Discovery
How TENSOR Discovery compares what your tools observe with the CMDB and turns every difference into a decision a person makes.
Preview — not yet field-tested
TENSOR Discovery is built, but it has not yet been validated against real customer environments. Every source, rule and report in this section has been tested with simulated data only. Before you rely on it in production, run a pilot in a test tenant with your own scanner, Intune tenant or cloud accounts, and compare the results with what you know about your estate.
TENSOR Discovery keeps your CMDB honest. It reads what your existing tools can see about your IT estate — vulnerability scanners and endpoint management today, with cloud accounts and an on-premises collector to follow — compares those observations with the configuration items (CIs) in the CMDB, and turns every difference into something a person can review and decide.
Discovery answers the auditor question How do you know your CMDB reflects reality? with evidence rather than a claim. It does not replace your CMDB and it never quietly rewrites it: discovery proposes, people decide, and every decision is written to the tamper-evident audit log.
Several capabilities described in this section are partially available or planned. Each page states the current limitation next to the feature; the full picture is on Availability.
Who uses Discovery
| Persona | What they do in Discovery |
|---|---|
| Tenant administrator | Switches the Discovery feature on, connects the external tools (scanner, Intune) under Settings → Integrations and acknowledges non-EU data residency. |
| CMDB administrator | Commissions sources, approves their scope, works the review inbox, decides deviations, topology links and absent CIs, seals the attestation. |
| Platform owner | Holds the same discovery rights as the CMDB administrator; typically owns the verification policy and production apply. |
| CI owner (business or technical) | Becomes the accountable owner of a deviation raised against their CI. |
| Auditor | Reads the attestation, the deviation queue, per-CI verification and the absence queue. Cannot change anything. |
The rights behind each persona are listed in Roles and permissions.
Problems Discovery solves
- Stale CMDB data. Attributes such as IP address, OS build or installed software drift silently. Discovery detects the drift and raises it as a deviation with an owner and a due date.
- Unproven inventory. Regulators ask how you know the inventory is accurate. Discovery counts which CIs a second, independent system has confirmed, and reports that figure with its denominator.
- Silent overwrites. Automated tools that write straight into a CMDB destroy curated data. Discovery decides per attribute which source may win, and never touches ownership or criticality.
- Ghost assets. Machines that were decommissioned but still sit in the CMDB. Discovery proposes them for retirement after repeated successful runs no longer see them. It never deletes anything.
- Unknown vulnerabilities. Open scanner findings land as CVEs on the matching CI, feeding the existing CVE and DORA detection workflows.
Key concepts
| Term | Meaning |
|---|---|
| Discovery source | One external system that delivers observations, for example a Tenable scanner or a Microsoft Intune tenant. Each source has a kind (such as vuln_scanner) and an origin system. |
| Origin system | The system that actually produced the data. Two sources with the same origin (for example Entra and Intune) never count as independent confirmation of each other. |
| Commissioning state | Where a source stands on its safety ladder: disabled, connection test, observe only, active, paused or quarantine. |
| Run | One pull from a source, recorded in the Run ledger with its scope, counts and outcome. |
| Observation | One record a source reported, stored as immutable evidence. An identical re-observation is not stored twice. |
| Reconciliation link | The answer to which CI an observation is about: unmatched, linked, ambiguous or blocked by an earlier split decision. |
| Source precedence | The per-attribute rule that decides which source may set a value, for example Intune for the OS build. |
| Governance attributes | Owner, technical owner, criticality tier and supports critical function. No source may ever set them. |
| Deviation | A recorded disagreement between the CMDB (Soll) and an observation (Ist), with severity, owner and due date. |
| Verification | Confirmation of a CI by an independent origin system. A CI is independently verified, stale or single-sourced by construction. |
| Tombstone candidate | A CI that enough successful runs no longer see. A proposal to retire, never a deletion. |
| Attestation | The auditor report that states how much of the CMDB is independently verified, sealed as an immutable artifact. |
| Collector | An on-premises agent (outbound-only) that runs discovery inside your network and reports to TENSOR. Partially available: see Sources and commissioning. |
Discovery proposes, people decide
No part of Discovery closes a deviation, retires a CI or overwrites a governance attribute on its own. Every such outcome requires a named person and is recorded in the audit chain.
Where to find it
Discovery is switched on per tenant with the discovery_sources feature flag (see How it works). Once it is on, the entry Discovery sources appears under Assets & Risk in the sidebar for users who hold discovery rights. It leads to five pages:
| Page | What it shows |
|---|---|
| Discovery sources | Every registered source with its commissioning state, the Microsoft Intune onboarding panel and the Run ledger. |
| Deviations | The page Verification and drift with the Deviation queue. |
| Review inbox | Every discovery decision waiting on a person, including Observed topology links. |
| Absent CIs | The page Absent assets with tombstone candidates. |
| Attestation | The page CMDB attestation. |
Each page only appears when you hold that page's read permission and the feature is on. Integrations — the data connections behind sources — are configured under Settings → Integrations, and ambiguous identities are settled in the CMDB's own Reconciliation queue (see Reconciliation and import).
In this section
- How it works — the pipeline, tenant isolation, background jobs, feature flags, data protection and audit trail.
- Roles and permissions — who holds which discovery right, and the separation of duties enforced in code.
- Sources and commissioning — the supported sources, the safety ladder, the run ledger and the on-premises collector.
- Reconciliation and apply — matching observations to CIs, per-attribute precedence, apply or review, and bounded production apply.
- Deviations and attestation — Soll/Ist deviations, verification, absent assets, the review inbox, software and CVE enrichment, and relationship mapping.
- Lifecycle and processes — states and transitions for sources, runs, deviations and tombstone candidates, and the end-to-end sequence per persona.
- Compliance — the regulatory requirements Discovery provides evidence for, and the flags you need.
- Guides for administrators — switching Discovery on, connecting and commissioning sources, and granting access.
- Guides for CMDB reviewers and auditors — the review inbox, deviations, identities, absent CIs and the attestation.
- Troubleshooting and FAQ — symptoms, causes and what to do.
- Availability — the implementation status of every capability as of 24 September 2026.