Make incompatible systems behave like one system.
Install · Capabilities · Tools · Architecture · Contributing
System 8 is an integration and automation practice focused on the joins between systems: identity, Microsoft 365, endpoints, infrastructure, applications, agents, data and the humans operating them.
The work is not limited to a vendor stack or interface. The operating problem is treated as one system, then reduced to explicit contracts, observable state and recoverable execution.
people → interfaces → applications → automation → platforms → infrastructure
L0 L8 L7 L6 L5–3 L2–1
Layer 0 is human context. A technically correct system that people cannot operate, trust or recover is incomplete.
| Domain | Typical work |
|---|---|
| Microsoft 365 | SharePoint, Teams, Purview, Entra ID, Power Platform, Graph, licensing and governance |
| Identity and access | Authentication, authorization, lifecycle, conditional access and cross-system identity mapping |
| Infrastructure | Windows, networking, TLS, DNS, endpoints, policy, deployment and operational diagnostics |
| Automation | PowerShell, APIs, browser automation, scheduled workflows, agents and event-driven orchestration |
| Data and middleware | Schema translation, adapters, migration, synchronization, audit trails and compatibility layers |
| Interfaces | Web, desktop, mobile, voice, DTMF, kiosk, dashboard and operator tooling |
| Operational control | Validation, dry runs, snapshots, rollback, observability and deterministic recovery |
The repository includes a PowerShell 5.1/7-compatible package manager for System 8 tools.
$url='https://raw.githubusercontent.com/enkayz/system8/0bb95a0eecd2302a46bd48ea73b7f30f710e06c9/tools/s8/install.ps1'; $path=Join-Path $env:TEMP 'system8-install.ps1'; Invoke-WebRequest -UseBasicParsing $url -OutFile $path; if((Get-FileHash $path -Algorithm SHA256).Hash.ToLowerInvariant() -ne '638e863bc2ae3a24af631b9d0fd88f71eef44c02d6229fe52ae85a880caf9069'){Remove-Item $path -Force; throw 'SHA256 mismatch; installation stopped.'}; & $path -NoAdmxThe bootstrap is pinned to an immutable commit and verified before it self-elevates, installs s8, and adds it to the machine PATH. The installed CLI independently verifies its pinned payload, stable manifest and package archive. Automatic ADMX installation remains disabled; operators can install the now-verified package explicitly with s8 install admx.
s8 list
s8 search m365
s8 install m365
s8 update m365
s8 doctor
s8 rollback m365
s8 remove m365The previous dashboard-v1.0.0 binary is withdrawn from supported installation paths because its per-user command map predates the current launchers. Do not install that release. The corrected dashboard source remains available for review, and a new Windows artifact must pass the same immutable-chain and launcher-parity checks before publication.
Source and current release status: tools/s8/dashboard
The government-generic feature pack focuses on a portable public catalogue rather than one buyer or one platform:
- Land asset sales migration — catalogue, GIS, temporal history, portability, legacy automation, security and migration gates.
- Machine-readable feature registry — ten outcomes with explicit evidence requirements.
- GitHub and library discovery keywords — Australian GIS, open standards, temporal maps, platform migration and security candidates.
- TLS management and DLP management — bounded public-edge and information-protection controls.
The synthetic source inventory contains no production data and can be executed through the offline migration estimator.
A common bootstrap and lifecycle layer for System 8 utilities.
- PowerShell 5.1 and 7 runtime support
- UAC self-elevation
- machine-level command registration
- stable, preview and nightly channel model
- package installation state
- update, diagnostics, removal and rollback
Source: tools/s8
Read-only tenant assessment utilities built around Microsoft Graph and explicit evidence output.
s8 install m365
s8m365 inventory -InstallDependencies
s8m365 licenses
s8m365 labels
s8m365 sharing
s8m365 full- tenant, user, group and directory-role inventory
- licence capacity, consumption and utilization analysis
- enabled unlicensed account detection
- disabled accounts retaining licence assignments
- sensitivity-label and policy-readiness evidence
- SharePoint site, guest identity and external-domain assessment
- JSON, CSV and styled HTML output
- partial-collection error reporting without invented results
Source: tools/s8/packages/m365
The stable catalogue also contains focused tools for recurring discovery, assurance and planning work:
| Package | Installed command | Operator output |
|---|---|---|
m365-governance |
s8gov |
Entra, consent, Conditional Access, stale identity, Teams and SharePoint governance evidence |
m365-license-optimizer |
s8license |
SKU utilization, dormant or disabled licensed users and customer-priced savings candidates |
m365-tenant-diff |
s8diff |
Normalized point-in-time snapshots and offline added/removed/changed configuration reports |
m365-sharepoint-modernizer |
s8spmodern |
Site and library inventory, stale/scale flags and an advisory modernization plan |
m365-security-baseline |
s8baseline |
Conditional Access, privileged-role and enterprise-application baseline findings |
m365-migration-estimator |
s8migrate |
Offline migration effort, elapsed-time, risk and optionally customer-priced cost estimates |
m365-entitlement-advisor |
s8entitlement |
Live service-plan entitlement compared with explicit persona and capability requirements |
m365-change-impact |
s8changes |
Service health and Message Center changes prioritized against tenant scale |
m365-copilot-readiness |
s8copilot |
Copilot licence, site lifecycle, collaboration-risk and pilot-gate evidence |
m365-access-explainer |
s8access |
User access paths through nested membership, applications, ownership and licensing |
m365-leaver-readiness |
s8leaver |
Ownership, reporting-line, membership and OneDrive dependencies before offboarding |
m365-recovery-readiness |
s8resilience |
Emergency access, privileged redundancy, domain and application credential recovery posture |
s8 install m365-license-optimizer
s8 install m365-tenant-diff
s8 install m365-sharepoint-modernizer
s8 install m365-security-baseline
s8 install m365-migration-estimator
s8 install m365-entitlement-advisor
s8 install m365-change-impact
s8 install m365-copilot-readiness
s8 install m365-access-explainer
s8 install m365-leaver-readiness
s8 install m365-recovery-readiness
s8license full -InstallDependencies
s8diff capture -InstallDependencies -OutputPath .\tenant-baseline
s8spmodern full -InstallDependencies
s8baseline full -InstallDependencies
s8migrate template -OutputPath .\migration-estimate
s8entitlement template -OutputPath .\entitlement
s8changes full -InstallDependencies
s8copilot full -InstallDependencies
s8access explain -UserPrincipalName user@contoso.com -InstallDependencies
s8leaver assess -UserPrincipalName leaver@contoso.com -InstallDependencies
s8resilience full -InstallDependenciesGraph-connected packages request delegated read scopes and preserve partial collection failures in collection-evidence.csv and JSON. The migration estimator is offline. The focused operator packages produce CSV, JSON and styled HTML, and none performs remediation.
The rationale for the newest operator workflows, including the market gaps they address and their external references, is documented in docs/M365-OPERATOR-GAPS.md.
Windows-native administrative-template repository manager designed for local PolicyDefinitions stores and Active Directory Central Stores.
- package import and staging
- ADMX/ADML XML validation
- SHA-256 inventory
- deployment dry runs
- pre-deployment snapshots
- transactional store replacement
- rollback and failure recovery
Source: tools/admx-manager
System 8 integrations are built around five invariants:
- Contract first — every boundary has an explicit input, output, ownership and failure mode.
- Observable state — operators can determine what happened without reverse-engineering the implementation.
- Reversible change — deployment includes validation, snapshot and rollback paths.
- Minimum coupling — adapters isolate vendor and platform assumptions.
- Layer 0 included — workflows are designed around the actual operator, not an imaginary perfect user.
The full model is documented in docs/INTEGRATION-MODEL.md.
.
├── assets/brand/ System 8 visual assets
├── docs/ architecture and operating model
├── tools/
│ ├── s8/ System 8 package manager and package catalog
│ │ └── packages/
│ │ ├── admx/ ADMX package lifecycle
│ │ ├── m365/ Microsoft 365 assessment toolkit
│ │ ├── _shared/ shared Graph authentication, evidence and reporting utilities
│ │ └── m365-*/ focused governance, security, optimization and planning packages
│ └── admx-manager/ ADMX repository and rollback tooling
├── src/ existing application source
├── convex/ existing Convex backend source
└── public/ static application assets
A System 8 tool should provide, where applicable:
- unattended and interactive execution paths
- PowerShell 5.1 and 7 compatibility for Windows administration tooling
- idempotent operations
- structured logs
- explicit exit conditions
- preflight diagnostics
- dry-run support
- checksums or signatures for downloaded artifacts
- transaction boundaries
- rollback or compensating actions
- documentation that reflects the actual implementation
Do not report vulnerabilities through public issues. See SECURITY.md.
Small, independently verifiable changes are preferred. See CONTRIBUTING.md.
Carry the zero.
System 8 · Perth, Western Australia