Remediation
A remediation scan reads the evidence and writes one fix per cause: the steps, how to verify it worked, and a hand-off prompt you can paste into Linear, Rovo, or a work item.
Remediation scan · Policies
6 fixes across 5 policies
Renew the checkout certificate and turn on auto-renewal
Low effort · Low risk
api.checkout.example.com · expires in 6 days · target ≥ 14 days · read 4 min ago
StepsThe policy re-evaluates to Clear on its next run. That is what marks this fix done.
PLAT-214 · Todo
Renew the checkout certificate and turn on auto-renewal
Evidence, steps, and how to verify attached
How it works
Run a scan on any view — policies, capabilities, or monitors. It reads the receipts on screen, not a summary of them.
Findings are grouped by what's actually wrong, so six violations with one root cause become one fix.
Each fix carries steps, effort, risk, and a prompt a person or an agent can act on. Send it to Linear, Rovo, or a work item.
A fix is done when the next evaluation comes back clear — not when a ticket closes.
Hand-off
The hand-off prompt quotes the evidence, spells out the steps, and says exactly what done looks like — so nothing gets lost between the finding and the fix.
Fix · Hand-off
Renew the checkout certificate and turn on auto-renewal
## Context
Policy “TLS certificates expire in under 14 days” is violating (critical).
Evidence: api.checkout.example.com expires in 6 days (target ≥ 14), read 4 min ago.
## Do
1. Reissue the certificate for api.checkout.example.com.
2. Turn on auto-renewal 30 days before expiry.
3. Deploy to both load balancers and confirm the chain.
## Done when
The policy re-evaluates to Clear on its next run.
Effort
Low
about 30 minutes
Risk
Low
no downtime expected
Owner
Platform
Edge & DNS workspace
PLAT-214 · In progress
Renew the checkout certificate and turn on auto-renewal
Verified by the next evaluation
Why it works
Every fix names the resource, the observed value, and the target it missed — no re-investigation needed.
Each fix says how big it is and what it could disturb, before anyone picks it up.
Related violations roll up to the change that resolves them, instead of a ticket per resource.
Hand off to Linear, Rovo, or a work item. Your team keeps working where it already works.
The scan tracks how many fixes are verified fixed — confirmed by evaluation, not by status fields.
When the evidence behind a scan changes, Panaptico tells you, so fixes never go stale.
Works with
Business capabilities, scored from their requirements — with receipts
Explore EnablementsLive state against declared targets, with evidence for every violation
Explore Policies & PostureMonitors on a cadence; classifications decide act, review, or pass
Explore MonitoringRun a scan on your noisiest policy. Panaptico groups the findings and writes the fixes.