Data model
Entities, typed attributes, keys and cardinalities — in your organisation's notation.
Enterprise architecture studio · repository, twenty-six notations, data included
Cartano puts every model up against 89 rules, recomputed on every read. That is what keeps a map true. It is also what gives our agents something nobody else can give them: a judge. They draft, the machine rules, they correct — and they show you the round count.
90 days, no credit card. Access is by invitation during the alpha.
Three trades, three problems, three paths. Take yours.
You sell days, and you spend half of them tidying up diagrams that will be out of date before the read-out.
Cartano hands over the file and the judgement calls: the position taken, the assumptions owned, and the questions still open. One partitioned workspace per client. The client leaves with their files — and you are the one selling them that.
The workshop on a real engagement →Your map exists. It lives in a drawing tool, a spreadsheet and three exports — and nobody knows which one is authoritative.
One repository that is authoritative, twenty-six views derived from it, and rules that refuse to publish a wrong model. Audit log, step-by-step undo, hosting wherever your security officer wants it. Without the budget or the sales cycle of an architecture suite.
Scope a first map →One tool for the ERD, a repo for the contracts, a wiki for the rest — and nothing connects a table to the process that fills it.
From the use case to the table, then to the data contract, with no re-keying. Five ERD notations, generated DDL, an open-format contract, import of your existing models.
Import one of your models during the demo →Ask an assistant for a class model and it produces plausible text. It guesses the notation, it knows nothing of your real applications, and above all: nothing tells it whether it got anything right. A Cartano agent is handed the notation, looks up your assets, writes a draft — then gets failed by 89 rules, and starts again.
A real screenshot of the product. The agent modelled motor underwriting in three passes, then wrote down in plain words the error it could not resolve — the draft stays yours, and so does accepting it. The interface shown is in French: our demonstration dataset has not been rebuilt in English yet.
You describe the need. The agent works alone, loops over the checks, and hands back a draft — never a published document.
The note that comes with the draft states the position taken, the assumptions owned and the closed questions that remain. That is the agenda for the next meeting.
Accepting belongs to a human, and it is recorded. An agent cannot get around that — it is a guarantee held in the database, not an application rule.
A conversation has no judge: it hands you a model and asks you to believe it. Here, the machine can tell whether the model is wrong — and that is exactly why it can correct it.
Architecture suites stop at the application portfolio. Data tools start from the tables and never come back up. Cartano holds the whole chain, in a single repository.
A business capability nobody owns is visible. An entity that appears in no process is visible too. Renaming an application renames it everywhere — because there is only one object, and twenty-six ways of looking at it.
And at the end of the chain, the data contract is not a courtesy export: it is an open, machine-readable format, and it is the bridge to the data product factory.
A map lives in a drawing tool, a spreadsheet and three slide exports. It looks good on review day, it is wrong three months later, and nobody knows which of the four versions is authoritative. Cartano takes the problem from the other end.
We inventory applications, components, servers, databases, flows and data products, with typed relations. Views are derived from the repository — never the other way round. No piece of data exists only in a drawing.
89 distinct issue codes, recomputed on every read, never stored — so never stale. A non-conforming model does not get published. It is an executable specification of what a correct model is.
Git mirror (model.json, layout.json), export of the whole
workspace, round trip verified on 63 assets and 89 relations. You leave when you want,
with everything.
Everything below is a screenshot, not an illustration. The figures you can see come out of the models — nobody typed them in for the photo. The interface shown is in French; the product itself is bilingual.
The notations your organisation already uses — without learning one more, and without switching tools between the business, the applications and the data.
Entities, typed attributes, keys and cardinalities — in your organisation's notation.
Lanes, tasks, gateways and flows — with the actors from the repository.
The three layers and their dependencies. You can see what falls over if a server does.
Asset categories, typed relations and declared properties are set in the interface, with no development. The taxonomy is yours, not the one the vendor decided was universal.
Undo and redo on the open document, derived from an append-only log. An undo writes a compensating action — it erases nothing. The audit log says who changed what, and when.
This is the family that turns the others from drawing into an operating discipline. Each one computes a verdict from what you entered — and refuses publication until the organisation has answered it.
Residual risk follows from control effectiveness and their actual state: a control that is merely planned counts for one fifth. A contract's notice deadline is the term minus the notice period. Typed in, these values would be wrong by the next quarter — and nobody would see it.
You never come back faster than your slowest dependency. You are never covered longer than your shortest contract. You condemn the platform carrying what you fund. Each record on its own is impeccable; it is the chain that lies, and it is walked on every read.
Risk register · Decision log · Compliance · Data classification · Technology radar · Business continuity · API catalogue · TIME portfolio · Vendor contracts.
Nobody migrates twelve years of drawings by hand. Drop a draw.io file: each page becomes a document, with its positions, sizes, colours and arrows — as they are.
The order matters. We measure a real corpus before writing a rule: across sixteen client drawings, 72 % of shapes are a bare rectangle and there is not a single diamond. Shape classifies nothing. Pretending otherwise would manufacture a meaning the drawing does not carry — and the lie would be undetectable, since it would look like entered data.
Zones are derived from the geometry, because nobody declares them in draw.io. Whatever could not be read lands as “to qualify” and stays there until someone settles it. The import report names every gap: arrows missing an end, clamped sizes, flattened labels.
This is the angle architecture suites do not cover and data tools do not reach. Model your entities and attributes, generate the ERD, produce the DDL — and publish a data contract in an open format.
dataContractSpecification: 1.1.0 id: billing.invoice info: title: Invoice owner: finance-department models: invoice: type: table fields: id: { type: string, required: true } customer_id: { type: string, required: true } amount: { type: decimal, precision: 12 } issued_on: { type: date }
What might read as caution is our strongest argument in the enterprise. A Cartano agent goes through the same routes as the interface — so it inherits the same guardrails, without anyone having had to reinvent them for it.
An agent's action is undone with one ⌘Z, cascades included. And an undo erases nothing: it writes a compensating action.
Every write is logged with its author, its action, and its before/after. The log is append-only — nobody rewrites it, us included.
An agent can neither create an asset type nor publish a document. That is not an instruction in a prompt: it is refused in the database.
Tokens, duration and cost per run. You will know what this AI costs you, to the euro — before deciding to use it.
"We don't let an AI write into our repository" becomes "we let it propose, we see everything, we undo everything".
We would rather tell you here than at the third meeting. You can judge whether it concerns you.
No connector to a CMDB or to a cloud provider: the repository is filled by import or by hand. An inventory that updates itself is what architecture suites are for, and they charge accordingly. Ours is to make a model right and defensible. If your first need is to synchronise, tell us: we will tell you so too.
No library of industry capabilities shipped with the tool. Ten shallow reference models are spotted in thirty seconds by someone who knows the trade, and they discredit everything else. You start from your taxonomy, which the meta-model lets you extend without development.
No simultaneous editing, no collection campaign across two hundred owners. An architecture model is decided by three people, not fifteen — and what matters next is that the repository tells the truth and that the log says who changed it. Both of those are here.
Cartano runs as shared SaaS, as a dedicated instance, or against your own database — yours, at your hosting provider, under your control. We document the latency, the outbound traffic, the costs, and what has to be opened on the network side. No hand-waving.
The simplest and the cheapest. Hosted in France, isolation between workspaces guaranteed by the database itself.
Your server, your backups, your maintenance window. A fixed, documented outbound address for your firewall rules.
Postgres at your premises or at your provider. We tell you frankly what it costs in latency — and when it is a bad idea.
The product is in alpha. We write it here rather than letting you find out in a meeting: you will know exactly what you are taking on, and the one thing we do not promise yet.
Everything described on this page works. We use it to map our own system.
The engineering is already there — it is the commitment that arrives. The difference between "we back up" and "we commit to it in writing".
An entry tier at €1 a month — enough to filter out sign-ups with no intent, not enough to be a barrier — and per-author plans for teams.
In the meantime, alpha access is free and guided. In exchange, we ask you to tell us what gets in your way.
We show you the repository, a model that refuses to publish because it is wrong, and the complete export. No slide deck.