Multi-cloud discovery

Find what live cloud is hiding.

ops0 scans AWS, GCP, Azure, and Oracle Cloud read-only for exposure, drift, unmanaged resources, and cost risk, before they become incident work. Then it turns the resources you pick into reviewed IaC.

AWS, GCP, Azure, and OCI
Correlated risk, graded A to F
Drift and shadow-resource alerting
Idle and orphaned spend detection

ops0 brings your clouds, runtime, infrastructure code, and workflows into one operating context. Multi-cloud discovery scans live cloud read-only to find exposure, drift, unmanaged resources, and cost risk before they become incidents.

ops0.ai/features/discovery/snapshot
ops0 discovery snapshot: security grade C, 312 findings by severity, regional footprint, 6 compliance frameworks, and recoverable spend

Your console shows one account at a time. Discovery shows everything running, at once. 

Read-only230+ resource types3 scan enginesGraded A to F
Discovery, live
01 / 04 · Connect

Connect read-only.

Four accounts across AWS, GCP, and Azure, with least-privilege, read-only access. Nothing in your cloud changes.

prod-payments-01shared-servicesanalytics-prodcorp-it
Going deeper

Everything a finding needs to be fixed.

Live cloud inventory

See what is actually running.

Find real cloud state across accounts and regions.
Surface unmanaged resources, exposure, and drift.
Accounts
8
scanned
Regions
4
scanned
Resource types
27
discovered
Total resources
3,800
live
Monthly spend
$155,000 /mo
Recoverable
$12,400 /mo
Findings
312
Under the hood

Discovery that stays current.

Coverage
230+ resource types, across every cloud you run.
AWS
EC2RDSS3IAM RoleSecurity Group
GCP
GCECloud SQLGCS BucketIAM Binding
Azure
Virtual MachineBlob StorageNSG
Kubernetes
DeploymentServiceIngress
Access
Read-only by design.
describe, list, getallowed
create, delete, modifyno write path

Least-privilege credentials. Nothing in your cloud changes.

Scoring
Graded A to F.
ABCDF

One grade per account, from what three engines confirmed together.

Kiwi
Ask about any account.
@ops0 what changed in prod-payments-01 this week?
12 resources added, 3 removed. One new security group is reachable from the internet.
Session diff
What changed since last week.
+12
added
-3
removed
27
changed
Schedule
Recurring scans.
FrequencyDaily · 02:00 UTC
Last run6 hours ago
Next runin 18 hours

In practice

Start cloud discovery with one read-only account.

Use a small, known environment for the first scan. Check what the connection can see, reconcile the inventory with your cloud console, and decide which unmanaged resources should move under IaC.

  1. Connect one account

    Choose the AWS account, GCP project, Azure subscription, or OCI scope you want to inspect. Use the read-only connection path and have the account owner review the requested access.

  2. Check permissions and regions

    Confirm that access covers the services and regions you expect to scan. Record permission failures or excluded scopes so a missing resource is not mistaken for an empty environment.

  3. Run discovery and compare inventory

    Review resource identifiers, account or project, region, and resource type. Compare a few known resources with the provider console before expanding the scan.

  4. Review owners, findings, and dependencies

    Check unmanaged resources, missing owner tags, exposure, and dependency context. Verify a relationship against configuration or provider evidence before using it to scope a change.

  5. Plan IaC adoption

    Select a bounded resource group, review the generated code, and check existing state ownership and import identifiers. Review the plan with the owning team. Generating HCL, importing state, and applying a change are separate decisions.

Inventory completeness depends on the connected scope, permissions, regions, and supported resource types. Reconcile gaps before drawing conclusions from a scan.

Common questions

Multi-cloud discovery is the process of scanning cloud environments across AWS, GCP, Azure, OCI, and Kubernetes to build a current inventory of live resources, their dependencies, and the risk attached to them: drift, unmanaged resources, public exposure, idle cost, and policy gaps. In ops0 it runs read-only first, so teams see what is actually running before any change is made.

See your whole cloud.
Before the next change.

Connect one account read-only. ops0 maps what is running, what changed, and what depends on what, and Kiwi answers questions about it in plain language.

Explore IaC