Assets¶
The Assets area provides visibility into all asset types managed within the platform. This includes cloud assets synced from your environment as well as alternative asset types used for reporting and advanced workflows.
Asset Types¶
Assets are filtered by type using the sidebar. The main asset types include:
- Cloud Assets - resources synced from your cloud environment (e.g. EC2 instances, S3 buckets, RDS databases). These are used for associating issues such as vulnerabilities and configuration findings back to the specific resources they affect.
- Hardware Assets - physical and endpoint resources in scope, maintained alongside cloud assets in the asset register
- Capability - organizational or system capabilities tracked within the platform
- Components - system components documented for inventory and boundary reporting
- Containers - container-based resources tracked within the environment
- Interfaces - system interfaces and integration points
- Implemented Requirements - control implementation records used in compliance reporting and advanced platform workflows
Assessment scope
Every information resource in the assessment scope is represented by one of three record types: a Component, a Cloud Asset, or a Hardware Asset. Provider integrations synchronize the register daily from the cloud and endpoint estate. See the Asset, Inventory & Assessment Scope policy for the full model.
System Documentation Assets¶
The compliance asset types (Capability, Component, Control Implementation, Implemented Requirement, Implementation Statement, Set Parameter) together form the system's OSCAL-based documentation: each Implementation Statement records how the platform implements specific FedRAMP controls, requirements, and KSIs per baseline, and the set renders into authorization package artifacts.
Usage¶
Cloud assets are the primary working set for most agents, providing the link between scan findings and the actual resources in your environment. The other asset types support compliance reporting, inventory documentation, and automated workflows within the platform such as mapping implemented requirements to controls and generating authorization package artifacts.

