Skip to content
Patronus
Website

Findings and policies

Review a local finding and understand how its actions affect future activity.

A finding requires investigation. A policy determines how matching activity is handled. Review the evidence before changing future behavior.

Open Findings, select an item, and check its kind, affected connection or tool, severity, current treatment, and linked evidence. Use the trace to understand what happened and which policy or audit contributed to the result.

Finding kindWhat it means
Unknown AI connectionAn observed AI connection needs an explicit review
Unknown tool callAn observed tool use needs an explicit review
Threat warningSecurity analysis reported a threat signal
Policy blockPatronus observed activity blocked by policy
Data exposureSensitive-data evidence needs a treatment decision

An unknown connection or tool is not automatically malicious. A threat warning is not, by itself, proof that an operation was blocked.

The available actions depend on the finding kind. Connection and tool findings can offer persistent allow or block rules. Threat and data-exposure findings can offer more specific treatments, including approval-based blocking or redaction where applicable.

Before applying a policy action, check what it matches and how future activity will be handled. Local policy actions update device policy. Acknowledge records a review; it does not create an allow rule.

Organization policy takes precedence over a less restrictive local rule. A local allow cannot weaken an organization block. If a local action does not change the effective treatment, inspect the organization policy with your administrator.

Organization finding actions follow a separate draft and publication workflow.

Repeat a harmless example of the same activity and inspect its trace. Confirm the actual runtime outcome and matched policy rather than relying only on the finding’s label.