Onam Security

Architecture

The block architecture of Onam Operations: eight blocks on the request path, a control plane beside them, and three forks — read, execute, infer.

Block architecture: workspace, entry, orchestration, agents and capability blocks descend to Cloud Estate Intelligence, the execution sandbox and approved models, with governance, policy, approval and audit beside them.
Block architecture: workspace, entry, orchestration, agents and capability blocks descend to Cloud Estate Intelligence, the execution sandbox and approved models, with governance, policy, approval and audit beside them.

The request path

BlockContainsMust never
A · ExperienceWorkspace UI, embedded panels, API clientsHold a credential or call a product backend directly
B · EntryThe platform API gateway and the Operations APIAccept a tenant ID from a request body
C · OrchestrationOrchestrator, task service, workflow engineRead estate data, or decide whether a control applies
D · AgentsAgent runtime, registry, context engine, memoryCall a tool directly, or change its own scope
E · CapabilitySkill runtime, tool gateway, model gatewayLet unsanitised text back into the model’s context
F · IntelligenceCloud Estate IntelligenceWrite anything, or guess an identity mapping
G · ExecutionThe execution sandboxStart without an approval record
H · ModelsApproved model providersReceive data outside the permitted provider or region

The control plane

Governance (kill switch, registries), the policy engine (permissions, risk class), the approval service (the human gate) and audit and evidence (append-only, hash-chained) sit beside every block. They are in the call path, not advisory: each can refuse, and a refusal stops the request.

Two paths

Read path with three gates; write path with seven gates including a person approving the exact change.
Read path with three gates; write path with seven gates including a person approving the exact change.

Reading passes entitlement, agent scope and the tenant filter, and returns an answer with evidence. Writing passes entitlement, agent scope, the actor level, an execute permission, a policy risk class, a person approving the exact change and a drift check — then runs in the sandbox, is validated, and rolls back on failure.

Cloud Estate Intelligence

A read-only layer over what the products already found. It reads published contract views of each product’s data — never their own tables — resolves every resource to one canonical identity, stamps every row with when it was observed, and says which sources were unavailable. In early access it carries the Onam Security inventory, assets and findings; relationships, exposure, attack paths and compliance results are being connected; cost and recovery data are on the roadmap.

Five architectural commitments

  1. The agent layer never touches a product database directly.
  2. Nothing reaches a customer cloud except through the tool gateway and the sandbox.
  3. No component holds a model SDK; inference goes through the model gateway.
  4. Identity comes only from the platform gateway.
  5. Agent records live alongside the platform’s own, under the same tenancy rules.

The product page has the same design with diagrams: How Onam Operations is designed.