Monitoring

Monitors watch the stream. Classifications make the call.

Monitors run saved code on a cadence against logs and events — provisioning results, job runs, API latency, storage usage. Classifications decide, record by record, whether to act, review, or pass.

Monitor · Employee IT workspace

Account provisioning failures

Counts app assignments that failed for new and changed accounts, per app, over a rolling 24-hour window.

ClearSeverity · warningEvery 15 minutesOkta System Log

Runs · 14 days

1,344

every one executed

Records examined

18,210

41 in the last run

Telemetry lag

4 min

inside one cadence

Last raised

22h ago

3 failures in Slack

Last 48 runsClearRaisedUndetermined
ClassificationTypeLatest run · per record

Failure needs IT action

Operational triage1 act2 review38 pass

Expected retry, self-heals

Control verification0 act0 review41 pass
The evidence decides: act, review, or pass

Record · 22h ago

Slack assignment failed for a new hire: license limit reached

Actconfidence 0.91

Failure needs IT action

Verdicts

Three honest answers.
Never a default green.

Every run ends in one of three verdicts, and each one keeps the records that produced it.

Clear

The monitor examined its records and found nothing that meets its condition.

Raised

The condition was met. The run keeps the matching records for classification and follow-up.

Undetermined

The evidence couldn't decide — no records, stale telemetry, or a failed read. Reported exactly that way.

Classifications

Every record gets a decision.
Act, review, or pass.

Classifications read the records a monitor keeps and decide what each one needs, with a confidence — so people spend time on the one record that matters, not the forty that don't.

Classification · Latest run

Failure needs IT action

on Account provisioning failures · 41 records

Act1

Slack · license limit reached for a new hire

confidence 0.91

Review2

Jira · group mapping missing

confidence 0.62

Zoom · SCIM request timed out

confidence 0.55

Pass38

Google Workspace · retry succeeded

confidence 0.97

Okta · duplicate assignment ignored

confidence 0.94

GitHub · seat already assigned

confidence 0.93

+35 more

Each record gets a decision and a confidence — kept with the run it came from.

Every record gets a decision

41 → 1

records examined, one that needs a person

Schedule

Scheduled and versioned.
Nothing goes live until it's published.

See every run coming in the next 24 hours, and move new monitors from draft to preview to published when they're ready.

Monitoring

Next 24 hours

3 active monitors · 11 drafts in flight

MonitorNow+6h+12h+18h+24h

Account provisioning failures

Every 15 minutes

API p95 latency within budget

Hourly

Nightly warehouse load finished by 06:00

Daily at 06:05

Drafts in flight

Nothing goes live until it’s published

Draft11
Previewed6
Validated4
Published3
Scheduled, versioned, on the record

121

runs in the next 24 hours, each one recorded

Run time

Code you can read.
Not a guess you can't.

Saved code, run on schedule

Evaluate now executes the saved code once, with no AI in the loop. What runs on schedule is code you can read.

Every run recorded

Records examined, telemetry lag, and what the run concluded — kept for every run, not just the ones that raised.

Lag you can see

Telemetry delay is tracked per monitor, so a quiet monitor and a blind one never look the same.

Examples

Monitors teams run.
Across the whole estate.

Account provisioning failures
Nightly data loads finish on time
API latency stays inside budget
Backup jobs report success
Storage growth outpaces headroom
Certificate renewals fail

Watch what matters.
Decide what needs a person.

Start with the logs you already collect. Panaptico turns them into monitors with verdicts you can defend.