Discovery Review Workflow
The Pavri Discovery workspace is where operators review shadow or hosted assets that have been identified but are not yet governed in the same way as instrumented agents.
Support status
| Area | Status | Notes |
|---|---|---|
| Discovery queue, filters, and saved views | Available | Review tenant-scoped discovered assets. |
| Approve / reject / defer actions | Available | Available to Admins and Security Analysts. |
| Read-only review for Viewers | Available | Viewers can inspect the workspace but cannot mutate review state or saved views. |
What the current workflow supports
Use Discovery to:
- review the triage queue
- filter by status and confidence
- save and revisit useful filtered views
- open asset detail and posture history
- approve, reject, or defer assets when your role allows it
Current role model
| Role | Discovery behavior |
|---|---|
| Admin | Full review access |
| Security Analyst | Full review access |
| Viewer | Read-only inspection with explicit non-mutating states |
Operating boundaries
Discovery records are evidence for review; they do not prove exploitation or automatically change a runtime policy. Review the linked asset details, posture history, ownership, and any related session evidence before approving, rejecting, or deferring an item. Record the reason through the dashboard so the decision is available for later audit.