Assets

Keep the asset register current: discovered and manual assets, grouping, ownership, classification, and risk links.

RolesViewerEditorAdminRoute/assetsShown toCompliance organizations

What it is

The asset register lists the systems, services, devices, and data stores your program covers. Most rows arrive from data sources: cloud accounts, repositories, and SaaS tools are discovered and refreshed on every sync. The rest you add by hand. Each asset carries an owner, a type, a source, data classification, and optional links to risks. The register itself is evidence: the dashboard's 4. Assets step counts assets with an owner, and the asset inventory control is satisfied once the register has at least one asset.

Where to find it

Assets
The asset register with the ownership, source, and type filters and the insight stripThe asset register with the ownership, source, and type filters and the insight strip
The register. Unassigned counts the assets still without an owner.

The insight strip shows Assets, Assigned, Unassigned, and Profile complete. Columns are Asset, Type, Source, Owner, Findings / Risks, and Updated.

Key actions

Add an asset by hand

Click Add Assets.
Enter a name (placeholder "Asset name") and pick the Type, Source, and Platform.
Optionally Link risk to an existing risk.
Under Data categorization, set Confidentiality, Integrity, and Availability (each starts as "Unclassified"), a retention period ("e.g. 7 years"), encryption at rest and in transit, and the data types held.
Open Advanced for an External ID ("Provider asset identifier") and free-form Metadata JSON.
Click Create asset.
The create asset dialog with type, source, risk link, and data categorization fieldsThe create asset dialog with type, source, risk link, and data categorization fields
The create dialog. Classification can be left for the bulk editor.

Filter the register

Filters are Ownership status (Assigned or Unassigned), Source, Type, Confidentiality, and Owner. Filter by Unassigned after each sync to find what still needs an owner.

Edit many assets at once

Select rows, or Select all followed by the total count.
Click Edit to open Bulk Edit Assets.
Every field starts as "No change": Owner, Confidentiality, Integrity, Availability, Type, Retention period, encryption, and Data types. Set only the ones you mean to change.
Click Apply changes.

The bulk bar also offers Link Risk and delete. Viewers see the text Read-only access instead.

Inspect an asset

Click a row to open the drawer. Properties shows Type, Source, Owner, Platform, Confidentiality, Integrity, Availability, and Linked risk. Data categorization shows Retention, Encrypted (rest), and Encrypted (transit). Advanced shows the External ID, and the menu offers Copy ID.

Group ephemeral cloud assets automatically

The Automatic asset grouping dialog with three steps and AWS, Azure, and GCP tabsThe Automatic asset grouping dialog with three steps and AWS, Azure, and GCP tabs
The grouping guide. The tag key is noru-asset on every provider.

Autoscaled instances, containers, and functions come and go, and each would otherwise be a separate row. Tag them in the cloud and Noru folds them into one asset.

On the banner Automatically group ephemeral assets, click View tagging instructions to open Automatic asset grouping.
Apply a shared tag: on the AWS or Azure tab a Tag, on the GCP tab a Label, with key noru-asset and a value naming the logical asset, for example noru-asset=payments-worker. "At least two resources from the same provider must have the same exact, case-sensitive value."
Wait for the next sync.
Noru groups matches: the register shows one row with noru-asset= and the value, an "N grouped" count, and a Grouped assets section in the drawer.

"The tag does not modify, merge, or delete cloud resources." When grouped members disagree on owner or classification the row is flagged as Partial Assignment or Mixed Assignment until you set the value on the group. A setup note about the tag also appears when you connect AWS, Azure, or Google Cloud.

Statuses and fields

SourceHow it arrivesWhat is different
DiscoveredCreated and refreshed by a data source syncCarries an External ID and provider metadata; provider fields update on each sync
ManualAdd AssetsEverything is yours to maintain
InsightMeaning
Assigned / UnassignedAssets with and without an owner
Profile completeAssets whose classification fields are all set
ClassificationValues
Confidentiality, Integrity, AvailabilityUnclassified, then the levels your organization uses
RetentionFree text, such as "7 years"
Encrypted (rest), Encrypted (transit)Yes or no

Tips and gotchas

Assign owners in bulk right after the first sync: filter by Unassigned, Select all, Edit, set Owner, Apply changes. The dashboard's 4. Assets step completes on owners alone.

Deleting a discovered asset does not stop the sync from recreating it on the next run. Group it or set it to the right type instead; delete only manual assets and assets whose source is disconnected.

The grouping banner can be dismissed and stays dismissed in this browser only. The dialog is always reachable from the page's getting-started guide, which highlights Automatic asset grouping.

What Noru does not do

Noru discovers what the connected accounts expose; it does not scan your network or find systems no data source knows about. It does not choose classifications or owners for you, and the grouping tag never changes, merges, or deletes anything in the cloud provider.

Last updated on