Skip to content
Patronus
Website

Findings and policy rollout

Investigate organization findings, publish policy, and verify device behavior.

Organization findings collect observed issues across devices. Their evidence helps set the scope of a response: one connection, a device group, or the organization.

Open a finding and review its kind, subject, occurrences, affected devices, and evidence. Occurrences count observations; the device count counts distinct devices. Repeated use on one device can therefore increase occurrences without increasing the device count.

Unknown connections and tool calls need review. Threat warnings, policy blocks, and data exposure describe different kinds of observed events and offer different actions.

Choose a supported action and review its confirmation. A policy action prepares a draft; check its match conditions, treatment, and scope before publishing.

Use a device group for a limited rollout when appropriate. Groups are assigned to devices directly; adding a person to an organization does not automatically assign that person’s devices to a group.

  1. Review the policy draft and its scope in the dashboard.
  2. Publish the intended version.
  3. Check the affected devices’ policy state and connectivity.
  4. Repeat a harmless matching interaction on a test device.
  5. Inspect the new trace to confirm the matched policy and actual outcome.

Publication makes a policy available for distribution; it does not prove that an offline device received it. Check the device’s last observed state when assessing rollout.

An enrolled device can still produce local findings and allow local review. Local policy can add restrictions, but a local allow cannot weaken an organization rule. Use device administration to check scope if the outcome differs from your expectation.