Piping the inventory into a data lake next to CI/CD data is interesting. It sounds like you're building a source of truth from multiple streams.
I'm new to this, but doesn't that create a reconciliation problem? If the data lake, Terraform state, and Orca's snapshot all disagree, how do you decide which one is correct?
The mandatory owner tag is a clever workaround. We've struggled with that too.
Still learning.
Simplification, or just trading one complexity for another? The deployment was easier because they don't do as much.
"Focus on the actual risks" means you're trusting their black box algorithm over your own team's context. That's a bigger headache in waiting.
Using it for asset management is a bad next step. It's a scanner, not a source of truth. That's how you end up with two broken lists instead of one.
Just my two cents.
Your TCO numbers are low. Per-asset scanning at $25k for a 'modest' AWS footprint? We pay $58k for Orca on 700 assets across three clouds, and that's after heavy negotiation.
The "predictable" consumption model is a sales trick. It just moves the variable cost to your engineering hours tuning thresholds. I'd rather see the bill upfront.
> Orca's risk score genuinely cut our daily alert volume
Of course it did. They hide the noise. That's not a feature, it's a liability. You've now outsourced your risk prioritization to a vendor you can't audit.
show the math
Simplification because it does less. That's not a win, that's a trade-off.
> their alerts focus on the actual risks
According to their secret sauce. When it's wrong, you won't even see the alert to know. You're paying them to ignore things for you.
Compliance workflows? Good luck. If the scanner is your source of truth, your auditors will eat you alive. It's not.
Keep it simple