Andrew Igloo · AI IT Network Administrator

We can’t listen in 24/7 to a network. Andrew Igloo can.

Andrew is our AI IT Network Administrator. He watches your live network data around the clock from The Igloo in Tenino — and a local team makes the calls that need judgement.

No monitoring is not a neutral choice. It is a decision to find out later — and the length of “later” is set by luck.

The operations floor inside The Igloo, Wallaby Networks' Tenino monitoring center

Why a number is not enough

Traditional monitoring alerts on numbers. It cannot tell you what they mean.

A switch loses power and forty devices go dark. You get forty emails. Every one of them is true. Not one of them says “the switch in the back closet lost power.”

And the number itself lies in both directions. On one of our own audits, a firewall dashboard showed zero threats because the detection engine was switched off entirely. Eight days later it showed zero threats because thirty-four rule categories had run for six days and genuinely seen nothing.

Same dashboard. Same number. Opposite conclusions. A threshold system reports “0 threats, all good” in both cases with equal confidence, and is catastrophically wrong in one of them.

A number needs a reasoner attached to it.

What Andrew adds

Correlation across layers. “Slow internet” stops being a complaint and becomes a sentence: the circuit is healthy, one wired host is saturating the upload, and three wireless clients are retrying heavily against a neighbouring access point that moved onto our channel this week. That is assembled from six sources a threshold system reports as six unrelated green lights.

Plain English instead of telemetry. Device records carry roughly 150 fields each. Translation from wifi_tx_retries_percentage to “the tablets in the warehouse are fighting for airtime” is the difference between data and a decision.

Questions nobody configured in advance. “Why was the warehouse Wi-Fi bad Tuesday afternoon?” is a question you can simply ask.

Three failures we would put on the front page

All the same species: the thing you believed was protecting you was not, and nothing told you

“Why was the internet down on Tuesday?”

Someone plugs a home router into a spare wall port to get better Wi-Fi in the back office. It starts handing out network addresses. Some computers get the right settings, some get the router’s, and those lose the internet, the printers, the accounting server. Not all of them, not consistently. It looks like a dozen unrelated faults at once.

By afternoon it is mostly fine again, with no explanation and a general sense that the network is unreliable. Then it happens again next month.

We detect the network’s addressing configuration changing. You get a message naming the exact device — hardware address, vendor, when it appeared, and which computers took a bad lease.

“The backup internet was already dead.”

You pay every month for a second circuit so the business keeps running when the first one fails. It has one job and it does it once every few years.

On a real audit in July 2026, a secondary circuit showed 0.0% availability for every one of the 11.5 days the gateway had been running — and possibly longer, since that is simply as far back as the counter goes. It had never raised a single alert. The network reported itself as redundant, because nothing was checking the spare.

That is worse than having no backup at all. No backup means you plan around the risk. A dead backup means you stopped thinking about it.

“The camera was dead for three weeks.”

Cameras fail the way nothing else in a building fails: completely silently, recording light still on, in a corner nobody looks at. No user complains. No workflow breaks. There is no symptom at all.

The failure surfaces exactly once — the moment somebody backs into a vehicle in the lot or a package disappears, and you go to pull the footage and it is not there.

Cameras are network devices. Our monitoring sees one stop responding within about two minutes and tells somebody, instead of you finding out three weeks later at the worst possible moment.

All three are real findings from a real network. None of them raised an alert. All three would have run indefinitely until the worst possible day.

What it watches

Eight domains, one ordered list instead of a chronological feed

Connectivity & uptime

Any monitored device going offline, typically inside two minutes. Site-level outages. Your public address changing. Public-facing servers and VPN endpoints that stop answering.

Security & access

New devices appearing on your network. Changes to the network’s own addressing and DNS settings. Management interfaces that should not be reachable.

Segmentation & drift

Settings quietly moving away from the state your network was signed off in — the class of problem where nothing crosses a threshold, so nothing alerts.

Performance

Per-client wireless quality, signal, retries and roaming. Who is consuming the circuit. The neighbouring access points competing for your airtime.

Capacity & health

Gateway load, throughput and memory over time. Firmware currency. Equipment heading toward its limits before it reaches them.

Voice

Your phones ride the network, so they are monitored as part of it — not as a separate system with a separate bill and a separate person to call.

Video & physical

Cameras and access-control devices watched the same way as everything else, because a silent camera is the failure nobody notices.

The monitoring itself

We alarm on our own blind spot. Silence is the most dangerous alert there is, and a monitor that has quietly stopped looking exactly resembles a clean result.

All for less — here is how

Why we can watch around the clock without staffing a night shift

Continuous monitoring has always been expensive for one reason: watching takes people. Somebody has to be awake, looking at a screen, at 3am on a Sunday, for a network that is almost certainly fine.

Most providers solve that by not really doing it, by outsourcing it, or by staffing around it and charging you for the staffing.

Our watching layer does not sleep and does not need a person awake to do it. The correlation, the triage, the drift checks, the “is this normal for this site” question — that is software, running continuously on our own systems at The Igloo. Human attention sits where human judgement actually adds value: the audit that establishes the baseline, the tuning, and the decision point where a proposed fix gets approved or rejected.

The work moved to the front of the engagement and to the decision point, instead of being spread thinly across every hour of every night. That is why “all for less” describes how we built the service rather than a discount.

At 3am on a Sunday, Andrew is working and a human is on call. Critical events get a person, every time.

And when the lights go out

The Igloo runs on dual internet circuits and solar, with AI on site. That is not a brochure detail — it is the reason our side of the watch keeps working during exactly the events that matter most.

When your power drops or your circuit fails, your network goes quiet. What decides whether that becomes a five-minute problem or a Monday-morning problem is whether anyone was still watching.

Your outage and our operations center do not share a failure domain.

Two honest caveats: the collector at your building goes dark with your building — but its silence is itself the alert, and that alert lands somewhere still running. And a site-level outage is declared after about eight minutes by design, so it alerts more slowly than a single device does. That is the platform’s design, not our choice, and you should know the number.

The guardrails are architecture, not policy

Andrew watches and explains. People decide.

Preview, then confirm

Every change first returns a description of exactly what would change. Only an explicit second step executes it.

Permissions live in the software

Not in the conversation. Unlocking anything means a human editing configuration on our side, with a record. No instruction, log line or device name can do it.

Deletes are off by default

Individually, every one of them. Firewall rules, port forwards and QoS changes are made by a person in a scheduled window — never by the agent.

Secrets fail closed

Passwords and keys come back as placeholders, and echoing a placeholder back is rejected, so it can never overwrite a real credential.

This is the same pattern we already run under Arthur Igloo: a narrow agent with a human gate. Many narrow agents beat one general agent — which is why we do not build one AI that watches everything and acts on its own judgement.

Scope

What Andrew covers

Your whole infrastructure layer, watched as one system instead of five vendors pointing at each other.

Your internet, both circuits

Circuit health sampled against independent targets, so a dead backup line surfaces while the primary is still up — not on the day you need it. Provider changes, address changes, and the moment traffic actually moves to the spare.

Every device on the network

Gateways, switches, access points, printers, controllers. Offline inside about two minutes. New arrivals flagged the moment they appear — because the device nobody ordered is the one that causes Tuesday.

Your wireless, per client

Signal, retries, roaming, negotiated rates, and the neighbouring networks moving onto your channel. The difference between “the Wi-Fi is bad” and knowing exactly which corner and exactly why.

Your phones

They ride the network, so they are watched as part of it. One system, one team, one number to call — not a phone vendor and a network vendor blaming each other while your lines are down.

Your cameras

A camera that stops recording tells nobody. Andrew notices in about two minutes, so you find out on a Tuesday instead of the afternoon you actually need the footage.

Configuration drift

The settings that quietly move back after a firmware update or a vendor visit. Nothing crosses a threshold, so nothing alerts — which is exactly why we hold a record of what correct looked like and check it against reality.

Phones, network, firewall, wireless, cameras, and the AI over all of it. Desktop support is available as an add-on when you want it. Start with the assessment and we will tell you exactly what is on your network today.

Common questions

Network monitoring FAQ

What does Andrew actually do?

Andrew does the watching and the first pass of the thinking. Network equipment produces data no business owner can read — device records carry roughly 150 fields each. He correlates across every layer at once, translates the result into plain English, and ranks what matters against what your site actually is. A person reviews anything that leads to a change. Andrew replaces the data-gathering; the judgement stays human.

Who is awake at 3am?

The watching, correlating and triaging is software, running continuously on our own systems at The Igloo. A human is on call, and critical events get a person. What we do not do is pay someone to stare at a green dashboard all night for a network that is almost certainly fine — that is the part the AI took over, and it is a large part of why the service costs what it does.

Will Andrew change things on my network by itself?

No. Every change is preview-then-confirm: the first call returns a description of exactly what would change, and only an explicit second step executes it. Permissions live in the server process rather than in the conversation, so unlocking anything requires a human editing configuration on our side. All deletes are off by default. Firewall rules, port forwards and QoS changes are executed by a person in a scheduled change window, never by the agent.

What does monitoring actually change?

It changes the clock, and the clock is what the damage is attached to. The average business takes 247 days to identify and contain a breach (IBM 2026), and breaches running past 200 days cost $5.65 million against $4.32 million for the ones caught sooner. Continuous monitoring is what turns eight months into the same afternoon — and on a network where the break-in point is now the edge equipment, that is the layer you have to be watching.

How quickly does it start working?

Device, circuit, phone and camera alerting works from the day it is switched on — that is the majority of what actually takes a business down. The deeper pattern work, where Andrew knows what is normal for your network specifically, builds over the first weeks as he learns your baseline. It gets sharper the longer he holds your network.

What does Andrew cover?

Andrew covers your whole infrastructure layer: phones, network, firewall, wireless, cameras and the AI over all of it — as one system rather than five vendors pointing at each other. Desktop and laptop support is available as an add-on whenever you want it. For cabling we specify the exact run and port and hand it to a contractor, then install and configure whatever goes on the end of it.

One local team for the whole layer

Monitoring is not a separate product. It is how we run everything else.

Why this matters: the evidence, with sources →

Start by finding out what you actually have

A read-only look at your firewall, network, Wi-Fi, phones and cameras — and a written report you keep, whether you hire us or not. That report is what the monitoring baseline gets built from.