Skip to main content

Discovery Review Workflow

The Pavri Discovery workspace is where operators review shadow or hosted assets that have been identified but are not yet governed in the same way as instrumented agents.

Current readiness

AreaStatusNotes
Discovery queue, filters, and saved viewsPreviewUseful for triage and UX review; still not a fully live hosted-discovery control plane.
Approve / reject / defer actionsPreviewAvailable to Admins and Security Analysts.
Read-only review for ViewersLiveViewers can inspect the workspace but cannot mutate review state or saved views.
Rich evidence correlation and hosted-discovery depthPlannedStill needs deeper live-data wiring and evidence UX.

What the current workflow supports

Use Discovery to:

  • review the triage queue
  • filter by status and confidence
  • save and revisit useful filtered views
  • open asset detail and posture history
  • approve, reject, or defer assets when your role allows it

Current role model

RoleDiscovery behavior
AdminFull review access
Security AnalystFull review access
ViewerRead-only inspection with explicit non-mutating states

What is still preview-only

Discovery has a credible operator shape, but it is still not the full hosted-discovery product promised in later roadmap phases. The main remaining gaps are:

  • deeper evidence correlation
  • richer drift/history storytelling
  • stronger rationale capture for review decisions
  • more complete live-data backing for hosted discovery

Use the current Discovery workspace for review and evaluation, but treat it as a preview operator surface rather than a finished discovery control plane.