Systems Sensor

Watch every system as it changes

Systems Sensor is the acquisition layer of the ledger — it watches the resources, services, and integrations every initiative depends on, across cloud, identity, endpoint, ITSM, networking, and observability. Current state against declared target, field by field, drift the moment it opens, for every record, every minute.

14 Data SourcesLive
Okta
Connected
AWS
Connected
Microsoft 365
Connected
ServiceNow
Connected
CrowdStrike
Connected
+ 9 more connected
Entities
Signals
Populations
Evidence
1

API-native, no agents

Every connector uses the provider's own API surface. Nothing to install in your environment, nothing to maintain.

2

Intent-scoped discovery

Panaptico pulls what your declared intent needs. The model stays lean by design — scoped to the operations that matter, not everything with an IP.

3

One live model

Every discovered object lands in the model as an entity, a signal, a population member, or evidence — ready to be verified.

Watch

148k resources watched, unified across every source

Sensor deduplicates findings from overlapping tools and preserves full provenance for every attribute — so you always know which source said what, when it last refreshed, and whether the record matches target.

148k Resources Watched

148,291 resources unified and continuously reconciled

Deduplicated across sources · current state checked against target

System NameSystem OwnerOS / DistributionCriticalityData Source
prod-api-gateway-01platform@panaptico.comUbuntu 22.04High
Qualys
AWS
auth-service-prod-mainIT teamUbuntu 22.04High
Orca
analytics-pipeline-proddata-eng@panaptico.comWindows Server 2016High
Tenable
ServiceNow
file-storage-cluster-02Infra engCentos 7.3.1611Medium
Rapid7
dev-sandbox-testingcurtis.w@panaptico.comRocky 8.10Medium
CrowdStrike
Microsoft
nettapphxy-12james.p@panaptico.comRocky 8.10Medium
Orca
nettapphxy-13james.p@panaptico.comRocky 8.10Medium
CrowdStrike
1

Cross-tool deduplication

When Qualys, Orca, and Rapid7 all describe the same host, Panaptico consolidates them into one system record without losing which source observed what.

2

Full provenance

Every field — owner, criticality, environment, controls — carries the exact data sources that contributed. Drill down to see the underlying reasoning.

3

Unified and raw views

See the consolidated graph or switch to per-tool raw data. Both are available; the unified view is the default.

Trust

Every attribute, every source, every confidence score

No attribute without provenance. Every value carries which sources said it, how confident the model is, and when it was last checked — so every claim traces back to evidence, not to a dashboard’s word.

tp1dist-01

Ubuntu Linux 22.04

System Metrics

Last updated: 02/20/2026, 12:20:31 AM

MetricValueData Source(s)
System Owner
Eng Infra Team
Qualys
AWS
Business Criticality
Critical99% confidence
Orca
Internet Facing?
Yes95% confidence
Tenable
ServiceNow
Contains Sensitive Data?
Yes95% confidence
Rapid7
Environment
Production99% confidence
CrowdStrike
Microsoft
Compensating Controls
Yes98% confidence
Tenable
Qualys
Rapid7
1

Cross-tool deduplication

When multiple sources describe the same attribute, Panaptico consolidates them into a single record while preserving the full provenance of which tools observed it.

2

Confidence scoring on every attribute

See how certain Panaptico's agents are about every judgment. Drill into confidence breakdowns to understand which sources contributed and the reasoning.

3

Raw and aggregated views

Both unified and source-specific details are preserved. Switch between the single pane of glass and the raw data from each tool at will.

Normalize

Provider-specific objects collapse to shared primitives

The ontology keeps only what verification needs — identity, state, relationships, evidence. Everything else stays in the raw source layer, in your lake, queryable whenever you want it.

IAM Role
Group
AD Security Group
Primitive

Access Principal

EC2 Instance
Virtual Machine
Compute Engine VM
Primitive

Compute Resource

Change Record
Jira Issue
Pull Request
Primitive

Change Request

Scan Report
Coverage Export
Change Attestation
Primitive

Evidence Artifact

Reconcile

Sensor never stops watching

Every category reconciles on its own cadence. When current state diverges from target, Sensor classifies the change — needs review, action required, in progress, or in sync. The status pill earns attention; the noise stays quiet.

+
Discovery Activity
5 events
Connected to Okta — 12 OUs, 847 groups mapped
Connected to AWS — 148,291 resources across 12 accounts
Normalized 3,217 IAM roles into 412 Access Principals
Identified 37 orphaned service accounts — owner assignment required
Linked 2,340 change records to ServiceNow CAB approval flows
1

Classified, not just alerted

Every drift is categorized — ignorable noise, watched, task-worthy, blocking, approval-gated, or auto-fixable. The engine decides what earns attention.

2

Continuous refresh

Providers are polled on their own cadence and rate limits. New resources appear in the graph as they show up in reality, not on a scheduled export.

3

Baselined forever

Once an initiative lands, the model becomes the baseline for drift, readiness, and the next change — without a second onboarding.

Next

Once Sensor sees the truth,
every claim becomes checkable

Gaps between current and declared state become routed work with owners — probes test the fix, signals re-score, and Sensor confirms the claim holds. Met, and staying met.

See the full platform