Ask three teams how many cloud accounts the company has and you will get three numbers.
The spreadsheet is a year old, the tagging standard was adopted by two of nine teams, and the account someone opened for a proof of concept in 2022 is still running, still billed, and still has a production database in it. Every security control you own applies only to the resources you know about.
The risk of not knowing
If it is not surfaced today, it is exposed today. Attackers do not wait for your quarterly review — and neither do auditors.
The mechanism, not the marketing
- 1
Discovery enumerates every resource across AWS, Azure, GCP, OCI, Alibaba Cloud, IBM Cloud and Kubernetes — 549 services in total — using read-only credentials.
- 2
Each resource is normalised into a shared model, so an AWS security group and an Azure network security group are comparable objects rather than two vendor formats.
- 3
Relationships are modelled explicitly — which instance sits in which subnet, which role is assumed by which function, which volume is attached where — forming the graph that attack-path analysis walks.
- 4
Discovery runs continuously, so new resources appear in inventory within minutes of creation and deleted resources are retired rather than lingering.
- 5
Every other engine reads from this inventory, which is why a resource cannot be evaluated by one engine and invisible to another.
Specific outputs, measurable outcomes
Asset Inventory & Discovery in the real console.
Not a mockup — the actual Onam console on a live demo account, showing exactly what your team sees.
Questions we get a lot
Ready to see Asset Inventory & Discovery in your cloud?
Connect a read-only role in three minutes. Your first findings surface in under five.