Findings & intelligence

Investigate and resolve security findings

Filter Secorvia findings, inspect evidence, assign owners, record remediation, and distinguish operational resolution from scan verification.

Reviewed

Before you start

At least one scan must have completed. Changing triage state requires the appropriate organization permissions.

Filter the queue

Open All Findings. Search by title, rule, or resource and filter by severity, category, detection state, operational state, or assignee. Start with critical and high severity, then use resource and attack-path context to decide priority.

Read the evidence and remediation

Open a finding. Read Why it matters, Affected resource, Evidence, Compliance impact, and Remediation. Evidence describes discovered configuration at the last scan; verify the resource identity before applying a change.

Assign and document the investigation

Set an Assignee, use Investigating when work begins, and add a comment with ownership, investigation details, or remediation notes. The Activity timeline records supported operational changes, making the hand-off visible to the team.

Separate triage decisions from detection

A team can mark a finding resolved, suppress it, or accept risk. Suppression requires a reason and may have an expiry. Suppression changes triage queues but still contributes to risk and compliance. Marking resolved does not change what the scanner detects.

Verify with a fresh scan

After remediation, trigger a scan for the affected account. Marked resolved, awaiting verification means the latest scan still detects the issue. Verified resolved means a scan confirmed it no longer reproduces. Revisit the evidence if it remains detected.

Where you are now

The finding has an accountable owner and a documented decision, with scan verification kept separate from manual triage.

WHEN SOMETHING LOOKS OFF

A few things to check

No inventory record for the resource

The resource may have been deleted, or the finding may cover an account-level control. The finding itself remains usable.

Suppressed finding still affects the score

This is expected: suppression does not remove the security condition from risk or compliance calculations.

PUT IT INTO PRACTICE

Make your next move in Secorvia.

Open the app and follow along with your own organization.

Open Secorvia