Availability and status
What in Onam Operations you can use today, what is in early access or development, and what is on the roadmap — stated plainly, capability by capability.
What the labels mean
| Label | Meaning |
|---|---|
| Available | In Onam Security today, for every customer. |
| Early access | Running on the Onam platform and enabled per organisation by invitation. Agents answer and propose; nothing changes your cloud. |
| In development | Built or specified; its data feed or enablement is not in place yet. |
| On the roadmap | Designed, not offered. No date is promised. |
Capabilities
| Capability | Status | Detail |
|---|---|---|
| AI Assistant in Onam Security | Available | Ask questions about your posture in plain language; specialists query your findings and cite them. Read-only. |
| Agent workspace | Early access | Chat with the agents, each reply attributed to the agent that produced it, with a context panel for evidence, tasks and actions. |
| Orchestrator and visible plans | Early access | A multi-step question becomes a plan you can see — which agent, which skill, in which order — before and while it runs. |
| Asset Agent and Security Agent | Early access | Over the Onam Security inventory and findings, on AWS first. |
| Evidence on every claim | Early access | Each number cites the skill, tool, query, rows and scan time that produced it. |
| Approval centre | Early access | One queue for every proposed change, diff first, with rollback and blast radius shown before the decision. |
| Activity and audit trail | Early access | Every turn, tool call, decision and approval recorded append-only, with a hash-chain check that nothing was edited. |
| Reports | Early access | A conversation or task exported with its evidence preserved. |
| Kill switch and autonomy ceiling | Early access | Stop all agent activity for your organisation; cap how far agents may go — read, analyse, recommend, simulate, propose. |
| Compliance Agent and Data Agent | In development | Built; waiting on the compliance-results, exposure and relationship feeds into the estate layer. |
| Change proposals with rollback | In development | Automation Planner proposals with exact change, rollback and dry run; blast-radius inputs are being connected. |
| Pre-built workflows | In development | Multi-step procedures such as audit preparation and exposure remediation, with approval steps built in. |
| Executing approved changes | On the roadmap | The actor applies an approved change in an isolated sandbox, validates it and rolls back on failure. Built and tested; enabled for no customer. |
| FinOps, DR and Architecture agents | On the roadmap | Cost, recovery and design reasoning across the estate. |
| Cost and recovery data (Onam FinOps, Onam DRM) | On the roadmap | Joining exposure with cost and recoverability in one answer. |
| Azure, Google Cloud and Kubernetes actions | On the roadmap | AWS first; the design keeps provider specifics inside tools so agents do not change. |
| Event triggers and a workflow builder | On the roadmap | Start investigations from events; compose workflows that cannot publish an execute step without an approval step. |
| Customer-authored agents | On the roadmap | Needs a sandbox and certification model that does not exist yet. |
Agents
| Agent | Level | Status | Note |
|---|---|---|---|
| Asset Agent | L1 | Early access | Reads the Onam Security inventory today. |
| Security Agent | L1 | Early access | Reads findings today; exposure and attack-path context are being connected. |
| Compliance Agent | L1 | In development | Waits on the compliance-results feed into the estate layer. |
| Data Agent | L1 | In development | Waits on the exposure and relationship feeds into the estate layer. |
| Automation Agent — planner | L2 | In development | Proposal flow is built; blast-radius inputs are being connected. |
| Automation Agent — actor | L3 | On the roadmap | Built and tested in the platform; not enabled for any customer. |
| FinOps Agent | L1 | On the roadmap | Needs cost data in the estate layer. |
| DR Agent | L1 | On the roadmap | Needs recovery data in the estate layer. |
| Architecture Agent | L2 | On the roadmap | Needs the full topology graph as an input. |
Use cases
| Use case | Agents | Status |
|---|---|---|
| Find internet-exposed critical assets | Asset → Security | Early access |
| Triage a new critical finding | Security → Asset | Early access |
| Identify excessive IAM permissions | Security | Early access |
| Review a newly connected cloud account | Asset → Security | Early access |
| Prepare compliance evidence for an audit | Compliance → Data → Security | In development |
| Find sensitive data exposed publicly | Data → Security | In development |
| Create a remediation plan | Security → Automation planner | In development |
| Execute an approved security remediation | Automation actor | On the roadmap |
| Decide whether an idle resource is safe to remove | FinOps → Asset → DR | On the roadmap |
| Find business-critical assets with no recovery plan | DR → Asset | On the roadmap |
Getting early access
Early access is by invitation. Onam enables your organisation, connects the agents to your Onam Security data, and sets your autonomy ceiling to “propose”. Ask for early access.
Executing changes in your cloud is not offered in early access. When it is, it will need a write role you create in your own account and an autonomy ceiling you raise yourself — and every change will still need a person’s approval.