01
Knowledge Graph Discovery & Inventory
The Internal Discovery Agent's ability to inventory assets across cloud, code, CI, identity, observability, and data stores from read-only integrations, and to keep that picture current as the environment ships.
“Discovers assets across cloud, code, CI, identity, and data stores” tolmo.com
Mapped capabilities
4 capabilities
Multi-surface asset discovery
Enumerates cloud accounts, repositories, pipelines, identity providers, monitoring tools, and datastores from read-only access, with no deployed agents or code changes.
Relationship inference from configuration
Derives service-to-service calls, repo-to-resource deployment, image-to-service, monitor-to-resource, and workload-to-assumed-identity edges from env vars, event source mappings, secret references, and IaC.
Datastore classification without data access
Classifies what each datastore holds and who reads or writes it, inferred from code, IaC, naming, and graph context rather than by reading stored data.
Graph history and point-in-time rewind
Maintains continuous change history so the state of the environment at a past moment can be reconstructed and queried.





