preflight_change
Diff proposed vs current config to risk-tag changes, flag compliance regressions, compute blast radius for shared subnets/VLANs. Returns BLOCK, REVIEW REQUIRED, PROCEED WITH CARE, or NO CHANGE.
Instructions
Before you push a change: diff the proposed config against the current one, risk-tag every change, list compliance checks that would regress, and — if you pass the configs of the other devices you manage — compute the blast radius (who shares the affected subnets and VLANs). Returns a gate verdict: BLOCK, REVIEW REQUIRED, PROCEED WITH CARE, or NO CHANGE. Read-only; nothing is applied.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| fleet | No | ||
| device | No | ||
| vendor | No | ||
| current | Yes | ||
| proposed | Yes |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| result | Yes |