Γλωσσάρι

Cloud asset inventory

A cloud asset inventory is a complete, continuously updated record of every resource an organization runs — compute instances, storage volumes, networks, and DNS records — across every connected cloud account and on-premise server, including resources provisioned outside official processes that manual, point-in-time audits routinely miss.

Ask most infrastructure teams for a full list of what they run, and the answer is a guess. A wiki page from eighteen months ago. A spreadsheet someone maintains part-time. The real estate is always bigger: a test instance an engineer spun up for a demo and forgot to tear down, a storage bucket created during an incident three teams ago, a DNS record nobody remembers routing anywhere, a whole cloud account opened with a personal card during a hackathon. None of this is malicious — it is just how infrastructure actually grows, one ad-hoc decision at a time, faster than anyone documents it. A cloud asset inventory exists to close that gap: not a snapshot someone updates when they remember, but a live, queryable answer to 'what do we actually have, right now.'

A useful inventory covers more than virtual machines. It tracks storage volumes and their attachment state, virtual networks and the subnets and routes inside them, DNS zones and the records that point at resources which may no longer exist, and security groups or firewall rules that quietly widen over time. It spans every provider an organization uses, not just the primary one — most mid-size infrastructure estates touch at least two or three clouds, plus a handful of bare-metal or on-premise servers that never show up in any cloud console at all. That spread is exactly where blind spots like the ones described above tend to hide: the account nobody remembers opening is rarely on the same provider as everything else. And an inventory has to stay continuous, not periodic — infrastructure changes by the hour, so a list that only refreshes at audit time is already out of date by the time anyone reads it.

In practice, an inventory is built two ways, often combined. For cloud accounts, discovery queries each provider's own API to enumerate what exists — instances, volumes, networks, DNS zones — without installing anything on the resources themselves. For physical servers and on-premise infrastructure, which have no provider API to query, discovery instead relies on a lightweight agent running on each host. Neither approach requires migrating anything: discovery is read-only by design, a way to see what's there before you decide what, if anything, to change. Most organizations then treat the inventory as a starting point rather than an end state — every discovered resource is a candidate for active management, tagging, or cost tracking, brought in one at a time rather than all at once.

Why cloud asset inventory matters

An inventory gap is a blind spot with real consequences. A server nobody remembers exists is a server nobody patches — and unpatched, forgotten infrastructure is a disproportionate source of breaches, precisely because it sits outside normal review. Storage volumes and idle instances left running after a project ends keep costing money indefinitely, invisible until someone happens to notice the bill. And when a regulator, auditor, or customer security questionnaire asks what infrastructure processes their data and who can reach it, "we're not entirely sure" is not an answer that holds up — proving control over an estate starts with proving you know what is in it. Incident response is faster for the same reason: you cannot contain what you cannot find.

How Sencai helps

Sencai connects to existing accounts across all eleven supported providers — nothing migrates, and credentials stay encrypted at rest and revocable at the provider at any time. The moment an account connects, Sencai discovers what's already there: instances, networks, storage, and DNS, across every connected provider. Bare-metal and on-premise servers get the same treatment through a lightweight fleet agent instead of a provider API. Every discovered resource is opt-in — nothing moves under active management until you choose it, one resource at a time — and every action taken afterward lands in an append-only, tamper-evident audit log. A free plan covers five managed resources, no card required.

Explore inventory and provisioning →