1
Sign in to Panaptico
Open https://alpha.panaptico.com and sign in with your work account.If your organization has not been onboarded yet, email support@panaptico.com and the team will provision your tenant.
2
Connect a provider
In the dashboard, choose Providers and select a system category to connect. Panaptico acquires data in three modes:
- Ask — scripted API pulls on a schedule.
- Listen — log, metric, and event streams (commonly via Cribl) into your lake.
- Test — active probes that prove behavior, including negative verification (send the packet, prove it gets dropped).
3
Define a Signal or tracked field
Declare the target condition for one resource population. For example, track a firewall rule field so that
sourceRanges contains only private IP ranges.- Go to Signals and click New Signal.
- Choose the connected provider and resource type (for example,
gcp_compute_firewall). - Select the field
sourceRanges. - Set the target condition:
all values in 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16. - Name the Signal and save.
4
Reconcile and review results
Panaptico compares live state with your declared target and produces one of four results:
- At target — the live value matches the declared condition.
- Off target — the live value violates the condition.
- Unknown — the provider returned data, but this field or resource was not included in the scope.
- Unobserved — no data arrived within the expected window.
5
Close the loop
For any gap you find, you have two paths:
- Open a Work Item — create a ticket with an owner directly from the gap. When the fix lands, Panaptico re-verifies automatically and closes the loop.
- Set up Routing — configure an automated response so that when reality slips, something happens. For example, a non-compliant firewall change can trigger a ServiceNow ticket or a quarantine action in Cloudflare.
What to verify next
How it works
Walk through the full Acquire, Understand, Verify, Run, Act loop.
System Sensor
Learn how always-on sensors read your estate field by field.
Connecting providers
Add more identity, cloud, security, and network sources.
Declaring intent
Define populations, thresholds, and initiatives.