Resources
The Resources page is the asset inventory the scans discovered across the connected accounts: every bucket, instance, database, cluster, and identity, each linked to the findings recorded against it.
No one feeds this inventory. It is a by-product of scanning. If a resource exists in a scanned account, it shows up here with its security context attached.
Filtering
A single search box sits beside a Filters button that carries a badge with the number of filters currently off their default and opens a grouped popover. Every filter you set becomes a removable chip in a row under the bar, unset filters show as quiet chips that open the popover, and Reset clears them all (the search box included).
The popover groups:
| Filter | Values |
|---|---|
| Posture | Failing (at least one failing check), Clean (nothing failing), or All |
| Service | S3, IAM, EC2, … |
| Region | any region seen in the connected accounts |
| Type | the native resource type |
| Account | one of the connected cloud accounts |
| Tag | a discovered key:value tag |
Search by name, UID, type, or tag. Selecting a tag, or clicking a tag chip in the table or the resource panel, filters the inventory to that tag.
The posture strip
Between the filters and the table, a strip states in one line how many resources match, how many on the current page are failing at least one check, and the most affected service.
The table
Each row shows:
| Column | Meaning |
|---|---|
| Resource | the service glyph, the resource name, and its provider-native identifier (the ARN or resource id) |
| Type | the native resource type |
| Account and region | the owning cloud account and where the resource lives |
| Findings | how many checks the resource is failing |
| Worst | Failing or Clean at a glance |
| Tags | the first couple of discovered tags; click one to filter the inventory |
A left stripe marks the posture at a glance: the fail colour when the resource is failing, the pass colour when it is clean.
The resource detail
Open a row and the resource takes the whole page in place of the list, with the navigation still at the side. A breadcrumb at the top reads Resources › the resource; tap Resources (or press Escape, or use your browser's Back) to return to the list exactly as you left it. J and K step to the next and previous resource from the keyboard. / focuses the search box on the list.
- Header. The service and type, a Worst severity badge (or a Clean pill), the resource name, its copyable identifier, and one line of facts: account and account id, region, service, partition, and the provider groups the account is bucketed into. The header stays neutral; colour is reserved for the checks below.
- Actions, at the top right (at the bottom of the screen on a narrow tablet). All findings for this resource opens the Findings page scoped to the resource.
- Posture. How many of the resource's checks are failing, when it was last evaluated, and a bar coloured by severity.
- Findings. The checks recorded against the resource, in Failing, Passing, and All tabs. Open one in place to read the full finding, then step back — or drill on from there into another affected resource.
- Change history. Not available yet.
- Tags, in the side column. The tags discovered at scan time, each one a filter on the inventory.
The open resource lives in the address bar as ?resource=<id>, so an open
resource is a link you can send. Anything you open inside the detail from
there — a finding, and the affected resource of a finding — is in-memory only
and is not written to the URL. The breadcrumb spans both kinds, so a trail can
read "Resources › a resource › a check"; each earlier crumb steps back to that
level, Escape steps out one level, and the Resources crumb closes the
whole trail.
What it is good for
- "What is this thing and how bad is it?" Paste a UID from an alert or a ticket into the search and get its full security context.
- Blast-radius reading. A resource with many failing checks concentrates risk. Fix the resource, not the individual findings.
- Tag-driven ownership. The discovered tags say whose queue a finding belongs in.
Freshness
The inventory reflects the most recent scans. A resource created five minutes ago appears after the next run of its account's scan. One deleted yesterday drops out the same way.