What it models
The schema is organized into three layers: business, service, and infrastructure.Business layer
This layer maps the outcomes an application outage affects, so that business impacts are clear.Service layer
The service layer describes what people name when they ask for help, and the applications behind it.Infrastructure layer
The infrastructure layer maps the resources that deliver the services, typically ingested from cloud, MDM, and discovery sources.The dependency map
In addition to the reference fields on each table, the CMDB template documents the following relationship types, which are useful for impact analysis:- Delivered By: an IT Service to the Application Services that deliver it.
- Service Dependency: one Application Service to another it calls at runtime.
- Runs On / Hosted On: an Application Service to the Server or Cloud Resource it runs on.
- Uses Database: an Application Service to the Database Instances it reads and writes.
- Secures: a Certificate to the services it secures.
- Supports Capability: a Business Application to the Business Capabilities it supports.
Use cases
- Impact analysis before a change. Before you take a server, database, or certificate down, trace what depends on it, so you know who’s affected and can plan.
- Faster incident triage. When someone reports a problem like “Salesforce is down,” the help desk agent resolves the named service to the applications and infrastructure behind it, and surfaces the likely culprit from the dependency chain.
- Service ownership. Understand which applications support each Business Capability and which infrastructure delivers each service.
Usage tips
- Populate it by connecting your cloud, MDM, and discovery sources with ingestion configs, or load records by CSV import. Key fields (e.g. FQDN, resource ID, instance ID) are the de-duplication keys that sync matches on.
- Extend it with your own fields, tables, and relationships, and add validation rules to keep records complete.
- Govern it with table, field, and record-level access, and mark sensitive fields so each reveal is logged in your organization’s audit logs (accessible by your admins).

