Findings & intelligence
Investigate and resolve security findings
Filter Secorvia findings, inspect evidence, assign owners, record remediation, and distinguish operational resolution from scan verification.
Reviewed
Before you start
At least one scan must have completed. Changing triage state requires the appropriate organization permissions.
Filter the queue
Open All Findings. Search by title, rule, or resource and filter by severity, category, detection state, operational state, or assignee. Start with critical and high severity, then use resource and attack-path context to decide priority.
Read the evidence and remediation
Open a finding. Read Why it matters, Affected resource, Evidence, Compliance impact, and Remediation. Evidence describes discovered configuration at the last scan; verify the resource identity before applying a change.
Assign and document the investigation
Set an Assignee, use Investigating when work begins, and add a comment with ownership, investigation details, or remediation notes. The Activity timeline records supported operational changes, making the hand-off visible to the team.
Separate triage decisions from detection
A team can mark a finding resolved, suppress it, or accept risk. Suppression requires a reason and may have an expiry. Suppression changes triage queues but still contributes to risk and compliance. Marking resolved does not change what the scanner detects.
Verify with a fresh scan
After remediation, trigger a scan for the affected account. Marked resolved, awaiting verification means the latest scan still detects the issue. Verified resolved means a scan confirmed it no longer reproduces. Revisit the evidence if it remains detected.
Where you are now
The finding has an accountable owner and a documented decision, with scan verification kept separate from manual triage.
WHEN SOMETHING LOOKS OFF
A few things to check
No inventory record for the resource
The resource may have been deleted, or the finding may cover an account-level control. The finding itself remains usable.
Suppressed finding still affects the score
This is expected: suppression does not remove the security condition from risk or compliance calculations.
PUT IT INTO PRACTICE
Make your next move in Secorvia.
Open the app and follow along with your own organization.