DSPM discovery
How DSPM finds data stores: the posture scan inventories each store and its settings through read-only cloud roles. Nothing extra is installed for it.
What is discovered
DSPM does not run a separate crawl. The same discovery pass that feeds CSPM records every resource in the connected accounts, and DSPM selects the ones that hold data: object storage, managed databases and warehouses, streams, and Kubernetes secrets, ConfigMaps, persistent volume claims and StatefulSets. The full per-cloud list is in Coverage by cloud.
Self-hosted databases — PostgreSQL, MySQL, MariaDB, SQL Server, MongoDB, Oracle, Cassandra, IBM Db2 and Snowflake — join the catalog when you onboard them as technology accounts with a database credential. Without that onboarding they are not visible to DSPM.
What is recorded per store
| Recorded | Used for |
|---|---|
| Name, description, tags | Classification |
| Encryption settings and key reference | Encryption checks; the Encryption engine's coverage and sensitive-data cross-check |
| Bucket policy, ACL grants, public-access block, provider public flags | Public exposure and cross-account grants |
| Access logging configuration | Activity-logging check and governance score |
| Versioning, lifecycle rules, backup retention, point-in-time restore, deletion protection | Lifecycle and backup checks |
| Region and account | Residency, and cross-region or cross-account lineage hops |
| Relationships to other resources | Lineage chains |
| Event notifications (S3) and stream consumers (Kinesis) | Per-store lineage records |
How often
Every scan. A store created since the last scan appears in the catalog on the next one, with its labels and checks; a store that has been deleted drops out. Findings are tied to the scan that produced them.
Access needed
Posture scanning connects through read-only cloud roles: list and describe calls on the storage and database services, plus reading bucket policies and ACLs. DSPM needs no permission to read objects, rows or secret values, because it never does. (Agentless workload scanning is a separate capability that runs inside your account; DSPM does not depend on it.)