tenant audit trails and compliance reports make it easier to answer questions from regulators, customers, and internal risk functions. Learn more about compliance and regulation

How does Vector handle multi-tenant separation and access control?

Vector lets you define tenants that represent customers, regions, or internal business units. Each tenant has its own devices, jobs, policies and audit history. Vector’s hierarchical RBAC model allows your NOC and engineering teams to see and manage multiple tenants, while granting scoped access to customer administrators or limited support teams. This model is particularly valuable for MSPs who want to give customers visibility into their own configuration backups, change history, and compliance status without exposing other customers or internal-only data. View multi-tenant Vector capabilities

What deployment options are available for rConfig Vector?

rConfig Vector is deployed as a self-hosted solution. You can run the central manager in your own data centre or private cloud, and place collectors wherever they make the most sense: customer sites, regional data centres, POPs, or specific network zones behind firewalls. Our team can help you design highly available deployments, regional failover patterns, and migration plans from existing NCM platforms. We also offer professional services for complex MSP and multi-region architectures, and you can see Vector pricing alongside the other rConfig editions. Explore Vector architecture options

How is rConfig Vector priced?

Vector is licensed per managed device with a base subscription that includes the central manager and an unlimited number of collectors. Pricing tiers are designed around MSP scale, so onboarding additional customers does not require additional infrastructure licences, only device capacity. You can see Vector pricing alongside V8 Pro and V8 Core, or contact our team for a quotation shaped to your customer count, device count, and required regions. Request a Vector quotation

How long does it take to onboard the first MSP customer?

For a new Vector deployment, a first customer typically goes from installation to first successful tenant-isolated backups within one to two weeks. The first week covers central manager install, credential vault setup, and tenant model design. The second week covers collector deployment at the customer site, device import, and policy and report configuration. Subsequent customers onboard much faster: deploy a tenant-scoped collector, import devices, attach the global policies you have already defined, and grant scoped portal access. Most MSPs settle into a one to three day onboarding pattern per new customer once their tenant template is stable.

Does Vector integrate with ITSM and PSA tools like ServiceNow, Jira, or HaloPSA?

Vector exposes a documented REST API that lets you connect NCM events and inventory to ITSM platforms such as ServiceNow and Jira, and to PSA platforms commonly used by MSPs, including HaloPSA, Autotask, and ConnectWise. Typical integrations create change tickets from configuration drift, attach diff output to change records, and post compliance breaches into customer-specific queues. For platforms without a packaged connector, Vector’s webhooks and API tokens are designed to plug into iPaaS tools like n8n, Make, or Workato so you can build connectors without changing the core product.

Can Vector feed AI copilots and automation pipelines with configuration data?

Yes. Vector’s API-first design exposes inventory, configuration history, diffs, and compliance state as structured data that AI copilots and automation pipelines can consume. Common patterns include retrieval-augmented assistants that answer engineer questions from current configurations, agents that propose remediations from drift events, and pipelines that gate change automation behind policy checks. Because Vector runs in your environment, the configuration data and credentials never leave your perimeter. You decide which subsets of data your AI tooling can read, and on what cadence.

Can Vector be deployed in EU and US regions to meet data residency rules?

Vector is fully self-hosted, so you choose where the central manager runs and where collectors live. Common patterns include a single central manager in your primary region with collectors in EU and US tenants, or fully separate Vector deployments per jurisdiction when regulation requires that no metadata leaves the region. For EU operators with NIS2 obligations and US operators with sector-specific frameworks, this lets you align deployment topology with the rules you actually need to satisfy, rather than working around a SaaS vendor’s region map.

What HA and failover patterns does Vector support?

The Vector central manager supports active or warm-standby HA pairs with shared storage for inventory, audit history, and policies. Collectors are stateless and horizontally scalable, so you can run multiple collectors per tenant or per region behind health checks. Job state is persisted centrally, so a failed collector hands work off to a peer rather than losing scheduled backups. For multi-region deployments, customers commonly run an HA central manager in one region with read-replica or warm-standby in another, plus collector pools per region. Our team can review your topology and recommend a pattern that matches your RTO and RPO targets.

Standardise NCM across every customer, site, and region

rConfig Vector is the distributed control plane for MSPs, telcos, and multi-region enterprises. Deploy collectors close to your devices, keep tenants cleanly isolated, and run one consistent NCM story across the whole estate.