PLATFORM ASSURANCE

See every change, and the risk it carries

Theom watches the configuration of your data platform, not just the data in it, so a risky change to access, integrations, or provisioning is something you see and can act on.

The bridge between security, governance, and platform operations

Most of what goes wrong in a data platform is a change nobody reviewed: a new integration, a widened grant, a network policy edited, a token issued. Theom watches those changes from inside the platform, ties each to the identity that made it, and flags the ones that introduce risk, so platform, security, and governance teams work from the same record instead of three partial ones.

See how it works

Configuration, not just content

Access and privilege changes

Grants, roles, group membership, and administrative privileges — how permissions change across users, service identities, and roles.

Integrations and external access

Storage and external-access integrations, external stages, and the creation, alteration, and deletion of stages, with the users and roles responsible.

Network and provisioning

Changes to network policies, provisioning tokens, and API endpoints within the approved metadata scope.

Tasks, functions, and procedures

Changes to the tasks, functions, and stored procedures running inside the platform.

Insecure clients and deprecated runtimes

Clients and runtimes that no longer meet a safe baseline, surfaced before they become the way in.

Every change tied to an identity

Account fingerprinting analyzes activity by user and service identity to establish typical behavior and surface material deviations.

Data resilience

Customer-managed keys, versioning, delete protection, and retention, watched alongside the rest of the configuration so the recoverability settings do not quietly drift.

Retire what should not be there

The same view surfaces the debt that accumulates in a platform over time, which is the concrete work behind medallion migration, technical-debt reduction, and platform consolidation.

  • Dark data, shadow copies, and clones

  • Objects sitting in public or default schemas

  • Overprovisioned users, roles, and datastores

  • Dormant privileges and dormant accounts

Common questions

How is platform assurance different from data security?

Data security watches who reaches your data and what they do with it. Platform assurance watches the configuration around it — integrations, network policies, provisioning, privileges, tasks — and answers what changed, who changed it, and whether the change introduced risk. Together they cover both the data and the platform it lives in.

Does Theom tie a change back to who made it?

Yes. Theom analyzes activity by user and service identity to establish typical behavior and surface material deviations, so a configuration change carries the identity that made it, not just a timestamp.

Can this help us clean up before a migration?

Yes. Theom surfaces dark data, shadow copies and clones, objects in public or default schemas, overprovisioned roles, and dormant privileges and accounts — the concrete cleanup that supports medallion migration, technical-debt reduction, and platform consolidation.

See what changed in your platform this week

We will show you configuration and privilege changes on your own environment, tied to who made them.

Book a Demo