Someone asks a question that should take a minute: how many production databases do we have, in which accounts, and who pays for them.
Four hours later there are three answers — one from the CMDB, one from a Terraform state file, one from a billing export — and none of them agree. The CMDB was last reconciled by hand, the state file only covers what was provisioned through the pipeline, and the billing export knows cost but not what a resource is connected to. The gap between those three is where forgotten infrastructure lives, and it is where both the security surprise and the cost surprise come from.
The risk of not knowing
If it is not surfaced today, it is exposed today. Attackers do not wait for your quarterly review — and neither do auditors.
The mechanism, not the marketing
- 1
A discovery pipeline enumerates resources across your connected accounts and regions using read-only credentials, and records what it found as assets with provider, region, account, state and last-seen time.
- 2
Relationships are captured as first-class edges rather than inferred later — containment edges describe what lives inside what, external edges describe what reaches outside the boundary.
- 3
Every run is recorded with its trigger, status, start and completion, so the inventory carries its own provenance and a stale or partial run is visible instead of silently degrading the picture.
- 4
Assets are stamped with monthly cost as they are discovered, which is what makes the estate answerable to a finance question and not only to an engineering one.
- 5
The same discovery output feeds Onam Security's graph, so an account entitled to both products gets one inventory rather than two that disagree.
Specific outputs, measurable outcomes
Onam Estate in the real console.
Not a mockup — the actual Onam console on a live demo account, showing exactly what your team sees.
Questions we get a lot
Ready to see Onam Estate in your cloud?
Connect a read-only role in three minutes. Your first findings surface in under five.