slug: cisco-crosswork provider: Cisco Crosswork generated_by: planning/capability-mapping/scripts/classify_capabilities.py model: claude-opus-5 frame: - Telecommunications min_confidence: 0.7 capability_model: source: https://github.com/vincentmakes/turbo-ea-capabilities license: CC-BY-4.0 attribution: Turbo EA Capabilities by Vincent Verdet — Turbo EA, https://github.com/vincentmakes/turbo-ea-capabilities, CC BY 4.0 notice: NOTICE edge_count: 40 edges: - tag: Get Nodes/Devices spec_file: cisco-crosswork-get-nodes-devices-api-openapi.yml capability_id: BC-2600.40 capability_id_l1: BC-2600 capability_name: Network Inventory Management confidence: 0.9 evidence: '"Retrieves a list of nodes. This api returns complete inventory data for each node"' reason: Explicitly returns complete inventory data for network devices/nodes — the authoritative record of network resources, i.e. network inventory management. - tag: Alarms spec_file: cisco-crosswork-alarms-api-openapi.yml capability_id: BC-2600.10 capability_id_l1: BC-2600 capability_name: Network Fault Management confidence: 0.85 evidence: PUT /v1/ack "Acknowledge Alarms"; PUT /v1/clear "Clear alarms"; POST /v1/query "Get Alarms according to criteria"; POST /v1/syslog-dest "Add Syslog Destination"; schemas alarmsAlarm, alarmsSeverity reason: Alarm raise/query/acknowledge/clear with severity, notes and syslog/REST forwarding destinations on a service-provider network controller is network fault detection and handling, not business alerting. - tag: Flat L2VPN Provision spec_file: cisco-crosswork-flat-l2vpn-provision-api-openapi.yml capability_id: BC-2620.30 capability_id_l1: BC-2620 capability_name: Service Provisioning confidence: 0.85 evidence: POST/PUT/PATCH/DELETE /proxy/nso/restconf/data/cisco-flat-L2vpn-fp:flat-L2vpn={flat-L2vpn-name} reason: Create/modify/delete of flat L2VPN service instances via NSO orchestration is instantiation of a network service through configuration of network resources — telecom Service Provisioning. - tag: Flat L3VPN Provision spec_file: cisco-crosswork-flat-l3vpn-provision-api-openapi.yml capability_id: BC-2620.30 capability_id_l1: BC-2620 capability_name: Service Provisioning confidence: 0.85 evidence: POST/PUT/PATCH/DELETE /proxy/nso/restconf/data/cisco-flat-L3vpn-fp:flat-L3vpn={flat-L3vpn-name} — "Crosswork Network Controller L3VPN Service" reason: Create/modify/delete of an L3VPN service instance pushed via NSO RESTCONF is orchestration of network configuration to instantiate a customer-facing VPN service — telecom service provisioning. - tag: Get Nodes Summary spec_file: cisco-crosswork-get-nodes-summary-api-openapi.yml capability_id: BC-2600.40 capability_id_l1: BC-2600 capability_name: Network Inventory Management confidence: 0.85 evidence: POST /v1/nodes/querybrief — "Retrieves a list of nodes"; schemas robotapiRobotNodeType, robotapiRobotNodeOperationalState reason: Brief listing of network nodes with type, admin and operational state is querying the network inventory record of physical/logical resources. - tag: IETF-TE Provision spec_file: cisco-crosswork-ietf-te-provision-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.85 evidence: PUT/PATCH/DELETE /proxy/nso/restconf/data/ietf-te:te/tunnels/tunnel={tunnel-name}; "Crosswork Network Controller IETF-TE Tunnel APIs" reason: Provisioning of traffic-engineering tunnels in the transport network is configuration of network infrastructure. recovered_from: sweep-20260828T235257Z-edges.json - tag: Replaces Nodes/Devices spec_file: cisco-crosswork-replaces-nodes-devices-api-openapi.yml capability_id: BC-2600.40 capability_id_l1: BC-2600 capability_name: Network Inventory Management confidence: 0.85 evidence: PUT /v1/nodes — "Replaces the bulk of nodes in CrossWork"; schemas robotapiRobotNodeDataList, robotapiRobotNodeOperationalState reason: Bulk maintenance of the managed network node inventory in a service-provider network controller is squarely network inventory management. - tag: Update Nodes/Devices spec_file: cisco-crosswork-update-nodes-devices-api-openapi.yml capability_id: BC-2600.40 capability_id_l1: BC-2600 capability_name: Network Inventory Management confidence: 0.85 evidence: PATCH /v1/nodes — "Updates/Overwrites the bulk of nodes in CrossWork"; schemas robotapiRobotNodeDataList, robotapiRobotNodeAdminState reason: Updating the managed device records of a service-provider network controller is network inventory management. - tag: L2VPN Route Policy Provision spec_file: cisco-crosswork-l2vpn-route-policy-provision-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.82 evidence: POST/PUT/PATCH/DELETE /proxy/nso/restconf/data/cisco-flat-L2vpn-fp:l2vpn-route-policy={l2vpn-route-policy-name} reason: Routing policy objects attached to L2VPN services — device/network configuration, so IT infrastructure (network) management, not enterprise policy management. recovered_from: sweep-20260828T235257Z-edges.json - tag: L3VPN Route Policy Provision spec_file: cisco-crosswork-l3vpn-route-policy-provision-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.82 evidence: POST/PUT/PATCH/DELETE /proxy/nso/restconf/data/cisco-flat-L3vpn-fp:l3vpn-route-policy={l3vpn-route-policy-name}; schema l3vpn-route-policy reason: Lifecycle of L3VPN routing policies on the network — configuration of network infrastructure via the Crosswork Network Controller. recovered_from: sweep-20260828T235257Z-edges.json - tag: Add Nodes/Devices spec_file: cisco-crosswork-add-nodes-devices-api-openapi.yml capability_id: BC-2600.40 capability_id_l1: BC-2600 capability_name: Network Inventory Management confidence: 0.8 evidence: '"Crosswork Inventory RESTful APIs that can be used to onboard and manage Device Groups(Tags), Credentials, Providers and Devices"; POST /v1/nodes "Adds node information in the CrossWork"' reason: Operation registers network nodes/devices in the Crosswork inventory, with schemas for node admin/operational state, geo data and capabilities — an authoritative record of network resources, i.e. network inventory management for a service-provider network automation product. - tag: Delete Nodes/Devices spec_file: cisco-crosswork-delete-nodes-devices-api-openapi.yml capability_id: BC-2600.40 capability_id_l1: BC-2600 capability_name: Network Inventory Management confidence: 0.8 evidence: DELETE /v1/nodes Delete the bulk of nodes from CrossWorks; "onboard and manage Device Groups(Tags), Credentials, Providers and Devices"; robotapiRobotNodeGeoData, robotapiRobotNodeOperationalState reason: Crosswork Inventory device records with operational/admin state, geo data and capabilities constitute the authoritative record of network resources; deleting nodes is inventory lifecycle maintenance — Network Inventory Management. - tag: Get Nodes Count spec_file: cisco-crosswork-get-nodes-count-api-openapi.yml capability_id: BC-2600.40 capability_id_l1: BC-2600 capability_name: Network Inventory Management confidence: 0.8 evidence: GET /v1/nodes/count — "Retrieves a count of all nodes in the database"; "manage Device Groups(Tags), Credentials, Providers and Devices" reason: Counting network nodes held in the Crosswork inventory database is a read over the authoritative record of network resources — network inventory management. - tag: IETF L2VPN NM Retrieval spec_file: cisco-crosswork-ietf-l2vpn-nm-retrieval-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.8 evidence: GET /nbi/cat-inventory/v1/restconf/data/ietf-l2vpn-ntw:l2vpn-ntw/vpn-services/vpn-service={vpn-service-vpn-id}; "network configuration model for Layer 2 VPN services" reason: Read of provisioned L2VPN network service configuration/state from the network controller inventory — network infrastructure management. recovered_from: sweep-20260828T235257Z-edges.json - tag: IETF-TE Retrieval spec_file: cisco-crosswork-ietf-te-retrieval-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.8 evidence: GET /nbi/cat-inventory/v1/restconf/data/ietf-te:te/tunnels/tunnel={tunnel-name}; "IETF-TE Tunnel APIs" reason: Retrieval of TE tunnel and tunnel-plan state from the network controller — network infrastructure inventory/configuration. recovered_from: sweep-20260828T235257Z-edges.json - tag: Map or Unmap Devices to a Data Gateway spec_file: cisco-crosswork-map-or-unmap-devices-to-a-data-gateway-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.8 evidence: PUT /v1/dg/devicemapping — "Maps or Unmaps a Data Gateway to devices. It will return a Job response of success or failure." reason: Associates managed network devices with a Crosswork Data Gateway collector, an infrastructure topology/management operation on network elements. recovered_from: sweep-20260828T235257Z-edges.json - tag: authconfig spec_file: cisco-crosswork-authconfig-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.8 evidence: APIs to support integration of the Crosswork platform and remote authentication servers. Currently only the TACACS server type is supported.; GET /v1/remote/ldap LdapGetAll Get list of remote LDAP servers reason: Configures integration with remote TACACS/LDAP authentication servers — federation of authentication directories for platform access, i.e. Identity & Access Management. Not subscriber AAA (these are operator/admin logins to the Crosswork platform), so the cross-industry IAM capability is the honest mapping. - tag: data spec_file: cisco-crosswork-data-api-openapi.yml capability_id: BC-2600.40 capability_id_l1: BC-2600 capability_name: Network Inventory Management confidence: 0.8 evidence: GET /data/ietf-network-state:networks/network ... Describes a network. A network typically contains an inventory of nodes, topological information (augmented through the network-topology data model) reason: Exposes IETF network-state / L3 unicast topology models — nodes, links, termination points, ISIS/OSPF/SR attributes — i.e. the authoritative record of logical network resources and their relationships. Reads as network inventory/topology rather than performance or fault. - tag: L2VPN Route Policy Retrieval spec_file: cisco-crosswork-l2vpn-route-policy-retrieval-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.78 evidence: GET /nbi/cat-inventory/v1/restconf/data/cisco-flat-L2vpn-fp:l2vpn-route-policy={l2vpn-route-policy-name} reason: Read of L2VPN route-policy network configuration; a routing construct, mapped to network infrastructure management. recovered_from: sweep-20260828T235257Z-edges.json - tag: L3VPN Route Policy Retrieval spec_file: cisco-crosswork-l3vpn-route-policy-retrieval-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.78 evidence: GET /nbi/cat-inventory/v1/restconf/data/cisco-flat-L3vpn-fp:l3vpn-route-policy={l3vpn-route-policy-name} reason: Read-only retrieval of L3VPN route-policy network configuration — network infrastructure management. recovered_from: sweep-20260828T235257Z-edges.json - tag: Remove Tags from Nodes/Devices spec_file: cisco-crosswork-remove-tags-from-nodes-devices-api-openapi.yml capability_id: BC-2600.40 capability_id_l1: BC-2600 capability_name: Network Inventory Management confidence: 0.78 evidence: PUT /v1/nodes/unassigntag — "Removes one or more tags associations from the list of nodes"; spec is used to "onboard and manage Device Groups(Tags), Credentials, Providers and Devices" reason: Tags here are device groupings within the Crosswork network device inventory; the operation maintains the authoritative record of network nodes and their grouping, i.e. network inventory management. - tag: ClusterManager spec_file: cisco-crosswork-clustermanager-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.75 evidence: GetAppHealthSummary; GetNodeDetails Get the Crosswork Cluster Details; Initiate collection of data for troubleshooting Crosswork Platform applications reason: Cluster node, microservice and app health management for the platform — IT infrastructure/operations management. recovered_from: sweep-20260828T235257Z-edges.json - tag: Flat L2VPN Retrieval spec_file: cisco-crosswork-flat-l2vpn-retrieval-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.75 evidence: GET "/nbi/cat-inventory/v1/restconf/data/cisco-flat-L2vpn-fp:flat-L2vpn={flat-L2vpn-name}" reason: Read-side of L2VPN network service configuration/inventory; network infrastructure management. recovered_from: sweep-20260828T235257Z-edges.json - tag: Flat L3VPN Retrieval spec_file: cisco-crosswork-flat-l3vpn-retrieval-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.75 evidence: GET "/nbi/cat-inventory/v1/restconf/data/cisco-flat-L3vpn-fp:flat-L3vpn-plan={flat-L3vpn-plan-name}" reason: Retrieval of L3VPN network service state/plan; network infrastructure management. recovered_from: sweep-20260828T235257Z-edges.json - tag: cwztpdevice spec_file: cisco-crosswork-cwztpdevice-api-openapi.yml capability_id: BC-2600 capability_id_l1: BC-2600 capability_name: Telecom Network Operations Management confidence: 0.75 evidence: POST /v1/devices SetDevices ... Add the bulk of Ztp devices; POST /v1/onboarding OnboardDevice Onboarding API For onboarding of individual Device from ZTP to DLM on ztp process provisioned reason: Zero Touch Provisioning device records with lifecycle states (unprovisioned / inprogress / provisioned / provisioningError) and onboarding of network devices into device lifecycle management. This is operation of the operator's own network elements — telecom network operations — spanning both element configuration and inventory, so no single L2 is named clearly enough. - tag: password spec_file: cisco-crosswork-password-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.75 evidence: '''Crosswork Password Management APIs are used to manage passwords for user accounts created on the local authentication store'' — PUT /v1 ChangePassword' reason: Credential lifecycle for user accounts in the local authentication store is identity and access management. It is a narrow single-operation surface, so confidence is moderate. - tag: IETF L2VPN NM Provision spec_file: cisco-crosswork-ietf-l2vpn-nm-provision-api-openapi.yml capability_id: BC-2620.30 capability_id_l1: BC-2620 capability_name: Service Provisioning confidence: 0.72 evidence: POST/PUT/PATCH/DELETE /proxy/nso/restconf/data/ietf-l2vpn-ntw:l2vpn-ntw/vpn-services/vpn-service={vpn-service-vpn-id}; "generic network configuration model for Layer 2 VPN services" reason: Create/modify/delete of L2VPN customer-facing VPN service instances pushed to the network via NSO — orchestration of configuration changes to instantiate a telecom service (service provisioning). Alternative reading is pure network configuration management, hence not higher confidence. - tag: ' Add Data Gateway Enrollments' spec_file: cisco-crosswork-add-data-gateway-enrollments-api-openapi.yml capability_id: BC-2600.40 capability_id_l1: BC-2600 capability_name: Network Inventory Management confidence: 0.7 evidence: Adds Dg Enrollments information in the CrossWork ... robotapiRobotDataGatewayConfig, RobotDataGatewayOperationalOperationalState reason: Crosswork Inventory API onboarding Data Gateway nodes with config and operational state into the inventory record of network resources; fits network inventory management, though it also carries a provisioning/config flavour. - tag: Add Tags spec_file: cisco-crosswork-add-tags-api-openapi.yml capability_id: BC-2600.40 capability_id_l1: BC-2600 capability_name: Network Inventory Management confidence: 0.7 evidence: POST /v1/tags "Create the tags in CrossWork to be associated with the nodes."; schema robotapiRobotNodeTag reason: Tags are device-group labels attached to network nodes in the Crosswork inventory, so this is classification/grouping within the network inventory record. - tag: BackupServices spec_file: cisco-crosswork-backupservices-api-openapi.yml capability_id: BC-600.40 capability_id_l1: BC-600 capability_name: IT Operations Management confidence: 0.7 evidence: RequestVMBackup; RequestVMDisasterRestore; RequestVMRestore reason: VM backup/restore and disaster restore jobs for the platform — IT operations; could also be read as disaster recovery, but this is platform-level backup tooling. recovered_from: sweep-20260828T235257Z-edges.json - tag: CollectionService spec_file: cisco-crosswork-collectionservice-api-openapi.yml capability_id: BC-600.40 capability_id_l1: BC-600 capability_name: IT Operations Management confidence: 0.7 evidence: '"control collection jobs across different collection types on a device or a device group within Crosswork" ... "CreateCollectionJob"' reason: Network telemetry collection jobs (MDT, SNMP, CLI) against devices — IT operations monitoring/automation of network infrastructure. Could arguably be observability, but this is enterprise network device operations rather than SaaS product observability, so Cross-Industry IT Operations Management is the honest fit. recovered_from: sweep-20260828T235257Z-edges.json - tag: Crosswork Health API spec_file: cisco-crosswork-crosswork-health-api-api-openapi.yml capability_id: BC-600.40 capability_id_l1: BC-600 capability_name: IT Operations Management confidence: 0.7 evidence: '"APIs to get the Health of Crosswork Applications and their dependent services"; GET /v1/platform/health "Get a health summary for all applications running on the Crosswork platform"' reason: Health/status monitoring of the platform's own applications and services is IT operations monitoring of the software platform, not telecom service assurance. - tag: Delete via CSV file spec_file: cisco-crosswork-delete-via-csv-file-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: '"Delete operation via CSV file upload... Can be applied to Credentials, Tags, Providers and Devices" in "Crosswork Inventory RESTful APIs that can be used to onboard and manage Device Groups(Tags), Credentials, Providers and Devices"' reason: Bulk deletion of network device inventory records — IT infrastructure (network device) management. Sub-capability choice is somewhat uncertain between IT Operations and IT Infrastructure Management. recovered_from: sweep-20260828T235257Z-edges.json - tag: Get Data Gateway Enrollments spec_file: cisco-crosswork-get-data-gateway-enrollments-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: '"Retrieves a list of DG enrollments. This api returns RobotDataGateway" with schemas "RobotDataGatewayConfigInterface", "RobotDataGatewayOperationalOperationalState"' reason: Enrollment and state of Crosswork Data Gateway appliances — management of network infrastructure components. recovered_from: sweep-20260828T235257Z-edges.json - tag: Get Providers spec_file: cisco-crosswork-get-providers-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: POST /v1/providers/query "Retrieves a list of providers."; schemas robotapiRobotProviderData, robotapiRobotTransportType, robotapiRobotEntityConnectivityState reason: '''Providers'' here are network element/controller providers registered in Crosswork inventory (transport, connectivity state), i.e. network infrastructure management — not suppliers or service vendors in a procurement sense.' recovered_from: sweep-20260828T235257Z-edges.json - tag: Update via CSV file spec_file: cisco-crosswork-update-via-csv-file-api-openapi.yml capability_id: BC-2600.40 capability_id_l1: BC-2600 capability_name: Network Inventory Management confidence: 0.7 evidence: PUT /v1/csvupload — "the uplaoded list of inventory will be updated in Crossworks. Can be applied to Devices"; schema robotapiRobotInventoryType reason: Bulk import mechanism whose payload is the device inventory itself; despite being a file-upload endpoint, the stated effect is updating network device inventory records. - tag: cwztpprofile spec_file: cisco-crosswork-cwztpprofile-api-openapi.yml capability_id: BC-2600.20 capability_id_l1: BC-2600 capability_name: Network Configuration Management confidence: 0.7 evidence: PUT /v1/profiles UpdateProfile Update the individual profile. profile cannot be updated, if it is associated to ztp device with the status other than "unprovisioned" reason: CRUD over ZTP configuration profiles that are bound to network devices and drive their day-zero provisioning — definition and controlled application of network element configuration standards. Slight residual doubt on whether this counts as configuration vs change management. - tag: get spec_file: cisco-crosswork-get-api-openapi.yml capability_id: BC-2600.40 capability_id_l1: BC-2600 capability_name: Network Inventory Management confidence: 0.7 evidence: GET /data/ietf-network-state:networks/network — 'A network typically contains an inventory of nodes, topological information (augmented through the network-topology data model)' reason: Although the tag is just the HTTP verb, every operation reads IETF network-state / L3-unicast-topology data — nodes, links, termination points, ISIS/OSPF/SR topology. That is an authoritative record of logical network resources and their relationships, i.e. network inventory/topology. Confidence held at 0.7 because the read-only topology-state surface could equally be read as performance/optimisation input. - tag: operations spec_file: cisco-crosswork-operations-api-openapi.yml capability_id: BC-2600.80 capability_id_l1: BC-2600 capability_name: Network Optimisation Management confidence: 0.7 evidence: POST /operations/cisco-crosswork-optimization-engine-sr-policy-operations:sr-policy-create, ...:sr-policy-modify, ...:sr-policy-delete, ...:sr-policy-dryrun; POST ...optimization-engine-operations:sr-policy-routes reason: Despite the generic tag, the operations create, modify, delete and dry-run Segment Routing policies via the Crosswork Optimization Engine and query SR policies on nodes/interfaces — i.e. tuning of traffic paths across the network. Best fits Network Optimisation Management; some chance a reviewer would file it under Network Configuration Management, hence 0.7. - tag: rbac spec_file: cisco-crosswork-rbac-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.7 evidence: Crosswork Role-based Access Control APIs; 'CreateRole', 'Create a user on the local authentication store.', 'Get the list of secured APIs.' reason: Operations manage roles, users and API authorisation in a local authentication store — role and user access administration, i.e. identity & access management. Confidence tempered because this is product-internal access control plumbing rather than an enterprise IAM service.