Mute rules
Not every failing check is a problem to fix. A sanctioned public bucket, a break-glass IAM user, a deliberately open dev security group: these are accepted risks, and they should not drown out the findings that actually need work.
Muting suppresses findings from active posture without deleting anything. Muted findings stay queryable, keep their history, and carry the reason they were muted.
Mute findings
- On the Findings page, select the finding rows to suppress. Multi-select works across the current filter.
- Click Mute. Give the rule a name and a reason. The reason is what future reviewers and auditors will read.
- The selected findings are muted immediately, and the rule re-mutes the same findings on every future scan while it stays enabled.
A muted finding shows its mute state and reason in the finding detail.
What muting changes
- The Findings page defaults to active findings, the non-muted ones. The mute-state filter switches to muted or all.
- Muted findings stop counting against the posture score and compliance requirement tallies, with a paper trail, unlike ignoring them.
Manage the rules
The Mute rules page lists every rule in the workspace:
| Action | Effect |
|---|---|
| Disable | the rule stops re-muting. The findings resurface on the next scan |
| Enable | resumes suppression on future scans |
| Delete | removes the rule. The findings resurface on the next scan |
Nothing is ever deleted by muting or unmuting. Rules only control whether matched findings count as active.
Muting well
- One rule per accepted risk, named for the risk rather than the date,
such as
public-assets-bucket. - Write the reason as a justification, not a restatement: "static marketing assets, approved 2026-05, review yearly" beats "public bucket".
- Review the rules page periodically. An accepted risk from last year may not be accepted anymore. Disabling a rule is a one-click way to re-audit: the findings come back on the next scan.