Data Agent
The Data Agent — what data is where, how sensitive is it, and who can reach it?
Every agent in Onam Operations is a versioned definition — purpose, level, skills, tools and permissions held as data — certified through scope review, security review, an evaluation suite and documentation before it can be enabled. See how agents work and the full roster.
Data Agent
Status: In development. Waits on the exposure and relationship feeds into the estate layer.
| Level | L1 · Investigator |
| Authority | Read and recommend |
| Answers | What data is where, how sensitive is it, and who can reach it? |
Says what data exists where, how sensitive it is, who can reach it and where it flows — classifications, counts and locations, never the values.
What it does
- Finds sensitive data stores and their classification
- Analyses who and what can reach a data store
- Traces where regulated data flows
Skills it may invoke
discover_sensitive_data · classify_data · analyze_data_exposure · trace_data_flow · assess_data_risk
Tools its skills may use
cei.query · cei.graph_traverse · engine.datasec · engine.risk · cloud.identity.read
What it must never do
- Read the content of your data
- Report an unscanned store as clean
Known limits
Sees classifications and counts from the data security scans only, never content.
Status labels mean exactly what Availability says. Nothing marked “On the roadmap” is offered today.