Cloudaware Glossary
This page lists core Cloudaware terms across modules in one place.
CMDB
CMDB is the core Cloudaware module that discovers, stores, and relates objects from multi‑cloud (AWS, Microsoft Azure, Google Cloud), virtualized (VMware vCenter) and hybrid infrastructure, along with other sources. Cloudaware CMDB stores configuration items (CIs), their relationships, and metadata that other modules use for compliance, cost, monitoring, and automation.
- Application Tier — A subdivision within a Cloudaware Application (e.g., Prod, Staging) to segment inventory and permissions. See Cloudaware Virtual Applications.
- Auto‑Attachment Rule — Criteria that continuously attaches matching resources to an Application, reducing manual upkeep. See Cloudaware Virtual Applications.
- Browse Objects — Query-builder view in Cloudaware CMDB for exploring object data, refining filters, previewing results, and saving reusable query scopes. See Browse Objects.
- Calculated Attribute — A derived field whose value is computed from other data (such as tags, names, relationships, or metrics), often implemented as a formula or rollup field. See Calculated Attributes.
- Cascades — Automatic attachment of related objects when a parent is attached to an Application (e.g., attach instance → also attach its volumes/NICs). See Cloudaware Virtual Applications.
- Change Event — Any modification to a CI attribute recorded in CMDB with history for audit and workflows. See Change Events.
- Change Tracking — CMDB capabilities that record configuration changes over time, including events, history, and notifications for CIs and their relationships. See Change Tracking.
- CI Detail Page — Record page for a configuration item that shows identity, source attributes, related CIs, summary tiles, tabs, actions, and module-specific context. See CI Detail Page Layout.
- Cloudaware Admin Console — Where administrators configure integrations, TunHub, Breeze downloads, and platform settings.
- Cloudaware Virtual Application — A logical grouping that organizes resources by business logic (team, environment, customer, project) across clouds.
- CMDB Navigator — The console’s search and browsing experience for finding objects, running list views, and accessing the CMDB and custom objects.
- CMDB Search — Global search experience for finding CIs, object records, and relevant CMDB data by name, identifier, or other searchable fields. See CMDB Search.
- Collection Schedule — Provider- or integration-specific refresh cadence that determines how often Cloudaware discovers and updates CMDB records. See CMDB Ingestion.
- Configuration Item (CI) — Any record in CMDB that represents an asset or logical entity (e.g., EC2 Instance, Azure VM, S3 Bucket, Policy Violation), application, service, or other managed object. See CMDB Objects.
- Coverage — The degree to which CIs are monitored, backed up, scanned, or otherwise included in required controls.
- Coverage Gap — A resource missing one or more required controls (for example, not monitored, not backed up, or not in vulnerability scanning).
- Custom Object — A CMDB object created or extended for a customer’s environment (for example, Application, Business Unit, or Service) and linked to discovered CIs to model business context. See Custom Objects.
- Data Model — The set of CMDB objects, attributes, and relationships that represent your estate in a normalized, provider‑agnostic way. See Data Model.
- Enrichment Rule — Logic that evaluates CIs as they are ingested or updated and sets fields, links objects, or flags conditions to standardize metadata and attach business context. See Enrichment Rules.
- Field History — A per‑object history of attribute changes shown on the Change Management tab. See History & Audit.
- History & Audit — Views and records that show who changed what and when for a CI, including previous values for tracked fields. Used for troubleshooting, approvals, and compliance evidence. See History & Audit.
- Ingestion — The process that discovers, imports, and continuously refreshes CMDB data from cloud provider APIs, billing exports, Cloudaware-managed agents (Breeze), and third‑party integrations on a defined schedule. See CMDB Ingestion.
- Integration — A specific connector or data source (for example, cloud provider, billing source, monitoring platform, ticketing system, or security scanner) that feeds data into CMDB.
- List View — A saved filter over a CMDB object type (e.g., Running Instances) used for quick navigation and bulk actions.
- Normalization Rule — A rule that harmonizes provider‑specific fields, units, and identifiers into CMDB’s standardized data model and resolves conflicts when multiple sources report different values for the same attribute. See Normalization Rules.
- Related CIs — Tab or relationship view that shows upstream, downstream, containment, dependency, or connectivity links for the current CI. See CI Layout Tabs.
- Relationship — A link between two CIs that represents containment, dependency, or connectivity (for example, instance ↔ volume, load balancer ↔ target group, application ↔ database, account ↔ regional resource). See Relationships.
- Scope — A set of CIs selected by filters (for example, provider, account/subscription/project, region, tags, ownership, environment, or business unit). Scopes are used for queries, dashboards, policies, and playbooks.
- Summary KPI Tile — Compact status card on a CI detail page that surfaces operational signals such as cost, backups, scans, IDS, Breeze, application association, or monitoring state. See Summary KPI Tiles.
- Tag Analyzer — Cloudaware CMDB operations tool that inspects tags/labels across providers, highlights gaps, and supports tagging governance.
Cost Management & FinOps
Cost Management (FinOps) is the Cloudaware module that provides cross‑cloud cost visibility, allocation, optimization, and showback/chargeback workflows.
- Allocation/Business Mapping — The process of mapping raw cloud spend to business dimensions (teams, apps, BUs, customers) using tags, accounts, projects, and mapping rules. See Business Mapping.
- Amortization — Process of spreading upfront or recurring commitment costs across the usage periods that benefit from them. See Commitments & Reservations.
- Anomaly — A detected deviation from expected spend or usage patterns for a given scope and timeframe, warranting investigation. See Anomaly Detection.
- Billing Cycle — Time period used for cost reporting, budget tracking, invoicing, showback, or chargeback. See Billing Cycles.
- Billing Export — Provider-generated billing dataset, such as AWS CUR, Azure billing exports, or Google Cloud Billing Export, ingested by Cloudaware Cost Management. See Cloud Billing Sources.
- Billing Line Item — Granular cost and usage record from a provider billing export, usually tied to a service, account, resource, region, usage type, and time period. See Billing Upload Schema.
- Blended Rate — Average cost rate across an organization/account; often used in consolidated billing views.
- Budget — Planned spend for a given scope and period, with thresholds used for alerts and variance analysis. See Budgets.
- Budget Alert — Threshold‑based notifications on spend against budgets, emailed or routed to collaboration tools. See Budget Alerts.
- Chargeback — Allocation of cloud costs by organization, application, or service line for internal or external billing, typically resulting in accounting entries or recharges. See Showback & Chargeback.
- Commitments & Reservations — Long‑term or usage‑based discount programs (RIs, Savings Plans, Azure Reservations, GCP CUDs) that trade flexibility for lower prices. See Commitments & Reservations.
- Commitment Coverage — Share of eligible usage covered by commitments such as Reserved Instances, Savings Plans, Azure Reservations, or GCP CUDs. See Commitments & Reservations.
- Commitment Utilization — Percentage of purchased commitment capacity that is actually consumed by eligible usage. See Commitments & Reservations.
- Cost Baseline — A reference period and set of KPIs used as the starting point for measuring trends, setting budgets, and evaluating optimization impact. See Cost Baseline.
- Cost Driver — Resource, service, account, application, team, or usage pattern responsible for a meaningful portion of spend or a cost change.
- Effective Cost — Cost that includes amortized commitments and discounts (for example, RIs, Savings Plans, CUDs), intended to represent the true economic cost of usage.
- Forecast — Projected spend based on historical data and known changes, used to anticipate whether budgets will be met or exceeded. See Forecasting.
- Rate Type — Cost calculation basis used in reports or exports, such as blended, unblended, on-demand, or effective cost. See Metrics & KPIs.
- Reserved Instance (RI) — Prepaid capacity commitment (e.g., EC2, RDS) tracked for coverage and utilization.
- Rightsizing — Adjusting resource size or configuration based on utilization to reduce cost while maintaining performance. See Rightsizing.
- Savings Plan (SP) — Flexible commit discount tracked similarly to RIs for utilization and coverage.
- Scope — A slice of cost data defined by filters such as provider, account/subscription/project, BU, application, environment, or customer. Used for budgets, dashboards, anomalies, and showback/chargeback.
- Shared Costs — Costs associated with shared/platform services (networking, security, shared clusters, support) that are allocated using special rules or kept in central buckets. See Shared Costs.
- Showback — Reporting cloud costs back to teams or business units for awareness and accountability, without necessarily transferring budget or issuing internal invoices. See Showback & Chargeback.
- Unblended Rate — The list cost rate applied to a specific usage line item without averaging.
- Unit Cost — Cost expressed per business driver (for example, per user, per customer, per transaction, per request), usually calculated by combining cost data with usage or revenue metrics. See KPIs.
- Waste Detection — Identifying idle or unused resources (such as unattached volumes, orphaned IPs) and estimating potential savings. See Waste Reduction.
Compliance
Compliance Engine (v1) is the Cloudaware’s module for policy‑driven, CMDB‑backed compliance evaluation and evidence generation. Compliance Engine evaluates resources using CMDB data and creates output objects for findings, with exception handling and ticketing integrations.
- Audit Evidence — Structured findings, timestamps, reports, and exports used to demonstrate control status during audits or customer reviews. See Audit Preparation.
- Benchmark Check — Compliance Engine output object that records the result of evaluating an asset against a benchmark control. See Finding/Output Schema.
Compliant/Incompliant/Inapplicable— Core statuses indicating whether an asset meets, violates, or is outside the scope of a control. See State Model.- Compliance Engine Policy — A ruleset implemented in Compliance Engine that defines scope, evaluation logic, and lifecycle for creating or closing findings. See Policies.
- Evaluation — A job that runs one or more policies against in-scope assets. See Evaluation & States.
- Exception — A recorded acceptance of risk where a violation is tolerated for a period of time under defined conditions. See Exceptions.
- MTTR (Mean Time To Remediate) — Average time for violations to move from incompliant to compliant. See State Model.
- Output Object/Finding — A persistent record of a policy's result for a given asset (for example, CloudAware Policy Violation, CloudAware Benchmark Check). See Findings & Output.
- Policy Deployment — Process of moving policy code, metadata, and packs into an environment where they can run against CMDB assets. See Deployment & Promotion.
- Policy Pack — A curated set of related policies (for example, a CIS benchmark pack). See Policy Packs.
- Policy Revision — Versioned change to policy logic or metadata, used to compare, audit, and manage policy updates over time. See Revisions & Diffs.
- Policy Scope — CMDB object type and filter/query logic that determines which assets a policy evaluates. See Scoping & Targeting.
- Policy Violation — An output object indicating noncompliance for a specific CI; reportable, dashboardable, and integrated with alerting/ticketing. See Finding/Output Schema.
- Standards — Prebuilt policy packs aligned to CIS, NIST, PCI DSS, HIPAA, ISO, GDPR, and other frameworks. See CIS Benchmark Packs.
- Utility Class — Reusable helper code used by multiple policies in Compliance Engine v1. See Utility Classes.
- Violation Age — Amount of time a finding has remained incompliant, used for prioritization, SLA tracking, and reporting. See State Model.
Security
- Certificate Authority (CA) — A trusted entity that issues and signs X.509 certificates used to establish TLS trust. Cloudaware components (including Breeze and TunHub) can use custom CA bundles when required.
- Field-Level Security — Salesforce security control that determines which fields a user can view or edit on Cloudaware objects. See Permission Sets.
- Identity Provider (IdP) — External identity system, such as Microsoft Entra ID or Okta, that authenticates users and supplies claims or groups for Cloudaware access mapping. See SSO & MFA Patterns.
- Least Privilege — Access principle where users, integrations, and service accounts receive only the permissions and data visibility required for their role. See Least-Privilege Patterns.
- Mutual Authentication — Certificate-based trust model where both client and server validate each other before exchanging data; used by Breeze Agent communication. See Breeze Agent Security.
- Permission Set — Additive Salesforce access bundle used to grant Cloudaware module or task privileges without changing a user's baseline profile. See Permission Sets.
- Profile — Salesforce user configuration that defines baseline object, field, app, tab, and login access for a Cloudaware user. See Profiles.
- Role‑Based Access Control (RBAC) — Access model that uses Salesforce profiles, permission sets, and scopes to control who can view or change data and configuration.
- SAML — Federation protocol commonly used for enterprise SSO between an identity provider and Cloudaware/Salesforce. See SSO Configuration.
- SIEM (Security Information and Event Management) — External platform, such as Splunk or Sumo Logic, that collects, searches, correlates, and analyzes security events enriched with Cloudaware context.
- SOAR (Security Orchestration, Automation, and Response) — External platform or workflow layer that automates security response actions, ticketing, enrichment, and remediation steps using Cloudaware data. See SIEM/SOAR integrations.
- SSO (Single Sign-On) — Authentication pattern that lets users access Cloudaware through a central identity provider instead of separate local credentials. See SSO & MFA Patterns.
Vulnerability Management
Vulnerability Management is the Cloudaware module for agent-based, network, URL, and compliance vulnerability scanning, with findings stored in CMDB for reporting, prioritization, exceptions, SLA tracking, and remediation workflows.
- Cloudaware Vulnerability Scan — Canonical record representing a vulnerability instance in Cloudaware, with record types used to distinguish sources (Qualys, Rapid7, Tenable, cloud-native, Snyk, etc.). See Finding Schema.
- Cloudaware Vulnerability Scan CVE — Related object used in some integrations to represent CVEs associated with scan records. See Cloudaware Vulnerability Scanning.
- Cloud-Native Scanner — Provider security service, such as AWS Inspector or GCP Security Command Center, whose findings are ingested and normalized into Cloudaware. See Cloud-Native Sources.
- CVE — Common Vulnerabilities and Exposures identifier associated with discovered vulnerabilities and used in reporting. See Finding Schema.
- CVSS — Common Vulnerability Scoring System score used by scanners and vendors to describe technical severity. See Severity & Scoring.
- Initiative — A high-level, often multi-team program of work to reduce vulnerability risk (e.g., OS upgrades, reducing High vulnerabilities by 50%).
- Is Suppressed — A flag on Vulnerability Scan records indicating that an active exception exists and the finding is suppressed for SLA purposes. See Exceptions.
- Last Scan Date — Timestamp showing when an asset or finding was last evaluated by a vulnerability source, used to identify stale coverage. See Vulnerability Management Overview.
- MTTR (Mean Time to Remediate) — Average time between vulnerability detection and verified remediation. See SLA Tracking.
- Organization Unit (OU) — Organizational grouping (e.g., department, business unit, platform team) used for ownership and reporting. See Ownership & Routing.
- Remediation Task — A concrete unit of work associated with one or more vulnerabilities and owners; may be synchronized with ITSM tickets.
- Risk Band — Aggregated risk category (e.g., CRITICAL, HIGH, MEDIUM, LOW) derived from severity, exploitability, and business impact. See Risk Models.
- Scan Coverage — Extent to which assets, containers, URLs, or cloud resources are included in vulnerability scanning. See Dashboards & Reporting.
- Vulnerability Age — Custom formula field that calculates the age of a vulnerability in days. See SLA Tracking.
- Vulnerability Exception — A record documenting risk acceptance for specific vulnerabilities, including justification and expiry.
- Vulnerability Scanning as a Service (VSaaS) — Cloudaware’s managed vulnerability scanning service, providing agent-based, network, URL, and compliance scans, as a part of Vulnerability Management. See Cloudaware Vulnerability Scanning.
Patch Management
Patch Management is the Cloudaware module for continuous patch visibility and deployment, including release notes, patch groups, maintenance windows, rollback, and emergency releases.
- Baseline — A defined set of patches and versions to be applied to a group of systems.
- Blackout Window — A period during which patching is not allowed, except possibly under emergency procedures.
- Canary Wave — A small initial batch of low-risk hosts used to validate a patch release before rolling it out more broadly.
cloudaware:PatchingMaintenance = CustomReboot— Tag value indicating that reboots should follow a custom order based oncloudaware:PatchGroup, with groups rebooted sequentially.cloudaware:PatchingMaintenance = NoReboot— Tag value indicating that Cloudaware should apply patches but not reboot the instance; the owner is responsible for performing the reboot manually.cloudaware:PatchingMaintenance = UpToDate— Tag value typically used for ad-hoc patching to mark instances that have been brought up to date outside the normal schedule and should be temporarily skipped by scheduled patch jobs until the value is removed.- Emergency Release — A patch release created outside the normal schedule to address a critical vulnerability or issue.
- Emergency Security Release — An out-of-band patch release for critical vulnerabilities.
- Eligible Host — Host that meets patching requirements, such as supported OS, active Breeze Agent, reachable package sources, and required permissions. See Patch Management Requirements.
- Exception — A documented decision to deviate from standard patch SLAs for a specific system or vulnerability.
- Exception Debt — The accumulated risk represented by open exceptions that defer or exclude patches; often tracked via compliance reporting to ensure exceptions are reviewed and closed.
- Job Orchestration — Coordination of patch execution across scopes, waves, schedules, retries, reboot behavior, and verification steps. See Job Orchestration.
- Maintenance Window — An allowed time period for performing patching and other changes.
- Patch Coverage — Percentage of eligible hosts tracked by Patch Management and included in baselines, jobs, dashboards, or reports. See Coverage Reporting.
- Patch Group — A logical grouping of hosts patched together to control rollout order, concurrency, and reboot behavior.
- Patch Job — Execution unit that applies a patch snapshot or baseline to a scoped set of hosts during an allowed schedule. See Job Orchestration.
- Patch Snapshot — A concrete instance of a baseline for a particular release or cycle.
- Premium Patch Management — Cloudaware’s patch deployment service, where Cloudaware orchestrates patch jobs, reboots, and rollbacks in addition to discovery and reporting.
- Reboot Policy — Rules that define whether and how hosts reboot after patching, including no-reboot, custom order, or default reboot behavior. See Reboot Policy.
- Repo Day — The day when update snapshots are captured for supported operating systems; those snapshots are then reused throughout the patch cycle so that the same set of patches is applied across environments.
- Rollback Scope — The level at which a rollback is applied (for example, a single host, a patch wave, or an entire patch release).
- Rollback Script — Script placed on each patched host to revert a specific release (
/opt/breeze-agent/os_updater/<timestamp>.sh). - Standard Patch Management — Cloudaware’s discovery-only mode that focuses on patch visibility, eligibility, and reporting without Cloudaware-run patch deployment.
- Wave/Batch — A group of hosts patched as part of the same step in a job; waves are used to control concurrency and risk.
Log Management
Log Management is the Cloudaware module for collecting, searching, and analyzing logs from discovered sources, using CMDB context for graph analysis, anomaly detection, and troubleshooting.
- Conflux — Cloudaware's log management service app for collecting, searching, and analyzing logs with CMDB-enriched context.
- Conflux Index — Searchable storage partition for logs from a specific source type, provider, account, or dataset, such as AWS CloudTrail or VPC Flow Logs. See Log Management Requirements.
- Field Filter — Query constraint applied to a structured log field, such as account, region, source IP, event name, status code, or resource ID. See Dashboards & Reporting.
- Graph API — Relationship analysis over CMDB and log data used for impact analysis and dependency mapping.
- Hot Data — Recent log data retained in searchable storage for fast investigation, dashboards, and alerting. See Log Management Overview.
- Log Source — Cloud provider, host, SaaS, identity, network, security, or custom system that produces logs ingested by Conflux. See Log Sources.
- Raw Event — Individual unaggregated log record available for search and investigation in Conflux.
- Saved Search — Reusable Conflux query or filtered view used for recurring investigations, dashboards, reports, or evidence exports. See Dashboards & Reporting.
Intrusion Detection
Intrusion Detection (IDS) is the Cloudaware module for host-based security monitoring, using Wazuh and Breeze Agent data to detect suspicious activity, policy violations, and security events across managed infrastructure.
- File Integrity Monitoring (FIM) — Wazuh capability that detects changes to critical files, directories, and registry paths for investigation and compliance evidence. See File Integrity Monitoring Dashboard.
- IDS Finding — Cloudaware-normalized security finding created from Wazuh alerts and linked to CMDB configuration items for reporting and investigation. See Findings & Rules.
- IDS Status — CMDB status indicator that summarizes Intrusion Detection coverage or risk for a CI, such as
Not monitored,Monitored, orUnder attack. See Sources & Agents. - Watcher — Wazuh alerting mechanism that periodically evaluates a saved search or query and triggers actions when matching events exceed configured conditions. See Wazuh Alerts & Watchers.
- Wazuh — Open-source security monitoring platform used by Cloudaware Intrusion Detection to collect and analyze host security events, file integrity changes, vulnerability signals, and compliance-related telemetry. See Intrusion Detection Architecture.
- Wazuh Agent — Lightweight endpoint component installed on servers or nodes to collect logs, file integrity changes, configuration data, and other host-based security telemetry. See Sources & Agents.
- Wazuh Dashboard — Web interface used to inspect Wazuh alerts, dashboards, saved searches, agent health, and threat-hunting views. See Navigation in Wazuh.
- Wazuh Indexer — Wazuh component that stores and indexes alerts and events so they can be searched, filtered, and visualized. See Intrusion Detection Architecture.
- Wazuh Rule — Detection rule that matches incoming events and assigns severity, category, and context used to generate alerts or IDS findings. See Findings & Rules.
- Wazuh Server (Manager) — Central Wazuh component that receives agent telemetry, decodes events, applies rules, generates alerts, and manages agent configuration. See Intrusion Detection Architecture.
Unified Monitoring
Unified Monitoring is the Cloudaware module that consolidates metrics, events, and incidents from connected tools, enriches them with CMDB context, and supports alerting, coverage analysis, and operational troubleshooting.
- Alert — A notification created when a policy's conditions are met; alerts can route to email, Slack, PagerDuty, Jira, or other destinations.
- Alert Noise — High volume of low-value, duplicate, or non-actionable alerts that can distract responders and weaken incident response. See Reduce Alert Noise.
- Anomaly Detection — Statistical detection across single or multiple metrics, including population-based anomalies (e.g., outlier instance behavior).
- Cardinality — Number of distinct combinations of label values. Cardinality is an important factor in monitoring scale and performance.
- Channel — Concrete destination for alerts, such as email, Slack, PagerDuty, or a webhook.
- Condition — The logic inside an alert policy that determines when a metric, event, baseline, or missing-data signal should create an alert. See Policies & Conditions.
- Data Health — Freshness, completeness, and consistency of metrics and events received by Unified Monitoring.
- Event — Discrete occurrence in time, such as an alert firing, configuration change, incident, deployment, or security finding.
- Golden Signals — Latency, traffic, errors, and saturation metrics that capture service health.
- Host-Level Telemetry — Metrics and health signals collected from servers or instances, often through Breeze Agent and monitoring collectors such as Zabbix. See Breeze Agent.
- Incident — An operational event (often from tools like PagerDuty) that may be discovered into CMDB and enriched with related CIs and Applications.
- Label/Tag — Key/value pair attached to metrics, events, or resources to provide context, such as
application=paymentsorenvironment=prod. - Maintenance Window — Period during which alerts are suppressed or treated differently due to planned work.
- Metric — Numerical time-series sampled over time, such as CPU utilization, request rate, or error count.
- Monitoring Coverage — Extent to which accounts, regions, and services have monitoring enabled and reporting. Coverage is often visualized through dashboards and CMDB reports.
- Monitoring Exception — Documented, time-bound deviation from standard monitoring coverage or alerting for specific services or scopes, including rationale and compensating controls.
- New Relic — External observability platform for APM, infrastructure, and logs that can be enabled as part of Unified Monitoring. License-based access is provided through Cloudaware Control Hub (Launcher).
- Policy — Rule that evaluates metrics, events, or both and decides when to create alerts.
- Route — Set of rules that determines where alerts are sent.
- Signal Type — The type of data evaluated by an alert policy, such as metrics, events, or a combination of both. See Policies & Conditions.
- Static Threshold — Alert condition that fires when a metric stays above or below a fixed value for a defined period. See Policies & Conditions.
- Time Series — Sequence of metric values recorded over time for a specific resource and label/tag combination. See Metrics.
- Webhook — HTTP-based integration used to send monitoring alerts or events to external systems such as ITSM, SIEM/SOAR, or custom automation tools. See Webhooks.
- Zabbix — Legacy Cloudaware-managed monitoring engine used for agent-based host telemetry within Unified Monitoring.
Backup & Replication
Backup & Replication is the Cloudaware module for backup coverage, cross-region replication, policy tracking, recovery objectives, and alerts across supported cloud services.
- Backup Coverage — Extent to which in-scope assets have a backup policy, recent successful backup, valid retention policy, and required replication policy. See Verify Backup Status.
- Backup Job — Scheduled Cloudaware workflow that interprets backup tags, creates backup media, rotates expired copies, and emits success or failure events. See Backup & Replication.
- Backup Policy — A set of rules that define how often backups run and how long backup media is retained.
- Backup Policy Tag — Standardized tag, such as
gig-backup, that encodes backup frequency and retention intent for an asset. See AWS Backup Tags. - Backup Window — The time period during which backup jobs are allowed to run.
- Blackout Period — The time period during which backup jobs are explicitly blocked or deferred.
- Cloudaware Scheduler Tag Generator — Cloudaware's web-based helper that builds valid
cloudaware:schedulertag values for AWS EC2/RDS Instance Scheduler start and stop schedules. - Cross-Account Replication — Copying backup media to a different cloud account, often for isolation, recovery ownership, or regulatory requirements. See Configure AWS Replication.
- Cross-Region Replication — Copying backup media to another region to support disaster recovery if the source region is unavailable. See Configure AWS Replication.
- Orphan Retention — Policy that defines how long backup media remains after its source asset is terminated or decommissioned. See Backup Retention Policies.
- Orphaned Backup — Backup media whose source asset has been terminated or decommissioned.
- Replication Policy — A set of rules that define how many recent backups are copied to which regions or accounts.
- RPO (Recovery Point Objective) — The maximum acceptable amount of data loss measured in time, for example, no more than 1 hour of data.
- RTO (Recovery Time Objective) — The maximum acceptable time to restore a service after an incident.
- Snapshot/AMI — Native cloud backup artifacts (e.g., EBS snapshot, AMI image) used for recovery or replication.
- Tag-Based Policy — A backup or replication policy expressed through standardized resource tags that encode frequency, retention, and replication rules.
- Tier — A grouping of services by criticality, often used to drive RPO/RTO and policy decisions.
Cloudaware Platform
Cloudaware Platform is the Salesforce-based foundation for Cloudaware navigation, data modeling, packaging, reporting, dashboards, APIs, and administrative access across modules.
- Account — A Cloudaware organization (Salesforce org) and its logical workspaces used to separate environments (for example, production vs. non‑production). See Platform Architecture.
- API Key/Token — Credentials required to authenticate to external APIs; generated by administrators and scoped for use.
- Approval History — Record of approval decisions, reviewers, timestamps, and outcomes used for change governance and audit evidence. See Approvals.
- Change Management — Platform capability for tracking, approving, and auditing planned or detected changes using CMDB context and approval workflows.
- CI Class — The object type definition in CMDB that specifies the schema (fields), relationships, and behavior for a set of CIs (e.g., AWS EC2 Instance, Azure VM). Equivalent to a Salesforce sObject; used by Navigator organization, reports, and policy scoping. Instances of a CI class are the individual CI records.
- Cloudaware Administrator — User responsible for operating and governing Cloudaware, including access management, integrations, CMDB governance, reporting, and platform configuration.
- Cloudaware Client Hub (formerly Launcher) — The entry point for accessing Cloudaware apps such as CMDB, Conflux, Wazuh, and other connected apps (New Relic, PagerDuty, Advanced Analytics dashboards, etc.).
- Cloudaware Collector — A data ingestion job that discovers resources and metadata via provider or product APIs and writes them to CMDB.
- Dashboard — A collection of visual components and KPIs powered by reports for monitoring posture, spend, or operations. See Report & Dashboard Gallery for examples.
- Encrypted Fields — CMDB fields stored with encryption for sensitive values. See Platform Architecture.
- Extension Package — A package named
StackBoard:{cloudName}adding provider-specific objects (e.g., Alibaba, Oracle) not included in core. See Extension Packages. - External API — Cloudaware API endpoints for programmatic access (e.g., listing TunHub tunnels, updating settings).
- Force.com (Salesforce) — The Salesforce platform on which Cloudaware runs as a managed application; provides data model, security, and packaging capabilities. See Force.com & Cloudaware Packages.
- Formula/Roll-Up Fields — Calculated and aggregated CMDB fields used for derived metrics and summaries.
- Integration — A configured connection to a cloud, billing source, or third-party system (e.g., PagerDuty, Qualys, vCenter, etc.). See Integrations.
- Integration Package — A package named
StackBoard:{integrationName}adding integration-specific metadata/objects (e.g., CyberArk, Kubernetes, Terraform). See Integration Packages. - Junction Object — A custom object that implements two master‑detail relationships to model many‑to‑many associations (e.g., Instance ↔ Security Group link).
- Lookup Relationship — A flexible association where a child references a parent via a foreign key; the parent can exist independently.
- Managed Package — A namespaced, versioned application installed in a Salesforce org. Cloudaware delivers core and extension packages (e.g., StackBoard
CA10). See Managed Package Versioning and Delivery. - Managed vs. Custom Objects — Objects shipped in Cloudaware packages are managed by Cloudaware; additional objects created by customers are custom relative to the Cloudaware model (Salesforce still classifies all package objects as custom due to namespace). See Managed vs. Custom Objects in Cloudaware.
- Master‑Detail Relationship — A strong dependency; the child inherits ownership/security and is deleted with the parent. Enables roll‑up summaries on the master.
- Namespace Prefix — A package identifier (e.g.,
CA10__,CA10K__,CA10TF__) added to API names of objects/fields for isolation and versioning. See Naming Conventions & Identification. - Package Versioning — Versioned releases delivered to customer orgs as managed package upgrades. See Managed Package Versioning and Delivery.
- Record Type — A configuration that differentiates business processes, picklists, layouts, or logic within a single object. Often used to vary relationships/fields by source.
- Report — A configurable tabular/summary view across CMDB data, often joining multiple objects; supports scheduling and sharing. See Report & Dashboard Gallery.
- Salesforce sObject — A Salesforce object type (standard or custom) representing a table schema and its records. Cloudaware maps each CMDB CI Class to an underlying sObject, enabling reports, dashboards, workflows, and API access. See Force.com & Cloudaware Packages.
- StackBoard (CA10) — Core Cloudaware managed package providing foundational CMDB schema and components. See Core Package: StackBoard (CA10).
- TunHub — Cloudaware-managed secure proxy for accessing private/on-prem endpoints from Cloudaware (backed by Breeze on a reachable host); provides tunnel routes and alternate addresses for integrations.
Advanced Analytics
Advanced Analytics is Cloudaware's BI analytics capability built on top of Cloudaware CMDB and Salesforce CRM Analytics. It combines events, metrics, and shared dimensions to provide dashboards, KPIs, and self-service analysis across modules.
- Analytics Studio — The CRM Analytics workspace where users browse datasets, build lenses, and design dashboards.
- App/Folder — Containers in CRM Analytics that hold datasets, lenses, and dashboards. Apps and folders control who can view or edit analytics content via Viewer/Editor/Manager permissions and Salesforce sharing.
- Attribute/Dimension — A non-numeric field used to slice and filter analytics, such as tenant, cloud account, application, environment, module, feature, team, or owner. Most attributes are derived from CMDB; see Attributes.
- Cohort, Funnel, Retention Analysis — Techniques for analyzing how groups of users or entities behave over time (cohorts), how they progress through multi-step flows (funnels), and how long they remain active (retention).
- CRM Analytics (Tableau CRM) — Salesforce's analytics platform used by Cloudaware Advanced Analytics to store datasets, run recipes/dataflows, and render lenses and dashboards.
- Dashboard — A visual collection of charts, metrics, filters, and tables built on top of one or more datasets. Dashboards answer a curated set of questions for specific personas; see Dashboards & Reporting.
- Data Health — A view of dataset freshness, completeness, and error conditions for analytics feeds. It combines checks on job status, row counts, null rates, and permission issues; see Data Health.
- Data Manager — The CRM Analytics workspace for configuring connections, monitoring jobs, managing datasets, and reviewing usage (rows, storage, external uploads). It is the primary operational console for Advanced Analytics ingestion.
- Dataflow — A legacy ETL mechanism in CRM Analytics used to build or refresh datasets. Existing customers may still rely on dataflows for some historical workloads; new development should prefer recipes.
- Dataset — A table of data stored in CRM Analytics, composed of fields (attributes and metrics) and rows. Datasets back lenses and dashboards and are created or refreshed by recipes/dataflows; see Data Preparation.
- Event — An atomic record of something that happened at a point in time, such as a user action, module activity, job status change, or configuration update. Events are the lowest-level building blocks of Advanced Analytics; see Events.
- Event-Driven Data Model — A modeling approach in which individual events (for example,
user.login,dashboard.view,policy.evaluate) are captured at high granularity and then aggregated into metrics and KPIs; see Data Model. - Ingestion Pipeline — The end-to-end flow that moves data from Cloudaware modules and integrations into CRM Analytics datasets, typically implemented via Salesforce objects, connections, and recipes/dataflows; see Ingestion and Event Sources.
- KPI (Key Performance Indicator) — A metric or small group of metrics that represent an important business or operational outcome, such as adoption, reliability, coverage, or data quality. Advanced Analytics maintains a KPI catalog; see KPIs.
- Lens — An exploratory view on a single dataset within Analytics Studio. Lenses allow users to pivot, filter, and chart data interactively and can be embedded into dashboards.
- Metric — A pre-aggregated numerical measure derived from events (for example, DAU/WAU/MAU, feature adoption rate, coverage percentage, time-to-detect, time-to-recover). Metrics are optimized for dashboards and external exports; see Metrics.
- Recipe — A visual pipeline in CRM Analytics Data Manager that transforms input data (objects, datasets, external connections) into one or more output datasets using nodes such as Join, Append, Transform, Filter, Aggregate, and Output.
- Segmentation — The practice of slicing analytics by dimensions such as team, application, environment, region, or service tier to compare behavior across cohorts.
Automation
- Google API Explorer — A tool used to test Cloudaware External API requests before automating them in scripts or external systems.
- Approval Process — A workflow that routes qualifying changes for review and decision (Pending, Approved, Rejected states tracked on the CI).
- Breeze Agent — Cloudaware’s lightweight endpoint agent that streams OS-level facts and enables security modules like IDS, Vulnerability Scanning, and Patch Management.
- Client Credentials Flow — An OAuth 2.0 server-to-server authentication flow where an integration uses a client ID and client secret to request API access.
- Event-Driven Automation — Automation triggered by Cloudaware events, such as alerts, resource changes, policy violations, or operational issues.
- External Client App — A Salesforce-based OAuth app used to grant external tools authenticated access to Cloudaware CMDB APIs.
- Flow — A Force.com automation capability for building guided screens and record-triggered processes without custom code. Typically used to trigger actions in external systems, update records, and orchestrate business logic.
- JWT Bearer Flow — An OAuth 2.0 authentication flow where an integration signs a JWT with a certificate to obtain API access without storing a client secret.
- OAuth Scope — A permission assigned to an OAuth app that defines which Cloudaware or Salesforce API actions the integration can perform.
- Running User — The Cloudaware user identity whose permissions are applied when an OAuth client credentials integration makes API requests.
- Workflow — An automated action chain triggered by conditions, such as email, ticket, policy application, or task creation. See Webhooks & Events for event-driven workflow patterns.