Skip to content

Data Ops

Database configuration auditing, backup compliance, data residency checks, and DB access controls. Currently in Beta.

Beta

Data Ops skills are in Beta. Expected GA: Q3 2026.


What it covers

SkillWhat it detectsOutput
RDS configuration auditEncryption at rest/in transit, public accessibility, deletion protectionFinding
Backup complianceRDS automated backups disabled, backup retention < required daysFinding
Data residencyResources storing data outside approved regionsFinding
DB access controlsRDS security groups, parameter groups, IAM database authReport
Multi-AZ complianceProduction RDS without Multi-AZ enabledFinding

Example prompts

Which RDS instances don't have encryption at rest enabled?

Are any of my databases publicly accessible?

Which production RDS instances lack Multi-AZ?

Show me all databases with backup retention under 7 days

Are any databases storing data outside approved regions?

Required permissions

json
"rds:DescribeDBInstances",
"rds:DescribeDBClusters",
"rds:DescribeDBSnapshots",
"rds:ListTagsForResource",
"rds:DescribeDBParameterGroups",
"rds:DescribeDBSubnetGroups"

Next steps

  • Compliance Ops — Data residency and encryption feed GDPR and HIPAA controls
  • SecOps — Network-level database exposure

Escher — Agentic CloudOps by Tessell