Roll out upgrades to every service that uses a plan.
Wayfinder finds new module versions, tests them against real usage and opens a pull request with the test results. Drift shows up with an owner and a diff.
Free forever plan, no commitment, in your own cloud account.
Built from the real interface. Open the demo tenant in the live demo. No sign-in.
- Today
- 74 daysAverage time to fix a high or critical vulnerability in an application.Edgescan, Vulnerability Statistics Report, 2025
Application/API Vulnerabilities High/Critical Severity: Average MTTR 74.3 DAYS; Device/Network 54.8 DAYS
Edgescan customer scan data across 14 industries, 2024 - With Wayfinder
Wayfinder timings are from our reference deployment and demo flows, not from customer studies.
- Under 1 hourA new version tested against every service on the plan, with a pull request opened in each repo. Timed on our reference deployment.
- PRBump aws-rds plan 1.4.0 to 1.5.0 across 12 servicesValidated against real usage in a replica of each. Evidence attached.12 of 12 passedPostgres 16owner: platform
- PRGolden path node-service 3.2 to 3.3, 9 reposCI template and scanner config updated in every repo pinned to it.9 PRs raisedTrivy 0.58
- DRDrift: uploads bucket versioning turned off in prodChanged outside Wayfinder on 21 Sep. Diff and owner attached, fix ready to apply.owner: checkout1 line diff
Before and after
Before
- Upgrade spreadsheets and quarterly big bangs
- Changes tested against a toy example
- Drift discovered during an incident
- Approvals in chat, evidence in someone's head
- Every team upgrading on its own schedule
With Wayfinder
- New versions surveyed across every stack
- Validated in a replica against real usage
- Drift surfaced with an owner and a one-line diff
- Plan, approve, apply with the evidence attached
- One bump, pull requests raised everywhere
How it works
Survey
Wayfinder knows every plan, template and module version in use, and what is newer.
Validate
The candidate runs in a replica of each consumer. Failures are reported, passes are evidence.
Roll out
Pull requests with the evidence attached, gated by approval where you want it.
In the product
Bump the aws-rds plan from 1.4.0 to 1.5.0 across 12 services. Tested against a replica of each, 12 of 12 passed. Needs 2 of 2 approvals from platform-team.
- workflow/module-upgradesvalidated 1.5.0 on a replica of all 12, as sa:module-upgrades12 of 12 passed
- workflow/module-upgradesopen_pull_request across 12 repos, gated on approvalheld
- jon@acmeapproved plan, 03:41recorded
What this shows
- Plan: what changes, for which stacks, with the validation result.
- Approve: the named people, in the tool, with the evidence in front of them.
- Apply: the change runs, and the audit shows every step that touched it.
Components
Which stacks run which version of which plan, template or module.
Candidate versions tested against real usage in a replica.
A resource changed outside Wayfinder, with the diff and the owner.
A workflow step that holds until the named people approve.
Test results and diffs attached to the pull request.
Old versions removed the same way.
Security and governance
Nothing changes your infrastructure without a plan, an approval and an apply, each logged.
The people who can approve are named per workspace and environment.
Validation runs under the same scoped identity as the change itself.
Drift is evidence of a change outside the record, and it is attributed.
Run one upgrade across your services.
Start free, pick a module, and let Wayfinder raise the pull requests.