Security1 distinct publisher2 min readPublished
A security scanner now owns the create, update and retire lifecycle for cloud configuration items. That moves the accuracy of IT's record of record onto whatever the scanner can reach.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
The write path decides how much of this is real. Orca says it syncs through ServiceNow's Service Graph Connector standard, the same one ServiceNow's most trusted data sources use [3], with integration modules running scheduled imports organized by asset type [8]. Deduplication happens in the connector, so new assets are created and existing CIs updated in place instead of duplicated [6]. Synced virtual machine records show Orca as the discovery source, with an attestation score and a most-recent-discovery timestamp [9]. The connector creates and retires the CI rather than annotating one, which is what supports the claim to authority [2].
Coverage sets the ceiling. The CMDB mapping covers what Orca discovers in AWS, Azure, GCP and OCI, across virtual machine, container, Kubernetes, database, load balancer, storage bucket, serverless, networking and identity classes [4]. Orca's own platform description names six clouds, adding Alibaba Cloud and Tencent Cloud [10]. Subtract the four in the CMDB list and two of the clouds Orca sells against are absent from the inventory it offers to own [11]. Silence in the CMDB about workloads there carries no information.
Each CI also carries Orca's risk score as an authoritative security field [5]. The stated payoff is service context: a critical vulnerability on an EC2 instance tied to a payments service should not be worked like the same finding in a dev sandbox, and the CMDB is where that difference becomes visible to the teams acting on it [12]. That holds only if the mapping is correct, and mapping fidelity is asserted in this material rather than measured.
The announcement does not say how precedence is resolved when another discovery source claims the same configuration item, gives no sync interval and no list of the ServiceNow permissions the connector requires, and states neither pricing nor an availability date [13]. Until those exist in writing, the defensible reading is a high-fidelity cloud feed into a record ServiceNow still arbitrates. The reconciliation available to a customer today is arithmetic: Orca's asset count per account against the cloud provider's own inventory, run before any change workflow starts trusting an automatic status flip.
Ranked by verification strength, evidence, and original report placement.
Orca announced that its platform now integrates with ServiceNow's Configuration Management Database (CMDB) to automatically populate and continuously maintain a customer's cloud asset inventory with data from Orca.
Orca says the CMDB integration expands its existing ServiceNow integration for alert-driven ticketing and remediation, and turns Orca into the authoritative source of cloud asset truth for the customer's entire ServiceNow environment.
Orca says it continuously syncs cloud asset inventory into ServiceNow using the same Service Graph Connector standard that ServiceNow's most trusted data sources follow.
Every asset Orca discovers across AWS, Azure, GCP and OCI is mapped automatically to the appropriate CMDB class, covering virtual machines, containers, Kubernetes clusters and workloads, databases, load balancers, storage buckets, serverless functions, networking and identity.
Alongside asset metadata, Orca syncs its risk score for each configuration item into ServiceNow as an authoritative security field, so each CI carries Orca's assessment of the risk the asset represents.
Orca's CMDB integration modules appear in ServiceNow with scheduled imports organized by asset type.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 3, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
build
NVIDIA books $96.2bn at 75% margins and guides 74%: compute is not getting cheaper5 distinct publishers
product
Pulumi points a security agent at its context graph to hunt cloud attack paths1 distinct publisher
build
Identical Helm charts, three clouds, one OOMKill loop: portability is a claim about YAML1 distinct publisher
leadership
Anthropic moves misuse monitoring into cloud storage its customers control3 distinct publishers
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Issuer-only, with screenshots
The class list, the risk-score field, the deduplication behaviour and the retirement logic all come from Orca's own product post. The captioned console images help — synced VM records with attestation scores and Orca named as discovery source are more specific than marketing prose usually gets — but they are still the vendor showing its own screen. Nothing from ServiceNow, a customer, or a third party stands beside it.
Shipped, no users named
What we can confirm is that the connector exists and that teams already running both products are pointed at setup documentation. Beyond that the post is empty of adoption signal: no customer, no count of synced accounts or CIs, no availability date, no indication whether anyone has run it against a CMDB that already has competing discovery sources.
'Source of truth' outruns the stated scope
Claiming to be the authoritative source of cloud asset truth for an entire ServiceNow environment is a claim about precedence in a database that usually has several discovery sources writing to it, and the post never says how a conflict resolves. The mapping also stops at four clouds while Orca's platform description sells six plus PaaS, runtimes and AI agents. The described mechanics are plausible and specific; the framing sits a step ahead of them.
Demo-gated vendor post
Orca is arguing that Orca should own IT's asset record, and the argument ends at a 1:1 demo booking. Writing into the CMDB also changes Orca's commercial position: a tool other teams' change and incident workflows read from is harder to remove than one that only files tickets, so 'source of truth' language does sales work as well as descriptive work.
Clear description, untested behaviour
We can say with confidence what Orca has described, because it is specific enough to be checked later: named clouds, named CMDB classes, a named integration standard, a stated retirement behaviour. We cannot say how any of it holds up in a CMDB with competing discovery sources, and the single self-published account gives us no way to find out.