Evidence & History

Prove it still holds

Verified once is not verified. Panaptico keeps intended posture pointed at live provider state — re-verifying every conclusion, keeping the evidence and history behind it, and proving recovery the hard way: backups that provably ran, restores that provably work.

Posture

Intended posture, continuously verified

You declare the intended posture — expected resources, required conditions, operating targets. Panaptico observes live provider state and verifies reality against it, field by field. Providers stay authoritative; Panaptico verifies across them.

LivePosture Overview· Enterprise-Wide
Updated 48s ago

Coverage

98.4%

of 148,291 expected resources evaluated

Off Target (7d)

37

drift with before/after values · 4 open

Unknown

2,381

stale or unobservable — never a pass

Evidence Freshness

48s

oldest in scope · verified continuously

Verification cadence · Last 24h

2,048 runs · 2.1s median

Verification runDrift detected
1

Continuous, not scheduled

Verification runs every few seconds against every connected provider. You find out about drift in seconds, not at next quarter's audit.

2

Denominators, not samples

Coverage starts from the expected population, not from whatever happened to report. Every expected resource is evaluated or explicitly missing — the denominator is always visible.

3

Unknown is a first-class result

When evidence goes stale or a scope can't be observed, the result degrades to Unknown instead of staying green. Silence never becomes a pass.

Detect

Drift, attributed and scoped

Every finding is current state against the declared target, field by field — before and after values, attribution, and a named blast radius of affected resources, identities, and paths. Severity isn't a vibes call; it's derived from that scope.

37 Drift Findings· rolling 7 days
All providersSeverity: All
IDResourceKindDriftSeverityProvidersDetected
d-7841prod-api-gateway-01Network

Security group 0.0.0.0/0 on port 22 — declared target is bastion-only

· 99%
Critical
AWS
Wiz
2m ago
d-7839hr-okta-app-204Access

9 users granted admin outside IAM change window

· 96%
High
Okta
Workday
11m ago
d-7835tp1dist-01Config

Terraform state drift — manual resize of i-0de42 to r6i.4xl

· 100%
High
Terraform
AWS
24m ago
d-7828ops-db-cluster-03Recovery

Backup retention 7d — declared standard requires 30d

· 100%
Critical
AWS
41m ago
d-7824dr-replica-usw2-01Recovery

Replication lag 26m — declared RPO is 15m

· 94%
Medium
AWS
Datadog
1h ago

Showing 5 of 37 · grouped by resource

Every row is two-sourced. No single-provider drift alerts.

1

Grounded in multiple providers

Every drift finding is corroborated by at least two providers. A single API blip never pages oncall.

2

Blast radius is named, not guessed

Divergence lands in a known scope — computed from dependencies and effective paths, down to the affected resources, identities, and routes. Critical means critical in your environment.

3

Context ready for triage

Click into a finding and the field-by-field diff, the before and after values, and the full state history load together — no tab-hopping.

Evidence

The proof assembles itself

Every verification run keeps its receipts — provider snapshots, config diffs, approvals, screenshots, logs — each tied to the conclusion it supports, stamped with scope, coverage, freshness, and the definition version it was judged under. When anyone asks for proof, audit is an export.

Evidence Vault· 1,204 artifacts · immutable
API snapshot4.2 KB

IAM policy GetAccountPasswordPolicy

Logical access

Access Policy Standard

AWS IAM
2026-04-22 14:08
Config diff18.6 KB

terraform plan — prod/us-east-1

Change management

Change Control Standard

Terraform
2026-04-22 14:05
Approval record2.1 KB

CHG-00482 — prod-db maintenance window

Change approval

Change Control Standard

ServiceNow
2026-04-22 13:41
Screenshot1.3 MB

Backup retention — 30d verified

System monitoring

Backup Recoverability Standard

AWS Backup
2026-04-22 13:02
Log7.8 KB

MFA enforcement — last 24h

Authentication

Identity Access Standard

Okta
2026-04-22 12:55
Log912 B

Restore probe — ops-db-cluster-03 point-in-time

Recovery & continuity

Backup Recoverability Standard

AWS Backup
2026-04-22 12:30
1

Tied to the contract, not folders

Every artifact carries its scope, target condition, and definition version at capture time. Any conclusion traces back to its provider evidence in one click.

2

Immutable, with full history

Evidence is hashed, signed, and append-only — every transition, exception, and recovery stays on the record. What was true at 14:08 is the same record you export next March.

3

Fresh, or it degrades

Evidence carries its age. When it goes stale, the result becomes Unknown rather than silently staying green. Nobody chases screenshots; nothing waits on a sprint.

Close the loop

A finding closes when reality says so

Panaptico doesn't make the fix — your teams, tools, and workflows own that. It holds the question open: the finding keeps its named scope, owners and gates consume the same verified answer, and the drift stays open until re-verification shows the target condition holding again. The loop doesn't stop.

Intended PostureVERIFICATION CONTRACTObservescoped · read-onlyDetecttwo-source corroborationScopenamed blast radiusHand offowners, gates, workflowsRe-verifytarget condition holdsEvidencesealed in history
Active event

d-7841 — prod-api-gateway-01

Security group 0.0.0.0/0 on port 22 · detected 2m ago

Observe

Evidence 48s fresh · AWS + Wiz

Detect

0.0.0.0/0 vs bastion-only target · attributed

Scope

Blast radius: 3 resources · 2 identities · 1 path

Hand off

Finding with owning team · release gate holds

Re-verify

Re-checked every run until the target holds

Evidence

CC6.1 + A.9.2 re-verified · transition sealed

1

Humans own the fix

Owners, workflows, gates, and agents consume the same verified answer that raised the finding. Panaptico observes, evaluates, and evidences — it never writes to your environment.

2

Closed means re-verified

A finding doesn't close because someone marked it fixed. It closes when re-verification shows the target condition holding — with fresh evidence attached.

3

History is the product

Every transition, exception, and recovery stays on the record. The longer Panaptico runs, the deeper the history behind every answer.

Operate

A live record of what's true now

One place to answer "what changed, when, why — and does the target condition still hold?" Recovery is where it bites: a configured backup is not a proven recovery. Real denominators, restore probes that actually restored, replication inside RPO, and the dependency chain behind every critical capability — verified, or Unknown.

Verification Activity
6 events · last 2h
Verified 148,291 resources across 14 providers
48s ago
Backup window closed — 412/412 protected databases show success evidence
3m ago
New drift — prod-api-gateway-01 · 0.0.0.0/0:22 vs bastion-only target
2m ago
Restore probe passed — ops-db-cluster-03 point-in-time restore, evidence sealed
14m ago
Evidence bundle exported — Backup Recoverability, 874 artifacts
1h ago
Failover capacity evidenced — us-west-2 standby at declared headroom
2h ago

The record never closes

Intended posture on one side, live provider state on the other — verified quietly, continuously, with the receipts every audit, gate, and 3 a.m. question will ask for.