PLATFORM ASSURANCE
See every change, and the risk it carries
Theom watches the configuration of your data platform, not just the data in it, so a risky change to access, integrations, or provisioning is something you see and can act on.
The bridge between security, governance, and platform operations
Most of what goes wrong in a data platform is a change nobody reviewed: a new integration, a widened grant, a network policy edited, a token issued. Theom watches those changes from inside the platform, ties each to the identity that made it, and flags the ones that introduce risk, so platform, security, and governance teams work from the same record instead of three partial ones.
See how it worksConfiguration, not just content
Access and privilege changes
Grants, roles, group membership, and administrative privileges — how permissions change across users, service identities, and roles.
Integrations and external access
Storage and external-access integrations, external stages, and the creation, alteration, and deletion of stages, with the users and roles responsible.
Network and provisioning
Changes to network policies, provisioning tokens, and API endpoints within the approved metadata scope.
Tasks, functions, and procedures
Changes to the tasks, functions, and stored procedures running inside the platform.
Insecure clients and deprecated runtimes
Clients and runtimes that no longer meet a safe baseline, surfaced before they become the way in.
Every change tied to an identity
Account fingerprinting analyzes activity by user and service identity to establish typical behavior and surface material deviations.
Data resilience
Customer-managed keys, versioning, delete protection, and retention, watched alongside the rest of the configuration so the recoverability settings do not quietly drift.
Retire what should not be there
The same view surfaces the debt that accumulates in a platform over time, which is the concrete work behind medallion migration, technical-debt reduction, and platform consolidation.
Dark data, shadow copies, and clones
Objects sitting in public or default schemas
Overprovisioned users, roles, and datastores
Dormant privileges and dormant accounts
Common questions
How is platform assurance different from data security?
Data security watches who reaches your data and what they do with it. Platform assurance watches the configuration around it — integrations, network policies, provisioning, privileges, tasks — and answers what changed, who changed it, and whether the change introduced risk. Together they cover both the data and the platform it lives in.
Does Theom tie a change back to who made it?
Yes. Theom analyzes activity by user and service identity to establish typical behavior and surface material deviations, so a configuration change carries the identity that made it, not just a timestamp.
Can this help us clean up before a migration?
Yes. Theom surfaces dark data, shadow copies and clones, objects in public or default schemas, overprovisioned roles, and dormant privileges and accounts — the concrete cleanup that supports medallion migration, technical-debt reduction, and platform consolidation.
See what changed in your platform this week
We will show you configuration and privilege changes on your own environment, tied to who made them.
Book a Demo