Asset Inventory

Every device, account, cloud resource and data store your integrations can see — merged into one record per asset, with every tool that reported it attached. It builds itself from the integrations you already run.

Start Free → Book a Demo

✓ Nothing to create ✓ Nothing to maintain ✓ Populates on your next sync

4
Inventories
10
Posture exceptions tracked
12h
Default sync cadence
90d
Retired asset retention

HOW IT WORKS

You already built it. You just can't see it yet.

Asset Inventory is derived, not maintained. There is no importer, no CSV, and no list to keep current.

It fills itself

Every evidence collection that returns an asset also feeds the inventory — on the same sync that gathers your automated compliance evidence. Connect an integration and the inventory populates on its first sync. As assets are decommissioned, it empties itself.

One record per real asset

A laptop enrolled in your MDM that also runs your EDR agent and gets swept by your vulnerability scanner is one device with three sources — not three rows. Merging is deterministic: serial number for devices, email for people, resource ID for cloud.

Unreported is not “no”

Every posture field is tri-state — Yes, No, and Unreported. A device showing Unreported for disk encryption is not counted as unencrypted; it is a device nothing has told you about. Filtering to Unreported finds gaps in your tooling rather than your controls.



Every count appears twice: the large number is logical assets, and the line beneath it is how many provider records were merged to produce them. When two tools disagree, the source closer to the asset wins — your device manager knows more about a laptop than the scanner that swept it once — and precedence is applied per field, so a lower-precedence source still fills in anything the higher one never reported.

THE FOUR INVENTORIES

Endpoints, identities, infrastructure and data

An integration appears only in the lists it can actually speak to. Connecting an MDM populates Devices; it will never populate Cloud.

Devices

Laptops, desktops, servers and other endpoints — with serial number, OS, disk encryption state, MDM compliance and critical CVE counts.

Fed by MDM and endpoint management, EDR, vulnerability scanners, and network asset intelligence.

People

User and service accounts — with email, MFA state, privileged status and last sign-in.

Fed by identity providers, directories and cloud providers.

Cloud

Compute and infrastructure resources — with resource type, region and public exposure.

Fed by cloud providers.

Data stores

Databases, buckets and other stores holding data — with resource type, region, public exposure and encryption at rest.

Fed by cloud providers.

WHAT COUNTS AS AN EXCEPTION

Ten posture gaps, worst first

The overview surfaces every non-empty gap across all four inventories, and each one links straight to the filtered list that produced it. You go from “11 unencrypted devices” to those eleven devices in one click.

No MFA Privileged account Unencrypted device MDM non-compliant Critical CVEs Not in MDM No EDR Stale 30 days Publicly exposed Unencrypted data store

Coverage gaps only fire for tools you actually have. “No EDR” stays silent until you connect an EDR, and “Not in MDM” until you connect an MDM — so you never open the page to a wall of red for products you never bought. Counts are asset counts, not occurrence counts: “Critical CVEs 11” means eleven devices carry at least one critical CVE, not eleven CVEs.

WORKING THE LISTS

Every view is a filter, and every filter is a link

Stat cards are filters

The cards along the top of each list are that inventory's exception counts. Click one to filter the list to exactly what it counted; click again to clear. The first card clears everything at once.

Shareable by URL

Every filter lives in the URL, so a filtered view is a link. Send a colleague “devices with no EDR” and they see exactly what you saw. Filter by environment, by provider, by tri-state posture, or search name, email, serial and hostname.

Every source, on the record

Open any asset to see the resolved value for each field, plus one card per source showing that provider's own identifier, when it was first seen, when it was last collected, and a click-through to the underlying evidence collection.

ASSET INVENTORY VS SECURITY INVENTORY

What you bought, and what it's actually protecting

RealCISO keeps both, because they answer different questions.

Security Inventory

A point-in-time record of the security products you have purchased and the controls they cover. It is the coverage claim — curated by you, snapshotted on a cadence you choose.

Asset Inventory

The live list of the assets those products are protecting, built from what your integrations actually report. It is the ground truth the claim runs against.



Retired, not deleted. When a sync stops seeing an asset it was previously reporting, the record is marked retired with the date it was last seen rather than vanishing. A merged asset is only retired once every source has stopped reporting it. Retired assets are hidden by default and excluded from every count and exception, and are removed permanently 90 days after they were last seen. If a provider starts reporting an asset again, it comes straight back.

THE SAME PRINCIPLE, ONE LAYER UP

Tests never change your control assessment

Integrations collect evidence. Automated tests run against that evidence and return pass or fail. Then they stop. A test result appears on the control page and is recorded in its history, but the control status stays exactly where you set it until a person changes it.

That separation exists for the same reason posture fields are tri-state. A test can only see what is connected. If a test could set your control status, the platform would be telling you your MFA is compliant while fifty people sit on a local directory it has never heard of. A test result is an input to a judgment — not a substitute for one.

See what your tools can — and can't — see

Asset Inventory sits at the organization level and spans every active environment you have access to. If it's empty, no connected integration has collected an asset yet — connect one from Environment → Settings → Cloud Integrations and it populates on the first sync.

Start Free → Book a Demo

Asset Inventory is available now and marked Early Access in the app: the data is real and safe to use, and the views and posture signals continue to evolve on customer feedback.