Onam Security

DSPM discovery

How DSPM finds data stores: the posture scan inventories each store and its settings through read-only cloud roles. Nothing extra is installed for it.

What is discovered

DSPM does not run a separate crawl. The same discovery pass that feeds CSPM records every resource in the connected accounts, and DSPM selects the ones that hold data: object storage, managed databases and warehouses, streams, and Kubernetes secrets, ConfigMaps, persistent volume claims and StatefulSets. The full per-cloud list is in Coverage by cloud.

Self-hosted databases — PostgreSQL, MySQL, MariaDB, SQL Server, MongoDB, Oracle, Cassandra, IBM Db2 and Snowflake — join the catalog when you onboard them as technology accounts with a database credential. Without that onboarding they are not visible to DSPM.

What is recorded per store

RecordedUsed for
Name, description, tagsClassification
Encryption settings and key referenceEncryption checks; the Encryption engine's coverage and sensitive-data cross-check
Bucket policy, ACL grants, public-access block, provider public flagsPublic exposure and cross-account grants
Access logging configurationActivity-logging check and governance score
Versioning, lifecycle rules, backup retention, point-in-time restore, deletion protectionLifecycle and backup checks
Region and accountResidency, and cross-region or cross-account lineage hops
Relationships to other resourcesLineage chains
Event notifications (S3) and stream consumers (Kinesis)Per-store lineage records

How often

Every scan. A store created since the last scan appears in the catalog on the next one, with its labels and checks; a store that has been deleted drops out. Findings are tied to the scan that produced them.

Access needed

Posture scanning connects through read-only cloud roles: list and describe calls on the storage and database services, plus reading bucket policies and ACLs. DSPM needs no permission to read objects, rows or secret values, because it never does. (Agentless workload scanning is a separate capability that runs inside your account; DSPM does not depend on it.)