Onam Security

Data lineage

How Onam links replication, backup, ETL, streaming and export hops into data lineage chains, and flags copies that cross regions or accounts.

An illustrative lineage chain with a cross-region replication hop and a cross-account export hop
An illustrative lineage chain with a cross-region replication hop and a cross-account export hop

How a chain is built

  1. Edges come from the inventory. Discovery records relationships between resources. Those that move data — replicates to, backs up to, stores data in, publishes to, subscribes to, reads from, writes to, exports to, imports from — become lineage edges.
  2. Each hop is typed and flagged. The relationship maps to a transfer type: replication, backup, ETL, streaming, read, write, export or import. Source and destination regions and accounts are read from their identifiers; a hop between two regions is flagged cross-region, a hop between two accounts is flagged cross-account.
  3. Edges are walked into chains. Chains start at stores nothing feeds — the true origins — and follow each path up to eight hops, which stops a cycle from running forever. If no multi-hop chain exists, each edge is shown on its own.

Chains appear in the console under Data Security → Lineage (/ui/datasec/lineage).

Per-store lineage records

Alongside chains, each store records its own outbound flows where the configuration shows them: S3 event notifications to Lambda, SQS or SNS, and the registered consumers of a Kinesis stream. These are informational — they describe where data goes, not a misconfiguration.

Why the flags matter

A copy is protected by the controls where it lands, not where it started. A replication hop into another region can move regulated data out of its permitted geography even when the source bucket passes every residency check; an export hop into another account hands the copy to that account's controls. The flags mark exactly those moments.

What lineage cannot see

  • Movement with no configuration trace. A script, notebook or scheduled job that copies files using its own credentials leaves no relationship in the cloud's resource configuration.
  • Transformations inside a job. Lineage records that an ETL job writes to a store, not which fields it carried.
  • Volumes. Records per day are shown only where a source provides them; most do not.
Encryption in transit and a per-chain risk grade appear in the lineage view where the underlying relationship records them. Most relationships do not carry those fields yet, so treat the cross-region and cross-account flags as the dependable signal today.