Policies & Posture

Live state against the targets you set.

Policies evaluate every resource in scope on a schedule — certificates, databases, laptops, storage, accounts. Every violation carries the observed value, the target, and when it was last read.

Policies

Policy library

Last evaluated 4 min ago

Policies

29

across 12 workspaces

Open violations

6

across 5 policies

Clear

21

of 26 evaluated

Evidence gaps

3

reported as unknown

PolicySeverityResourcesVerdict

TLS certificates expire in under 14 days

Edge & DNS

Critical2 of 318 certificatesViolating

Databases without automated backups

Data Platform

Critical1 of 24 instancesViolating

Laptops two or more OS versions behind

Device Fleet

Warning9 of 612 devicesViolating

Storage volumes above 85% capacity

Infrastructure

Warning61 of 61 clearClear

Shared mailboxes without an owner

Collaboration

Warningevidence 3h staleUnknown
Every violation carries its receipt

Receipt

api.checkout.example.com

TLS certificate · load balancer

observedexpires in 6 days

target≥ 14 days

read4 min ago

Receipts

Every verdict, with its receipt.
The argument is over before it starts.

Open a policy to see its rule, its recent evaluations, and a receipt for every resource it judged — clear ones included.

Policy · Edge & DNS

TLS certificates expire in under 14 days

ViolatingSeverity · criticalDaily · next run in 16h

Rule & evidence

certificate.daysToExpiry ≥ 14

Every certificate on a public load balancer · 318 in scope

Last 14 evaluations

Violating for the last 3 runs

Resource receiptExpires inVerdict
api.checkout.example.com6 daysViolatingWaive
status.example.com11 daysViolatingWaive
www.example.com71 daysClear
sso.example.com203 daysClear
Edit policyRun now
Every resource, every run, on the record

316

clear

2

violating

0

unknown

Posture

Field by field.
Current value against target.

Posture tracks the fields that matter on each resource and compares the live value with the target you declared. Anything that can't be read is reported as unknown.

Posture

Cloud SQL · billing-db-prod

14 fields tracked · read 3 min ago
Tracked fieldCurrentTargetState
backupConfiguration.enabledtruetrueAt target
pointInTimeRecovery.enabledfalsetrueOff target
availabilityTypeZONALREGIONALOff target
settings.deletionProtectiontruetrueAt target
maintenanceWindow.daySunday—Observed only
diskAutoresizeLimitunobserved≤ 500 GBUnknown
1 field could not be read — reported as Unknown, never assumed healthy
Field by field, against the target you set

2

fields off target on a tier-1 database

ZONALREGIONAL

How it works

Built for how IT actually runs.
Not for a quarterly spreadsheet.

Scoped to workspaces

Group policies by the systems a team owns, so every violation lands with the people who can fix it.

Critical or warning

Severity is part of the policy, so a certificate expiring in six days never reads like a style issue.

On your schedule

Evaluate daily, hourly, or every 15 minutes — or run a policy now when you need an answer.

Clear, violating, unknown

Three separate counts. Evidence gaps are never folded into the clear column.

History for every resource

Every evaluation is kept, so you can see when something drifted and when it came back.

Explicit waivers

Accept a known exception on the record instead of muting the policy for everyone.

Examples

Policies teams start with.
The checks you already do by hand.

TLS certificates expire in under 14 days
Databases have automated backups
Laptops are at most one OS version behind
Storage volumes stay under 85% full
Every production resource has an owner tag
Shared mailboxes have an owner
Kubernetes nodes run a supported version
DNS records point at live endpoints
Backup jobs ran in the last 24 hours

Declare the target once.
Panaptico holds every resource to it.

Start with the policies you already check by hand. Panaptico evaluates them on schedule and keeps the receipts.