Get Started with Datadog

The Monitor

Prioritize security findings with the Datadog Runtime Prioritization Engine

Published

Read time

4m

Prioritize security findings with the Datadog Runtime Prioritization Engine
Christina DePinto

Christina DePinto

Senior Product Marketing Manager

Lucas Maley

Lucas Maley

Product Manager

Leo Wang

Leo Wang

Product Manager

If you run a cloud security program, two questions follow almost every security finding: Who owns this? And how important is it? Many security tools answer those questions with static metadata such as owner tags, business criticality labels, and manually maintained inventories of critical assets, known as crown jewels. But cloud environments aren’t static. Teams reorganize, services change hands, and dependencies evolve. The result is stale tags, manual triage, and thousands of findings with little indication of which ones actually matter.

The Datadog Runtime Prioritization Engine (RPE), a component of Datadog Cloud Security, helps you prioritize findings by identifying who should address them and whether they affect your most critical resources. It continuously analyzes the live telemetry data that you send to Datadog, combining runtime context with security signals to reduce alert noise.

In this post, we’ll explore how AI-powered capabilities in RPE automatically infer ownership and discover crown jewels.

Automatically infer ownership

The Runtime Prioritization Engine uses the Ownership Agent to identify the most likely owner for security findings, even when ownership metadata is incomplete or missing. The agent considers explicit ownership signals such as owner tags and ownership preferences when they’re available, and it uses observability and security telemetry data to fill in the gaps when that information is missing.

To infer ownership, the agent evaluates the following signals and combines them in a ranked evidence model:

  • Owner tags and ownership preferences

  • Ownership metadata as defined in the Datadog Catalog 

  • Cloud audit logs that identify who created or modified a resource

  • Container and host metadata

  • Naming conventions and organizational patterns

  • Source control integrations, including CODEOWNERS files

  • The affected resource and security finding

By combining these signals, RPE identifies the most likely owner and enriches that information with on-call schedules, team hierarchies, dashboards, ticketing and team member information, team messaging channels, and team-owned repositories. This context enables security teams to route findings and coordinate remediation by using their existing collaboration tools and engineering workflows.

Ownership information appears directly in the Cloud Security side panel for vulnerabilities and misconfigurations. You can review, confirm, or override suggested owners, helping the Ownership Agent continuously learn. You can also define ownership preferences to map tags, exclude specific teams from being assigned ownership, and provide custom guidance directly to the agent.

A finding in Datadog Cloud Security that identifies the Shopist Web team as the owner and specifies that the container image is a crown jewel.
A finding in Datadog Cloud Security that identifies the Shopist Web team as the owner and specifies that the container image is a crown jewel.

Automatically identify critical resources

Knowing who owns a finding is only half the equation. Security teams also need to understand what is actually worth protecting. Organizations typically maintain some version of a crown jewels inventory—a list of the applications, databases, and cloud resources whose compromise would have the greatest business impact. These inventories are often manually maintained and quickly become outdated as cloud environments evolve.

With Datadog Crown Jewels, the Runtime Prioritization Engine uses observability data to build your inventory of critical resources automatically. Rather than relying on static classifications, RPE continuously analyzes runtime telemetry data to identify the services, databases, and cloud storage resources that matter most to your business. These assets typically handle sensitive data, process critical workloads, or occupy central positions in your production architecture.

RPE identifies crown jewels by using signals such as:

  • Sensitive data detected in Datadog APM spans, application logs, cloud storage, and API traffic

  • Database schemas that contain sensitive fields

  • Service dependency fan-in and architectural centrality from APM

An inventory of crown jewels with a visual representation of crown jewel distribution by detection source and resource type.
An inventory of crown jewels with a visual representation of crown jewel distribution by detection source and resource type.

Because RPE analyzes live observability data, the inventory of crown jewels continuously evolves. As services are deployed, workloads change, or instrumentation expands, RPE automatically updates the inventory to reflect which resources are critical.

Security teams remain in control with the ability to validate and refine the generated inventory. They can remove resources from the list and manually add assets that RPE didn’t include automatically.

Start prioritizing findings with the Runtime Prioritization Engine

The Datadog Runtime Prioritization Engine, generally available, analyzes security findings to help you prioritize the issues that require remediation. By combining observability data with AI-powered ownership inference and Crown Jewels detection, RPE reduces alert noise and helps your teams focus on business-critical risks. To learn more, read the Runtime Prioritization Engine documentation.

If you’re new to Datadog, you can to get started.

Start monitoring your metrics in minutes