Onam
1 · Discover · Onam EstateDiscovery pipeline

Is our inventory current, and did the last run finish?

The Pipeline view is the run history for discovery: every pass over your accounts and regions, what triggered it and how it ended. Discovery is read-only — nothing is installed and nothing is modified.

Illustration: cloud resources on one platform, joined by relationship lines into a single asset graph.
Illustrative
The problem

In your words

Someone asks whether a resource is really gone. The honest answer depends on whether the last discovery run over that account actually finished. A failed or partial run leaves an inventory that looks complete and is not, and without the run history nobody can tell the difference. An inventory without provenance is a claim.
What you see

What Discovery pipeline shows you

Described from the product documentation — what the view holds, not what we hope it will.

  • Run

    The identifier of each discovery run.

  • Trigger

    What started it — the schedule, onboarding, or a manual request.

  • Status

    How the run ended, so a failed or partial run is visible as one.

  • Started and completed

    When it ran, and how long it took.

  • Read-only access

    The same read-only role, service principal or service account as the rest of the platform. Nothing installed on a workload, nothing written to your environment.

How it works

The mechanism, step by step

What Discovery pipeline does, in the order it does it.

  1. 1
    Connect read-only

    Discovery uses the platform's read-only access: an IAM role, a service principal or a service account. No agents, no write permissions.

  2. 2
    Run on schedule

    Runs start on the schedule, at onboarding, or on a manual request. Scheduling is automatic and follows the organisation's entitlement.

  3. 3
    Enumerate and record

    Each run enumerates resources across connected accounts and regions, and writes assets and their relationships as edges.

  4. 4
    Record the run

    Every pass is recorded with its trigger, status, start and completion, so the inventory carries its own provenance.

Limits, said plainly

What it does not do

Knowing where a capability stops is part of deciding whether to buy it.

  • It never writes to your cloud

    Discovery reads. It installs nothing on a workload and changes nothing in your environment.

  • Scope follows entitlement, not settings

    Estate alone runs discovery on its own; Estate with Onam Security runs the full pipeline. There is nothing to configure.

  • Scheduled, not real-time

    The inventory is as current as the last successful run. The run history shows exactly when that was.

Onam AIOps

The Asset Agent

Onam AIOps agents investigate with evidence on every claim and propose changes a person approves. Nothing changes your cloud without that approval.

Asset Agent

Early access

Answers questions over the resolved estate, never by re-scanning — it works from what discovery recorded. In early access, it reads the Onam Security inventory today.

Early access: Running on the Onam platform and enabled per organisation by invitation. Agents answer and propose; nothing changes your cloud.

FAQ

Questions about Discovery pipeline

Neither. Discovery uses read-only cloud credentials, the same connection model as the rest of the platform. Nothing is installed on a workload and nothing in your environment is modified.

1 · Discover · Onam Estate

See Discovery pipeline on your own cloud.

Onam Estate runs in the same console and login as the rest of Onam, with read-only access to your cloud.