agent-bom
Connecting...

Data sources

Data sources and operating surfaces

The product should support three honest modes: launch direct scans, connect to a read-only source, or ingest evidence that the customer already centralizes elsewhere. This page makes those boundaries explicit and also shows where runtime, fleet, graph, and policy surfaces fit once the data is in the system.

Canonical model firstRead-only where possibleBring your data when collection already exists

Direct scans

Agentless or local scan jobs that agent-bom launches directly.

Connected sources

Read-only sources where the customer points us at a cloud or SaaS system that already contains the data.

Read-only integration

Governance and cloud activity

Snowflake-backed governance, access history, and activity pages already consume cloud-side telemetry without forcing everything through the local scan form.

Shipping nowOpen Governance
Read-only integration

Connector-backed discovery

The backend exposes connector and SIEM connector routes today. The product still needs a first-class setup wizard in the UI.

API first today

Ingested evidence

Evidence pushed into agent-bom from an existing collector, exporter, or security data lake workflow.

Imported artifacts

Customer-exported files that agent-bom can analyze without managing the source system.

Operating surfaces after ingest

Discovery and ingest are only the front door. Agent-bom also needs clear surfaces for runtime review, fleet operations, policy enforcement, and graph analysis after the data lands.

Guardrail principle

Prefer agentless read-only discovery when the product can safely gather the data itself. When the customer already owns the collection path, use imported artifacts or pushed ingest instead of rebuilding their telemetry pipeline inside agent-bom.