1
Set workspace policy
Risk policy defines the baselines and thresholds Ordantra should evaluate for the selected workspace. Tune it to the environment rather than accepting irrelevant alert volume.
- Keep Windows and Linux agent baselines platform specific.
- Review posture thresholds when security tooling or patch policy changes.
- Use policy changes deliberately because they affect findings across the workspace.
2
Read a finding
Open the finding and affected asset together. Check the evidence, inventory collection time, agent version and last successful heartbeat before deciding priority.
- Separate unavailable data from an observed failure.
- Use asset and relationship context to understand impact.
- Confirm whether remediation is endpoint work, service work or an accepted exception.
3
Create accountable work
Important findings can become linked tickets. The ticket carries the asset relationship and gives the team ownership, priority, discussion and resolution history.
- Avoid creating duplicate tickets for the same unresolved evidence.
- Link change work when remediation needs controlled rollout.
- Record validation evidence before treating the risk as resolved.