Environments drift — vendors patch, engineers tweak, exceptions accumulate. Panaptico continuously verifies live provider state against your declared targets and surfaces every material change — with before and after values, source, and attribution.
sp · finance-etl-prod
Azure
sensor policy · EMEA-finance
CrowdStrike
group · fin-admins
Okta
warehouse · REPORTING_WH
Snowflake
kms key rotation · 14 CMKs
AWS
monitor · auth-latency-p99
Datadog
policy · pki-intermediate
Vault
integration system user
Workday
3 critical · 3 notable · 2 expected · every row carries before/after values, source, and attribution
DRIFT-FEED-0491 · liveWhy existing monitoring misses it
01
Datadog tells you latency jumped. Nobody tells you the warehouse was resized to L an hour ago, and nobody approved it. The alert and the cause live in two different tools.
02
The cloud trail logs 40,000 changes a day. Nine out of ten are routine. The one that matters is buried in noise. Humans give up; the tenth one becomes an incident.
03
Who changed the CrowdStrike policy to monitor-only? The console shows a service-principal name that wasn't tied to a human. Two weeks later, nobody admits to it.
Continuous reconciliation
Declared targets are the anchor. Panaptico observes live provider state on a loop and reconciles it against the operating graph — per object, per field, with attribution when there is one.
Intent · declared target
Live · observed
Fields evaluated
92,418
Drifted
217
Attributed
203
Unknown source
14
Smart classification
Raw state transitions are evaluated against the operating graph — scoped, explained, and ranked by severity. You see the 14 that matter, not the 18,417 that don't.
The funnel turns 18k events into a queue of 14 — each one with context, not a ticket template
Object
azure · finance-etl-prod · service principal
Change
Why it's critical
Change attribution
Each drift gets correlated against the graph's source streams — CHG tickets, Terraform runs, vendor patch feeds, SCIM syncs, human console activity. "Unknown source" is a category, not a shrug.
Terraform Cloud · workspace finance-prod
run #2841 · plan applied 14:21:08Z
Snowflake activity log · user
session held by svc-dbt-prod · no interactive user
CHG ticket queue
no ticket matched object · window ±60min
Vendor patch feed
no Snowflake release event in window
Attributed to Terraform run #2841 · commit a4f2…e991 · author j.tran@ · matched to CHG-00604
Findings, routed
Every classified drift lands where it gets acted on — recorded as expected, opened as a finding, sent to a gate, or escalated. Humans, workflows, gates, and agents consume the same verified answer.
When
drift is expected · matches vendor patch feed or scheduled change
Action
recorded as expected · history updated · evidence attached
Volume
8,902 in last 24h
When
drift is notable · bounded deviation inside the declared envelope
Action
finding opened · owner notified · tracked until resolved or accepted
Volume
389 in last 24h
When
drift touches a governed control · re-approval required
Action
routed to the approval gate · same verified evidence attached
Volume
11 in last 24h
When
drift breaks a declared target or has no attributable source
Action
critical finding · oncall paged · evidence bundle captured
Volume
3 in last 24h
Rules are reviewed quarterly · every routed finding is recorded with its evidence and history
ROUTING-POLICY-v14The environment is always changing. Panaptico keeps the record honest — every material change captured with before and after values, source, and attribution, and every finding backed by evidence.