What do we run, where, and in which account?
The Inventory view lists every resource Onam Estate's discovery has found, across every connected account and region — each with the time discovery last confirmed it exists.
In your words
Someone asks how many production databases we run, and in which accounts. We get three answers: one from the CMDB, one from Terraform state, one from the billing export. The CMDB was last reconciled by hand, the state file only covers what went through the pipeline, and nobody can say which list is right. The gap between them is where forgotten infrastructure lives.
What Inventory shows you
Described from the product documentation — what the view holds, not what we hope it will.
Asset and type
The resource name with its type, for every resource the discovery pipeline has found.
Provider, region and account
Which cloud it was discovered in, the region it lives in, and the account or subscription that owns it.
Lifecycle state
The resource's current state, as discovery last recorded it.
Last seen
How long ago discovery last confirmed the resource exists. A resource that stops appearing ages instead of silently vanishing.
All 7 supported clouds
AWS, Azure, Google Cloud, Oracle Cloud, Alibaba Cloud, IBM Cloud and Kubernetes — from the platform's shared discovery.
Quick on very large estates
Listings are keyset-paginated, so each page costs the same however deep you are in a list of hundreds of thousands of assets.
The mechanism, step by step
What Inventory does, in the order it does it.
- 1Discover
A discovery pipeline enumerates resources across your connected accounts and regions with read-only credentials. Nothing is installed and nothing is modified.
- 2Record each asset
Each resource is written as an asset with provider, region, account, state and last-seen time.
- 3Confirm on every run
Each run confirms the resources it finds again. A resource that is no longer found keeps its row, and its last-seen time ages.
- 4Read the list
The Inventory view lists every asset across accounts and regions, paged with keysets so large estates stay quick.
What it does not do
Knowing where a capability stops is part of deciding whether to buy it.
It does not show cost
Estate answers what exists and how it is connected, not what a resource costs. Spend, owners, forecasts, budgets and savings are Onam FinOps, a separate product built on your billing data.
It does not raise security findings
Estate does not evaluate posture rules, score risk or raise findings. That is Onam Security, which reads the same discovery output.
As current as the last run
The list reflects the last completed discovery run, not a real-time feed. Last-seen times and the run history show how fresh it is.
The Asset Agent
Onam AIOps agents investigate with evidence on every claim and propose changes a person approves. Nothing changes your cloud without that approval.
Asset Agent
Early accessAnswers what exists, how it is connected and who owns it — over the resolved estate, never by re-scanning. In early access, it reads the Onam Security inventory today.
Early access: Running on the Onam platform and enabled per organisation by invitation. Agents answer and propose; nothing changes your cloud.
Questions about Inventory
More in Onam Estate
Architecture
How is this account wired together, and what reaches outside it?
Explore ArchitectureDiscovery pipeline
Is our inventory current, and did the last run finish?
Explore Discovery pipelineOnam Estate
Continuous discovery of every cloud resource and the relationships between them — one estate of record that every other product works from.
The whole productSee Inventory on your own cloud.
Onam Estate runs in the same console and login as the rest of Onam, with read-only access to your cloud.