Article

Managing findings

Filter audit findings, record what you're doing about each one and track them from one audit to the next.

Every audit produces findings: specific issues in your code, servers or site, each with a severity, a description, evidence and a recommendation. Structurell keeps findings from all your audits in one place under Diagnose → Findings, and recognises the same finding when it appears again, so you can plan fixes, accept risks and see issues resolve themselves as you fix them.

Before you start

The findings page

Go to Diagnose → Findings. At the top, summary tiles show Open findings, Critical findings, the Severity mix and how many were Resolved (30d). Select a tile to filter the table.

The Finding Trend chart shows how your findings have changed over your last 12 audits, alongside your Active Findings, Total Findings and Latest Audit.

The Findings table lists each finding's Title, Status, Severity, Category, Repository ID and Updated At. Findings are sorted by severity, with the most serious first. Select a column heading to sort by it, or select a finding to open it.

Filtering findings

  1. Use the filters above the table to narrow the list by status, severity and Repository.
  2. Select Apply. Select Clear to reset them.

By default the table shows Outstanding findings, meaning everything that still needs attention. Choose All to include resolved and completed findings too. To focus on one project, filter by its repository.

Severity

Each finding has a severity of Critical, High, Medium or Low. Start with critical and high findings, which are also highlighted on the Diagnose overview and on Today.

Some checks also record a passing result, so you may see Pass or Passed when you filter by severity. In a health report, Info marks a check that couldn't be assessed; it isn't scored.

Statuses

A finding's status tells your team what is happening with it:

  • Open: the issue has been found and no decision has been made yet.
  • Planned: you intend to fix it. You can add a Target Release.
  • In Progress: someone is working on a fix. You can add a Target Release.
  • Deferred: you've decided to fix it later. You can add a Target Release.
  • Accepted Risk: you've decided not to fix it. Add an Accepted Risk Reason so others know why.
  • Completed: the fix has been done.
  • Resolved: the issue is no longer found.

Outstanding covers Open, Planned, In Progress, Accepted Risk and Deferred.

Updating a finding

  1. Open the finding.
  2. In the Update Status panel, choose the new Status.
  3. Add a Note explaining the change. If you chose Accepted Risk, fill in the Accepted Risk Reason. If you chose Planned, In Progress or Deferred, you can add a Target Release.
  4. Select Save Status. You'll see "Status updated."

You can also change a finding's status straight from the Findings tab of an audit.

What the finding page shows

  • The finding's title, description, severity and status.
  • Its Category, when it was created, and the Repository and Site it relates to.
  • Details, including the Evidence the audit found and the Recommendation for fixing it.
  • Audit Appearances: every audit the finding appeared in, with that audit's status and score.
  • Status History: every status change, who made it, when, and any note.

How findings change between audits

Structurell matches findings across audits of the same target or repository, so the same issue isn't listed twice:

  • If a later audit runs the same check and no longer finds the issue, the finding is automatically marked Resolved. Checks that didn't run, or a step that failed, never resolve anything.
  • If a Resolved or Completed finding is detected again, it goes back to Open.
  • A finding marked Accepted Risk stays that way when it's detected again.

Also in Assure

The same findings view is also available from Assure → Embedded findings context, so teams working in Assure can see and update findings without switching to Diagnose.

Troubleshooting

  • A finding keeps coming back. It's still being detected. Check the Evidence and Recommendation, and confirm the fix is on the branch or server being audited.
  • I can't save a status. You may not have permission to change findings. Ask a subscription administrator.
  • "This finding cannot be opened." The finding may have been removed. Refresh the list.