Skip to main content

Resources

The Resources page is the asset inventory the scans discovered across the connected accounts: every bucket, instance, database, cluster, and identity, each linked to the findings recorded against it.

No one feeds this inventory. It is a by-product of scanning. If a resource exists in a scanned account, it shows up here with its security context attached.

Filtering​

A single search box sits beside a Filters button that carries a badge with the number of filters currently off their default and opens a grouped popover. Every filter you set becomes a removable chip in a row under the bar, unset filters show as quiet chips that open the popover, and Reset clears them all (the search box included).

The popover groups:

FilterValues
PostureFailing (at least one failing check), Clean (nothing failing), or All
ServiceS3, IAM, EC2, …
Regionany region seen in the connected accounts
Typethe native resource type
Accountone of the connected cloud accounts
Taga discovered key:value tag

Search by name, UID, type, or tag. Selecting a tag, or clicking a tag chip in the table or the resource panel, filters the inventory to that tag.

The posture strip​

Between the filters and the table, a strip states in one line how many resources match, how many on the current page are failing at least one check, and the most affected service.

The table​

Each row shows:

ColumnMeaning
Resourcethe service glyph, the resource name, and its provider-native identifier (the ARN or resource id)
Typethe native resource type
Account and regionthe owning cloud account and where the resource lives
Findingshow many checks the resource is failing
WorstFailing or Clean at a glance
Tagsthe first couple of discovered tags; click one to filter the inventory

A left stripe marks the posture at a glance: the fail colour when the resource is failing, the pass colour when it is clean.

The resource detail​

Open a row and the resource takes the whole page in place of the list, with the navigation still at the side. A breadcrumb at the top reads Resources › the resource; tap Resources (or press Escape, or use your browser's Back) to return to the list exactly as you left it. J and K step to the next and previous resource from the keyboard. / focuses the search box on the list.

  • Header. The service and type, a Worst severity badge (or a Clean pill), the resource name, its copyable identifier, and one line of facts: account and account id, region, service, partition, and the provider groups the account is bucketed into. The header stays neutral; colour is reserved for the checks below.
  • Actions, at the top right (at the bottom of the screen on a narrow tablet). All findings for this resource opens the Findings page scoped to the resource.
  • Posture. How many of the resource's checks are failing, when it was last evaluated, and a bar coloured by severity.
  • Findings. The checks recorded against the resource, in Failing, Passing, and All tabs. Open one in place to read the full finding, then step back — or drill on from there into another affected resource.
  • Change history. Not available yet.
  • Tags, in the side column. The tags discovered at scan time, each one a filter on the inventory.

The open resource lives in the address bar as ?resource=<id>, so an open resource is a link you can send. Anything you open inside the detail from there — a finding, and the affected resource of a finding — is in-memory only and is not written to the URL. The breadcrumb spans both kinds, so a trail can read "Resources › a resource › a check"; each earlier crumb steps back to that level, Escape steps out one level, and the Resources crumb closes the whole trail.

What it is good for​

  • "What is this thing and how bad is it?" Paste a UID from an alert or a ticket into the search and get its full security context.
  • Blast-radius reading. A resource with many failing checks concentrates risk. Fix the resource, not the individual findings.
  • Tag-driven ownership. The discovered tags say whose queue a finding belongs in.

Freshness​

The inventory reflects the most recent scans. A resource created five minutes ago appears after the next run of its account's scan. One deleted yesterday drops out the same way.