How Work Items work
A Work Item is created from a verified gap. It contains:- What is off target — the specific field, Signal, or Probe result that diverged from intent
- Current state vs target — the actual value and the declared intent
- Owner — the person or team assigned to resolve the gap
- Priority and due date — derived from Initiative policy or manually set
- Evidence link — the full history of the gap, including when it first appeared and every drift since
Closed loop with continuous verification
Traditional ticketing systems close when a human marks the ticket done. Panaptico closes when the system proves the fix worked. This matters because:- Fixes can be partial: a firewall rule might change but not cover all intended ports
- Fixes can regress: a patch might be reverted by a subsequent deployment
- Fixes can be unobserved: the sensor might not be able to read the field after the change
Example: Device compliance gap
An Initiative requires all “Main Admin Users” devices to be encrypted. A System Sensor read finds a device with encryption disabled. Panaptico creates a Work Item for the device owner in the IT team. The owner enables encryption. On the next Intune sensor poll, the device is marked encrypted and the Work Item closes. Two weeks later, a policy push reimages the device and encryption is temporarily off. The next sensor read detects the regression, the Initiative goes off target, and a new Work Item opens automatically.When to use Work Items
Use Work Items when you need accountability for every gap and proof that fixes actually worked. They are the operational output of Initiatives and the input to operational review and audit.Initiatives
The programs that generate Work Items when gaps are discovered.
Routing
Route actions automatically to prevent or remediate gaps before Work Items are needed.
System Quality
See how Work Items drive continuous system quality and assurance.