Skip to main content

Discovery Review Workflow

The Pavri Discovery workspace is where operators review shadow or hosted assets that have been identified but are not yet governed in the same way as instrumented agents.

Support status

AreaStatusNotes
Discovery queue, filters, and saved viewsAvailableReview tenant-scoped discovered assets.
Approve / reject / defer actionsAvailableAvailable to Admins and Security Analysts.
Read-only review for ViewersAvailableViewers can inspect the workspace but cannot mutate review state or saved views.

What the current workflow supports

Use Discovery to:

  • review the triage queue
  • filter by status and confidence
  • save and revisit useful filtered views
  • open asset detail and posture history
  • approve, reject, or defer assets when your role allows it

Current role model

RoleDiscovery behavior
AdminFull review access
Security AnalystFull review access
ViewerRead-only inspection with explicit non-mutating states

Operating boundaries

Discovery records are evidence for review; they do not prove exploitation or automatically change a runtime policy. Review the linked asset details, posture history, ownership, and any related session evidence before approving, rejecting, or deferring an item. Record the reason through the dashboard so the decision is available for later audit.