Can I approve only some recommendations?
Yes. Selective authorisation, approval of individual findings and choosing no changes are explicit parts of the specified workflow.
Governance / Authorise → Remediate → Verify
Controlled security remediation means turning a finding into a bounded, authorised change, then proving the intended outcome. AI Defence is designed to recommend hardening actions, explain their operational impact and request explicit customer approval before applying them.
A customer can authorise the complete recommended bundle, selected remediation, individual findings or no changes. Each approval needs to be tied to identified targets and actions. Approval of a report is not an unrestricted grant to alter unrelated systems.
The full specification includes closing unnecessary ports, modifying firewall rules, disabling unsafe services, correcting permissions, patching software, removing insecure defaults and strengthening SSH or TLS configuration. Credential rotation, database hardening, container restrictions, logging improvements and isolation are also specified where supported and authorised.
The pre-change workflow establishes current state, determines dependencies and possible impact, prepares rollback, preserves connectivity and records the authorised action. It must account for administrator access and production workloads. If the current state no longer matches the approved plan, the action should return for reassessment.
A firewall change illustrates the requirement. Record the existing rules and management path, confirm the intended new access, arrange recovery and check the affected services. Removing an exposure while locking out the operator is not a verified successful outcome.
After remediation, AI Defence is designed to retest the vulnerability, exposure, service health, network accessibility, application health and security configuration relevant to the change. The result should preserve the evidence and distinguish success, failure and an inconclusive check.
An action that runs successfully but leaves the vulnerable process active remains unresolved. A security fix that breaks application health requires investigation and recovery. Unsupported actions must remain recommendations for an authorised operator, rather than being presented as automated capabilities.
Yes. Selective authorisation, approval of individual findings and choosing no changes are explicit parts of the specified workflow.
No. Database diagnostics and changes are separate. The intended model uses read-only evidence and governed, explicitly authorised changes with safe testing and verification.
Start with understanding
Discuss the assessment scope, current capabilities and the control you need with Altari Systems.