Evidence & History
Verified once is not verified. Panaptico keeps intended posture pointed at live provider state — re-verifying every conclusion, keeping the evidence and history behind it, and proving recovery the hard way: backups that provably ran, restores that provably work.
Posture
You declare the intended posture — expected resources, required conditions, operating targets. Panaptico observes live provider state and verifies reality against it, field by field. Providers stay authoritative; Panaptico verifies across them.
Coverage
98.4%
of 148,291 expected resources evaluated
Off Target (7d)
37
drift with before/after values · 4 open
Unknown
2,381
stale or unobservable — never a pass
Evidence Freshness
48s
oldest in scope · verified continuously
Verification cadence · Last 24h
2,048 runs · 2.1s median
Continuous, not scheduled
Verification runs every few seconds against every connected provider. You find out about drift in seconds, not at next quarter's audit.
Denominators, not samples
Coverage starts from the expected population, not from whatever happened to report. Every expected resource is evaluated or explicitly missing — the denominator is always visible.
Unknown is a first-class result
When evidence goes stale or a scope can't be observed, the result degrades to Unknown instead of staying green. Silence never becomes a pass.
Detect
Every finding is current state against the declared target, field by field — before and after values, attribution, and a named blast radius of affected resources, identities, and paths. Severity isn't a vibes call; it's derived from that scope.
| ID | Resource | Kind | Drift | Severity | Providers | Detected |
|---|---|---|---|---|---|---|
| d-7841 | prod-api-gateway-01 | Network | Security group 0.0.0.0/0 on port 22 — declared target is bastion-only · 99% | Critical | 2m ago | |
| d-7839 | hr-okta-app-204 | Access | 9 users granted admin outside IAM change window · 96% | High | 11m ago | |
| d-7835 | tp1dist-01 | Config | Terraform state drift — manual resize of i-0de42 to r6i.4xl · 100% | High | 24m ago | |
| d-7828 | ops-db-cluster-03 | Recovery | Backup retention 7d — declared standard requires 30d · 100% | Critical | 41m ago | |
| d-7824 | dr-replica-usw2-01 | Recovery | Replication lag 26m — declared RPO is 15m · 94% | Medium | 1h ago |
Showing 5 of 37 · grouped by resource
Every row is two-sourced. No single-provider drift alerts.
Grounded in multiple providers
Every drift finding is corroborated by at least two providers. A single API blip never pages oncall.
Blast radius is named, not guessed
Divergence lands in a known scope — computed from dependencies and effective paths, down to the affected resources, identities, and routes. Critical means critical in your environment.
Context ready for triage
Click into a finding and the field-by-field diff, the before and after values, and the full state history load together — no tab-hopping.
Evidence
Every verification run keeps its receipts — provider snapshots, config diffs, approvals, screenshots, logs — each tied to the conclusion it supports, stamped with scope, coverage, freshness, and the definition version it was judged under. When anyone asks for proof, audit is an export.
IAM policy GetAccountPasswordPolicy
Logical access
Access Policy Standard
terraform plan — prod/us-east-1
Change management
Change Control Standard
CHG-00482 — prod-db maintenance window
Change approval
Change Control Standard
Backup retention — 30d verified
System monitoring
Backup Recoverability Standard
MFA enforcement — last 24h
Authentication
Identity Access Standard
Restore probe — ops-db-cluster-03 point-in-time
Recovery & continuity
Backup Recoverability Standard
Tied to the contract, not folders
Every artifact carries its scope, target condition, and definition version at capture time. Any conclusion traces back to its provider evidence in one click.
Immutable, with full history
Evidence is hashed, signed, and append-only — every transition, exception, and recovery stays on the record. What was true at 14:08 is the same record you export next March.
Fresh, or it degrades
Evidence carries its age. When it goes stale, the result becomes Unknown rather than silently staying green. Nobody chases screenshots; nothing waits on a sprint.
Close the loop
Panaptico doesn't make the fix — your teams, tools, and workflows own that. It holds the question open: the finding keeps its named scope, owners and gates consume the same verified answer, and the drift stays open until re-verification shows the target condition holding again. The loop doesn't stop.
d-7841 — prod-api-gateway-01
Security group 0.0.0.0/0 on port 22 · detected 2m ago
Observe
Evidence 48s fresh · AWS + Wiz
Detect
0.0.0.0/0 vs bastion-only target · attributed
Scope
Blast radius: 3 resources · 2 identities · 1 path
Hand off
Finding with owning team · release gate holds
Re-verify
Re-checked every run until the target holds
Evidence
CC6.1 + A.9.2 re-verified · transition sealed
Humans own the fix
Owners, workflows, gates, and agents consume the same verified answer that raised the finding. Panaptico observes, evaluates, and evidences — it never writes to your environment.
Closed means re-verified
A finding doesn't close because someone marked it fixed. It closes when re-verification shows the target condition holding — with fresh evidence attached.
History is the product
Every transition, exception, and recovery stays on the record. The longer Panaptico runs, the deeper the history behind every answer.
Operate
One place to answer "what changed, when, why — and does the target condition still hold?" Recovery is where it bites: a configured backup is not a proven recovery. Real denominators, restore probes that actually restored, replication inside RPO, and the dependency chain behind every critical capability — verified, or Unknown.
Intended posture on one side, live provider state on the other — verified quietly, continuously, with the receipts every audit, gate, and 3 a.m. question will ask for.