Skip to main content

Mute rules

Not every failing check is a problem to fix. A sanctioned public bucket, a break-glass IAM user, a deliberately open dev security group: these are accepted risks, and they should not drown out the findings that actually need work.

Muting suppresses findings from active posture without deleting anything. Muted findings stay queryable, keep their history, and carry the reason they were muted.

Mute findings​

  1. On the Findings page, select the finding rows to suppress. Multi-select works across the current filter.
  2. Click Mute. Give the rule a name and a reason. The reason is what future reviewers and auditors will read.
  3. The selected findings are muted immediately, and the rule re-mutes the same findings on every future scan while it stays enabled.

A muted finding shows its mute state and reason in the finding detail.

What muting changes​

  • The Findings page defaults to active findings, the non-muted ones. The mute-state filter switches to muted or all.
  • Muted findings stop counting against the posture score and compliance requirement tallies, with a paper trail, unlike ignoring them.

Manage the rules​

The Mute rules page lists every rule in the workspace:

ActionEffect
Disablethe rule stops re-muting. The findings resurface on the next scan
Enableresumes suppression on future scans
Deleteremoves the rule. The findings resurface on the next scan

Nothing is ever deleted by muting or unmuting. Rules only control whether matched findings count as active.

Muting well​

  • One rule per accepted risk, named for the risk rather than the date, such as public-assets-bucket.
  • Write the reason as a justification, not a restatement: "static marketing assets, approved 2026-05, review yearly" beats "public bucket".
  • Review the rules page periodically. An accepted risk from last year may not be accepted anymore. Disabling a rule is a one-click way to re-audit: the findings come back on the next scan.