Findings and policies
Review a local finding and understand how its actions affect future activity.
A finding requires investigation. A policy determines how matching activity is handled. Review the evidence before changing future behavior.
Read a finding
Section titled “Read a finding”Open Findings, select an item, and check its kind, affected connection or tool, severity, current treatment, and linked evidence. Use the trace to understand what happened and which policy or audit contributed to the result.
| Finding kind | What it means |
|---|---|
| Unknown AI connection | An observed AI connection needs an explicit review |
| Unknown tool call | An observed tool use needs an explicit review |
| Threat warning | Security analysis reported a threat signal |
| Policy block | Patronus observed activity blocked by policy |
| Data exposure | Sensitive-data evidence needs a treatment decision |
An unknown connection or tool is not automatically malicious. A threat warning is not, by itself, proof that an operation was blocked.
Choose an action
Section titled “Choose an action”The available actions depend on the finding kind. Connection and tool findings can offer persistent allow or block rules. Threat and data-exposure findings can offer more specific treatments, including approval-based blocking or redaction where applicable.
Before applying a policy action, check what it matches and how future activity will be handled. Local policy actions update device policy. Acknowledge records a review; it does not create an allow rule.
On an enrolled device
Section titled “On an enrolled device”Organization policy takes precedence over a less restrictive local rule. A local allow cannot weaken an organization block. If a local action does not change the effective treatment, inspect the organization policy with your administrator.
Organization finding actions follow a separate draft and publication workflow.
Verify the result
Section titled “Verify the result”Repeat a harmless example of the same activity and inspect its trace. Confirm the actual runtime outcome and matched policy rather than relying only on the finding’s label.