How is this account wired together, and what reaches outside it?
The Architecture view summarises one account's topology: what it holds, how the pieces connect, and which relationships cross the account boundary. It draws AWS accounts today.
In your words
We have a diagram of how an account is supposed to look. It was drawn for a design review and has not been touched since. What we need to know is what the account actually holds and what it really connects to — the peering, the cross-account trust, the shared service — because that is what decides whether it is isolated, whatever the diagram says.
What Architecture shows you
Described from the product documentation — what the view holds, not what we hope it will.
Assets
The resources discovered in this account.
Edges
The total of recorded relationships between those resources.
Containment edges
"Lives inside" relationships — a subnet in a VPC, a container in a task.
External edges
Relationships that cross the account boundary. The number to read first: an account with very few is genuinely isolated; one with many is not.
Asset type breakdown
Assets by type, so sprawl is visible by shape and not only by total. Two thousand log groups is a different estate from two thousand compute resources.
The mechanism, step by step
What Architecture does, in the order it does it.
- 1Discover
The discovery pipeline enumerates the account's resources with read-only credentials and writes each one as an asset.
- 2Record relationships
Relationships are written as edges: containment edges for what lives inside what, external edges for what crosses the account boundary.
- 3Build the scene
The discovery pipeline builds a scene for the account — what the view renders from.
- 4Render the view
The Architecture view renders from that scene. An account that has never completed a run has no scene, and the view says so instead of drawing an empty diagram.
What it does not do
Knowing where a capability stops is part of deciding whether to buy it.
AWS accounts only, today
The per-account architecture view draws AWS accounts today. The asset inventory itself covers all 7 supported clouds.
Nothing to draw before a completed run
The view renders from a scene the discovery pipeline builds. Until an account completes a run, the view says there is no scene rather than showing an empty diagram.
It does not judge the topology
It shows how the account is connected. It does not evaluate posture or raise findings about it — that is Onam Security.
The Asset Agent
Onam AIOps agents investigate with evidence on every claim and propose changes a person approves. Nothing changes your cloud without that approval.
Asset Agent
Early accessMaps relationships and dependencies between resources, and answers how the estate is connected. In early access, it reads the Onam Security inventory today.
Early access: Running on the Onam platform and enabled per organisation by invitation. Agents answer and propose; nothing changes your cloud.
Questions about Architecture
More in Onam Estate
Inventory
What do we run, where, and in which account?
Explore InventoryDiscovery pipeline
Is our inventory current, and did the last run finish?
Explore Discovery pipelineOnam Estate
Continuous discovery of every cloud resource and the relationships between them — one estate of record that every other product works from.
The whole productSee Architecture on your own cloud.
Onam Estate runs in the same console and login as the rest of Onam, with read-only access to your cloud.