Begin with observations from several sources
This reference design combines inventory records, endpoint observations, and permitted external exposure feeds for an analyst. Sources differ in what they can see and how often they update. The application presents evidence and qualified relationships; it does not declare an asset owned, vulnerable, or compromised merely because a scan found it.
Assume tenant-scoped access, changing infrastructure, and source-specific identifiers. Record which source supports each fact. A successful import establishes receipt of that source's report, not its completeness or correctness.
Keep the observation and its time
Preserve the source record identifier, observed time or interval, collection time, and import time. A service banner observed last week describes that observation; it does not establish the service's current state. Keep the source's confidence separately from confidence assigned by local matching rules.
Retain permitted evidence references and contradictory observations. STIX observed-data records provide a useful distinction between observed content and the assertions built from it. Repeated reports copied from one original feed should not count as independent corroboration.
Resolve identity within a time interval
Match using scoped source identifiers and dated relationships. Keep an asset instance distinct from the address, hostname, or account associated with it. Addresses can be shared or reassigned; a replacement machine can inherit a familiar name.
NIST's asset-identification model separates identifier representation from the matching logic that consumes it. This design records the matching rule, evidence, and effective interval. Ambiguous candidates remain separate. Corrections create a new mapping version and preserve the earlier interpretation so historical investigations can be reconstructed.
Explain every relationship in the graph
A graph edge needs a type, direction, time range, and supporting source. “Reported as assigned to” differs from “observed communicating with” or “possibly related through a shared certificate.” Mark inferred relationships and the rule that produced them.
Shared hosting or a discovery link does not establish common ownership. Public external inventory documentation distinguishes confirmed inventory, dependencies, and candidates requiring review. Keep comparable distinctions here. A chain of individually plausible links is not automatically a verified ownership or attack path.
Give analysts a bounded pivot
The interface starts from an asset and interval, then shows permitted observations, relationship evidence, conflicts, and missing coverage. Apply authorization before returning nodes, edges, counts, or exports. Limit graph depth, time range, result size, and execution time; offer an explicit next pivot instead of expanding everything.
Attach the selected evidence and mapping versions to a case. Ownership confirmation, vulnerability validation, and incident conclusions need their own evidence. Following a relationship in the interface grants no authority to scan, change, or contain its target.
Treat disappearance as something to explain
A missing observation can mean retirement, permission loss, an expired feed, or a collection gap. Track source coverage and last observation separately from an asset's confirmed lifecycle state. End outdated relationships without erasing evidence needed for earlier intervals.
Monitor stale sources, unresolved matches, disputed links, and review backlog. A graph adds identity maintenance and careful access control. When the question is simple, a source-linked inventory table may be easier to use and validate.