Evidence & History

Every check, change, and fix on the record.

Panaptico keeps the evidence behind every verdict — what was read, when, and against which definition — so an audit or an incident review becomes an export, not a fire drill.

History · Policy

Databases without automated backups

billing-db-prodExport CSV

Sep 24 · 06:02

ClearAutomated backups on

backupConfiguration.enabled = true

Cloud SQL API · definition v3

Sep 23 · 14:40

Fix doneConfirmed by the next evaluation, not a checkbox

Remediation · PLAT-209

Sep 23 · 09:15

ViolatingAutomated backups off

backupConfiguration.enabled = false

Cloud SQL API · definition v3

Sep 20 · 11:00

Definition v3Point-in-time recovery added as a requirement

Changed by j.rivera

Sep 18 · 06:00

UnknownPermission denied reading the instance

Reported as Unknown, never as Clear

Every transition, with the evidence behind it

v3

definitions are versioned, so old verdicts stay explainable

Receipts

What every receipt holds.
Enough to defend the answer.

Policies, monitors, verifications, and capabilities all keep the same four facts for every verdict.

Resource and scope

Exactly what was judged, and why it was in scope for that check.

Observed value

The value Panaptico read from the system that owns it, attributed to its source.

Freshness

When it was read, and whether that's recent enough to trust for this check.

Definition version

The version of the rule that judged it, so old verdicts stay explainable after a change.

Reports

Reports from the record.
Not from memory.

Pull a period's capabilities, policies, verification runs, and fixes into one report — every number linked back to its receipts.

Reports

Quarterly IT continuity report

Jul 1 – Sep 30Export CSV

Capabilities

15

6 enabled at quarter end

Policies

29

21 clear · 3 unknown

Verification runs

412

97% passed

Fixes closed

38

each confirmed by evaluation

Capability health, week by week

58 → 70

JulAugSep

Still open

3 fixes · 2 checks with stale evidence

Every number links to its receipts

Resource, observed value, time read, definition

Audit becomes an export, not a fire drill

412

verification runs this quarter, each one kept

Honest by design

History you can rely on.
Because nothing is smoothed over.

Unknown stays unknown

A failed read is recorded as unknown, never back-filled with the last good value.

Nothing is overwritten

Every transition is kept — violating, fixed, clear — with the evidence that caused it.

Export on demand

Export history and reports as CSV whenever an auditor, a customer, or a board asks.

Used for

When someone asks for proof.
You already have it.

Quarterly continuity reviews
Audit evidence requests
Post-incident timelines
Before-and-after checks for a migration
Customer assurance questionnaires
Leadership and board reporting

Stop rebuilding the evidence.
Keep it as you go.

Connect one system and Panaptico starts keeping receipts from the first evaluation.