Be the fleet baseline owner. Build a compliant firmware/BIOS/BMC matrix across vendors. Deliver: source of truth, hash/signature checks, ringed rollout (lab→canary→zone), auto-rollback, maintenance windows, and evidence pack for audit. KPIs: drift %, success rate, MTTR after rollback. Output: runbooks, SBOM pointers, change log template.