Is our inventory current, and did the last run finish?
The Pipeline view is the run history for discovery: every pass over your accounts and regions, what triggered it and how it ended. Discovery is read-only — nothing is installed and nothing is modified.
In your words
Someone asks whether a resource is really gone. The honest answer depends on whether the last discovery run over that account actually finished. A failed or partial run leaves an inventory that looks complete and is not, and without the run history nobody can tell the difference. An inventory without provenance is a claim.
What Discovery pipeline shows you
Described from the product documentation — what the view holds, not what we hope it will.
Run
The identifier of each discovery run.
Trigger
What started it — the schedule, onboarding, or a manual request.
Status
How the run ended, so a failed or partial run is visible as one.
Started and completed
When it ran, and how long it took.
Read-only access
The same read-only role, service principal or service account as the rest of the platform. Nothing installed on a workload, nothing written to your environment.
The mechanism, step by step
What Discovery pipeline does, in the order it does it.
- 1Connect read-only
Discovery uses the platform's read-only access: an IAM role, a service principal or a service account. No agents, no write permissions.
- 2Run on schedule
Runs start on the schedule, at onboarding, or on a manual request. Scheduling is automatic and follows the organisation's entitlement.
- 3Enumerate and record
Each run enumerates resources across connected accounts and regions, and writes assets and their relationships as edges.
- 4Record the run
Every pass is recorded with its trigger, status, start and completion, so the inventory carries its own provenance.
What it does not do
Knowing where a capability stops is part of deciding whether to buy it.
It never writes to your cloud
Discovery reads. It installs nothing on a workload and changes nothing in your environment.
Scope follows entitlement, not settings
Estate alone runs discovery on its own; Estate with Onam Security runs the full pipeline. There is nothing to configure.
Scheduled, not real-time
The inventory is as current as the last successful run. The run history shows exactly when that was.
The Asset Agent
Onam AIOps agents investigate with evidence on every claim and propose changes a person approves. Nothing changes your cloud without that approval.
Asset Agent
Early accessAnswers questions over the resolved estate, never by re-scanning — it works from what discovery recorded. In early access, it reads the Onam Security inventory today.
Early access: Running on the Onam platform and enabled per organisation by invitation. Agents answer and propose; nothing changes your cloud.
Questions about Discovery pipeline
More in Onam Estate
Inventory
What do we run, where, and in which account?
Explore InventoryArchitecture
How is this account wired together, and what reaches outside it?
Explore ArchitectureOnam Estate
Continuous discovery of every cloud resource and the relationships between them — one estate of record that every other product works from.
The whole productSee Discovery pipeline on your own cloud.
Onam Estate runs in the same console and login as the rest of Onam, with read-only access to your cloud.