Remediation

Every failure comes with its fix.

A remediation scan reads the evidence and writes one fix per cause: the steps, how to verify it worked, and a hand-off prompt you can paste into Linear, Rovo, or a work item.

Remediation scan · Policies

6 fixes across 5 policies

2 critical4 warning
2 of 6 verified fixed33%
CriticalTLS certificates expire in under 14 days

Renew the checkout certificate and turn on auto-renewal

Low effort · Low risk

Evidence

api.checkout.example.com · expires in 6 days · target ≥ 14 days · read 4 min ago

Steps
  1. 1. Reissue the certificate for api.checkout.example.com
  2. 2. Turn on auto-renewal 30 days before expiry
  3. 3. Deploy to both load balancers and confirm the chain
Verify

The policy re-evaluates to Clear on its next run. That is what marks this fix done.

LinearRovoWork item
Copy hand-off prompt
WarningTurn on automated backups for 1 database instance
WarningUpgrade 9 laptops to a supported OS version
Every failure comes with its fix

PLAT-214 · Todo

Renew the checkout certificate and turn on auto-renewal

Evidence, steps, and how to verify attached

How it works

From evidence to done.
And done means verified.

  1. 1

    Scan

    Run a scan on any view — policies, capabilities, or monitors. It reads the receipts on screen, not a summary of them.

  2. 2

    Group by cause

    Findings are grouped by what's actually wrong, so six violations with one root cause become one fix.

  3. 3

    Hand off

    Each fix carries steps, effort, risk, and a prompt a person or an agent can act on. Send it to Linear, Rovo, or a work item.

  4. 4

    Verify

    A fix is done when the next evaluation comes back clear — not when a ticket closes.

Hand-off

A fix anyone can pick up.
Person or agent.

The hand-off prompt quotes the evidence, spells out the steps, and says exactly what done looks like — so nothing gets lost between the finding and the fix.

Fix · Hand-off

Renew the checkout certificate and turn on auto-renewal

LinearRovoWork item
Hand-off promptCopy prompt

## Context
Policy “TLS certificates expire in under 14 days” is violating (critical).
Evidence: api.checkout.example.com expires in 6 days (target ≥ 14), read 4 min ago.

## Do
1. Reissue the certificate for api.checkout.example.com.
2. Turn on auto-renewal 30 days before expiry.
3. Deploy to both load balancers and confirm the chain.

## Done when
The policy re-evaluates to Clear on its next run.

Effort

Low

about 30 minutes

Risk

Low

no downtime expected

Owner

Platform

Edge & DNS workspace

Written for a person or an agent to act on

PLAT-214 · In progress

Renew the checkout certificate and turn on auto-renewal

Verified by the next evaluation

Why it works

Less triage.
More closed loops.

Quotes the evidence

Every fix names the resource, the observed value, and the target it missed — no re-investigation needed.

Effort and risk up front

Each fix says how big it is and what it could disturb, before anyone picks it up.

One fix per cause

Related violations roll up to the change that resolves them, instead of a ticket per resource.

Works with your queue

Hand off to Linear, Rovo, or a work item. Your team keeps working where it already works.

Progress you can trust

The scan tracks how many fixes are verified fixed — confirmed by evaluation, not by status fields.

Rescan when evidence moves

When the evidence behind a scan changes, Panaptico tells you, so fixes never go stale.

Close the gap.
Then prove it's closed.

Run a scan on your noisiest policy. Panaptico groups the findings and writes the fixes.