If you run a cloud security program, two questions follow almost every security finding: Who owns this? And how important is it? Many security tools answer those questions with static metadata such as owner tags, business criticality labels, and manually maintained inventories of critical assets, known as crown jewels. But cloud environments aren’t static. Teams reorganize, services change hands, and dependencies evolve. The result is stale tags, manual triage, and thousands of findings with little indication of which ones actually matter.
The Datadog Runtime Prioritization Engine (RPE), a component of Datadog Cloud Security, helps you prioritize findings by identifying who should address them and whether they affect your most critical resources. It continuously analyzes the live telemetry data that you send to Datadog, combining runtime context with security signals to reduce alert noise.
In this post, we’ll explore how AI-powered capabilities in RPE automatically infer ownership and discover crown jewels.
Automatically infer ownership
The Runtime Prioritization Engine uses the Ownership Agent to identify the most likely owner for security findings, even when ownership metadata is incomplete or missing. The agent considers explicit ownership signals such as owner tags and ownership preferences when they’re available, and it uses observability and security telemetry data to fill in the gaps when that information is missing.






