Onam
1 · Discover · Onam EstateArchitecture

How is this account wired together, and what reaches outside it?

The Architecture view summarises one account's topology: what it holds, how the pieces connect, and which relationships cross the account boundary. It draws AWS accounts today.

Illustration: cloud resources on one platform, joined by relationship lines into a single asset graph.
Illustrative
The problem

In your words

We have a diagram of how an account is supposed to look. It was drawn for a design review and has not been touched since. What we need to know is what the account actually holds and what it really connects to — the peering, the cross-account trust, the shared service — because that is what decides whether it is isolated, whatever the diagram says.
What you see

What Architecture shows you

Described from the product documentation — what the view holds, not what we hope it will.

  • Assets

    The resources discovered in this account.

  • Edges

    The total of recorded relationships between those resources.

  • Containment edges

    "Lives inside" relationships — a subnet in a VPC, a container in a task.

  • External edges

    Relationships that cross the account boundary. The number to read first: an account with very few is genuinely isolated; one with many is not.

  • Asset type breakdown

    Assets by type, so sprawl is visible by shape and not only by total. Two thousand log groups is a different estate from two thousand compute resources.

How it works

The mechanism, step by step

What Architecture does, in the order it does it.

  1. 1
    Discover

    The discovery pipeline enumerates the account's resources with read-only credentials and writes each one as an asset.

  2. 2
    Record relationships

    Relationships are written as edges: containment edges for what lives inside what, external edges for what crosses the account boundary.

  3. 3
    Build the scene

    The discovery pipeline builds a scene for the account — what the view renders from.

  4. 4
    Render the view

    The Architecture view renders from that scene. An account that has never completed a run has no scene, and the view says so instead of drawing an empty diagram.

Limits, said plainly

What it does not do

Knowing where a capability stops is part of deciding whether to buy it.

  • AWS accounts only, today

    The per-account architecture view draws AWS accounts today. The asset inventory itself covers all 7 supported clouds.

  • Nothing to draw before a completed run

    The view renders from a scene the discovery pipeline builds. Until an account completes a run, the view says there is no scene rather than showing an empty diagram.

  • It does not judge the topology

    It shows how the account is connected. It does not evaluate posture or raise findings about it — that is Onam Security.

Onam AIOps

The Asset Agent

Onam AIOps agents investigate with evidence on every claim and propose changes a person approves. Nothing changes your cloud without that approval.

Asset Agent

Early access

Maps relationships and dependencies between resources, and answers how the estate is connected. In early access, it reads the Onam Security inventory today.

Early access: Running on the Onam platform and enabled per organisation by invitation. Agents answer and propose; nothing changes your cloud.

FAQ

Questions about Architecture

AWS accounts today. The asset inventory covers all 7 clouds Onam supports, because it comes from the platform's shared discovery; the per-account topology view is AWS-only for now.

1 · Discover · Onam Estate

See Architecture on your own cloud.

Onam Estate runs in the same console and login as the rest of Onam, with read-only access to your cloud.