Access & Entitlement
One login, one console
Onam Estate runs at /estate inside the same console as the rest of the platform, behind the same session. You switch to it from the product switcher — there is no second login, no second URL to remember and no separate credential.
Entitlement
Estate is a per-organisation add-on, granted individually. It is not part of any Onam Security plan tier, so upgrading a security plan does not turn it on.
- Organisations without the grant do not see the Estate link at all — it is hidden rather than shown greyed-out.
- The API gateway enforces the same grant server-side on every Estate request, so hiding the link is a user-experience choice and not the security boundary.
"I'm on Enterprise, why can't I see Estate?" Because it is not a tier feature. Ask your platform administrator to grant the add-on for your organisation, or talk to us.
Permissions
Discovery uses the same read-only cloud credentials as the rest of the platform — a read-only IAM role, service principal, or service account. Estate installs nothing on a workload, holds no long-lived keys, and never writes to your environment.