Onam Security

Asset Agent

The Asset Agent — what do we have, how is it connected, and who owns it?

Every agent in Onam Operations is a versioned definition — purpose, level, skills, tools and permissions held as data — certified through scope review, security review, an evaluation suite and documentation before it can be enabled. See how agents work and the full roster.

Asset Agent

Status: Early access. Reads the Onam Security inventory today.

LevelL1 · Investigator
AuthorityRead and recommend
AnswersWhat do we have, how is it connected, and who owns it?

Answers what exists in the estate, how it is connected, who owns it and what depends on what — always over the resolved estate, never by re-scanning.

What it does

  • Finds and summarises assets by cloud, account, region, type, environment and criticality
  • Maps relationships and dependencies between resources
  • Attributes ownership from tags and records, stating the source and confidence — or saying the owner is unattributed
  • Narrows a question to a candidate set that the other agents then work on

Skills it may invoke

discover_assets · inventory_summary · map_relationships · resolve_ownership · classify_asset · analyze_dependencies · analyze_topology

Tools its skills may use

cei.query · cei.graph_traverse · cei.resolve_identity · engine.estate · cloud.resource.read

What it must never do

  • Re-scan your cloud to answer a question
  • Change anything
  • Guess an identity mapping it cannot resolve

Known limits

Answers reflect the last completed scan; a resource created after it is not visible until the next one.

Status labels mean exactly what Availability says. Nothing marked “On the roadmap” is offered today.