Skip to main content

Continuum Cloud

Continuum Cloud

Continuum Cloud reads an AWS account or Azure subscription and draws what it finds onto a Vellum canvas, with each resource's detail attached as a stratum.

It needs a Teams licence and cloud_connections.manage on the organisation or team that owns the connection. Free and Premium have no Continuum surface, and creating a connection below Teams refuses with "Continuum is a Teams-plan feature."

What it produces

One Continuum tab in a blueprint, backed by a private Vellum document named after the tab.

ArtefactWhat it holds
Shapes on a canvasResources the layout draws, nested inside the boundaries in the source: accounts, regions, VPCs and subnets, resource groups
A stratum per resourceIdentity, configuration, per-type tables, tags, related strata, and the raw payload in a collapsed Raw data disclosure
A poll run per scope, per syncWhat was found, what changed, and every read that failed

A stratum is a blueprint file, so it follows the blueprint's own visibility. On a public blueprint, anonymous readers see every discovered resource's account id, resource id, region, addresses and the Raw data payload. Review what a Continuum diagram carries before publishing it publicly.

Resources that describe relationships rather than occupy space, such as route tables, security groups, network ACLs, IAM and KMS, get a stratum with no shape. They are filed under a (Context) folder in the Files sidebar and cross-linked from the resources they affect.

A resource collapsed into a group shape, such as Auto Scaling members or a Lambda name family, also gets a stratum with no shape of its own. Those sit alongside the drawn resources rather than under (Context).

What is discovered

Continuum discovers 77 AWS resource types and 75 Azure resource types. Of those, 53 AWS types and 52 Azure types are drawn as shapes by default. The rest are read for their relationships, for the containers they define, or for stratum context.

A scope narrows by place and by tag, never by service. There is no resource-type picker.

Permissions

Every action on the settings page checks cloud_connections.manage on the owning organisation or team. Built-in owners and admins hold it; anyone else needs it granted through a custom role.

integration.manage is a different permission, for embedding Blueprintr content in SharePoint and Confluence. Holding it opens the settings page but grants nothing in Continuum.

Limits

TeamEnterprise
Cloud connections per owner3Unlimited
Scopes per diagram3Unlimited

Team settings → Plan & limits also shows Resources per integration as 200 on Teams. Nothing enforces that figure today, and a sync is not truncated at 200 resources.

Syncing is manual

Open the tab's settings cog and choose Sync now to re-discover every scope, or Re-sync one scope from Settings….

Scheduled syncing does not work on any plan. The Auto-sync picker offers Off, Every 1h, 4h, 12h and 24h, but choosing any cadence returns "Scheduled polling is not available yet - Continuum runs one-time scans." That is not a plan gate and no upgrade lifts it.

Views on the same canvas

The canvas carries a View switcher. Base topology is the default; the others recolour the same shapes to answer one question each: Routing, Security groups, Cost (est.), IP addresses, Public exposure, Availability zone and Tag coverage. Views authored on the diagram appear in the same list.

Setting one up

Connecting an AWS account covers the role, the verify step and the first scan.

Connecting Azure covers the app registration and the Reader grant.

Scopes and syncing covers what a diagram covers and how to keep it current.

Keeping diagrams true covers what a sync preserves and what the shape outlines mean.