Remediation Zero

Every action this fleet takes is recorded here with the clock that produced it. Nothing on this page is summarised on the fleet's behalf.

reading firestore · refreshes every 30s

real elapsed · never falsified

33d 0h 24m

The orchestrator session has been alive this long in wall-clock time, since 2026-08-27 01:04. This number can only be earned by waiting.

scenario time · simulated

2026-09-15

The furthest point the simulation has reached. Where this runs ahead of wall clock, the gap is shown on every record rather than smoothed over.

remediated · confirmed absent

106

Findings this scan stopped reporting on an asset it had actually examined. Resolution ends the chase: the next cycle closes the ticket and the tracker issue with it.

unverifiable · not examined

102

Also absent, but nothing looked at their assets. Absence is not evidence here, so these stay open, still chased, still on the SLA clock.

rescan-01 examined 45 of 60 assets. A scan that reached nothing reports exactly what a fleet that fixed everything reports, so the manifest of what was examined is stored with the scan and every closure is checked against it.

findings 412assets 60owners 12decisions 107tickets 6human_queue 80sla_clocks 6idempotency 1089

This period

report-c1056

Written by the reporting agent from figures it was given and did not compute. The counts below are the ones it was handed, kept beside the prose so the narrative can be checked against them.

The human queue stands at 65 total items, requiring your attention to resolve 20 escalated unresolved findings and one expired acceptance. The reviewer disagreement rate is 65% across 91 rejections, driven by triage proposing severity levels unsupported by CVSS evidence and submitting vague remediation steps that omit specific versions.

We remediated 36% of scanned findings, but our scan coverage rate is 75% of the estate (45 out of 60 assets), leaving 102 findings unverifiable. Because the unverifiable findings nearly match the 106 resolved findings, scan coverage remains the primary bottleneck.

The queue has no SLA breaches out of 2 tracked items, and active exceptions are at zero, with no new escalations this period.

reviewer disagreement 65% 91 rejections of 139 verdicts
ratified 53% 48 of 90 decisions
needing a person 65 0 SLA breached

Human queue

80 waiting

The terminal state for anything the fleet could not resolve safely. No agent reads from here; a person does. A finding arriving here is a successful outcome, not a failure.

FindingReason classWhat happenedRecorded
RZ-0046 escalated unresolved Escalated and still unresolved 1 simulated days past the SLA. The fleet has no further action that does not involve a person. 2026-09-16 09:00
RZ-0054 adjudication rejected twice; a person decides 2026-08-31 22:13
RZ-0053 adjudication rejected twice; a person decides 2026-08-31 22:13
RZ-0052 adjudication rejected twice; a person decides 2026-08-31 22:13
RZ-0051 adjudication rejected twice; a person decides 2026-08-31 22:12
RZ-0045 adjudication rejected twice; a person decides 2026-08-31 22:07
RZ-0044 adjudication rejected twice; a person decides 2026-08-31 22:07
RZ-0043 adjudication rejected twice; a person decides 2026-08-31 21:23
RZ-0041 adjudication rejected twice; a person decides 2026-08-31 21:22
RZ-0043 adjudication rejected twice; a person decides 2026-08-31 21:19
RZ-0042 adjudication rejected twice; a person decides 2026-08-31 21:18
RZ-0041 adjudication rejected twice; a person decides 2026-08-31 21:18
RZ-0216 adjudication rejected twice; a person decides 2026-08-31 12:02
RZ-0043 adjudication rejected twice; a person decides 2026-08-31 11:58
RZ-0041 adjudication rejected twice; a person decides 2026-08-31 11:57
RZ-0043 adjudication rejected twice; a person decides 2026-08-29 23:49
RZ-0012 adjudication rejected twice; a person decides 2026-08-29 23:43
RZ-0011 adjudication rejected twice; a person decides 2026-08-29 23:43
RZ-0020 escalated unresolved Escalated and still unresolved 3 simulated days past the SLA. The fleet has no further action that does not involve a person. 2026-08-28 02:232026-09-07 02:23simulation ahead by 10d
RZ-0021 adjudication rejected twice; a person decides 2026-08-28 02:19
RZ-0003 escalated unresolved Escalated and still unresolved 3 simulated days past the SLA. The fleet has no further action that does not involve a person. 2026-08-28 01:272026-09-07 01:27simulation ahead by 10d
RZ-0001 escalated unresolved Escalated and still unresolved 3 simulated days past the SLA. The fleet has no further action that does not involve a person. 2026-08-28 01:272026-09-07 01:27simulation ahead by 10d
RZ-0101 adjudication rejected twice; a person decides 2026-08-28 01:27
RZ-0002 adjudication rejected twice; a person decides 2026-08-28 01:26
RZ-0320 adjudication rejected twice; a person decides 2026-08-27 20:43
RZ-0302 adjudication rejected twice; a person decides 2026-08-27 20:05
RZ-0250 adjudication rejected twice; a person decides 2026-08-27 17:03
RZ-0216 adjudication rejected twice; a person decides 2026-08-27 15:55
RZ-0215 adjudication rejected twice; a person decides 2026-08-27 15:54
RZ-0204 adjudication rejected twice; a person decides 2026-08-27 15:53
RZ-0203 adjudication rejected twice; a person decides 2026-08-27 15:53
RZ-0202 adjudication rejected twice; a person decides 2026-08-27 15:52
RZ-0101 adjudication rejected twice; a person decides 2026-08-27 15:16
RZ-0002 adjudication rejected twice; a person decides 2026-08-27 15:15
RZ-0140 adjudication rejected twice; a person decides 2026-08-27 15:07
RZ-0121 adjudication rejected twice; a person decides 2026-08-27 15:03
RZ-0354 adjudication rejected twice; a person decides 2026-08-27 06:32
RZ-0353 adjudication rejected twice; a person decides 2026-08-27 06:26
RZ-0350 adjudication rejected twice; a person decides 2026-08-27 06:12
RZ-0343 adjudication rejected twice; a person decides 2026-08-27 05:27
RZ-0341 adjudication rejected twice; a person decides 2026-08-27 05:26
RZ-0216 adjudication rejected twice; a person decides 2026-08-27 03:47
RZ-0216 adjudication rejected twice; a person decides 2026-08-27 03:46
RZ-0216 adjudication rejected twice; a person decides 2026-08-27 03:46
RZ-0216 adjudication rejected twice; a person decides 2026-08-27 03:46
RZ-0216 cycle failure Adjudication did not complete: CapacityError: triage model unavailable after 4 attempts: 429 RESOURCE_EXHAUSTED. {'error': {'code': 429, 'message': 'Resource exhausted. Please try again later. Please refer to https://cloud.google.com/vertex-ai/generative-ai/do 2026-08-27 03:45
RZ-0216 adjudication rejected twice; a person decides 2026-08-27 03:44
RZ-0216 adjudication rejected twice; a person decides 2026-08-27 03:44
RZ-0216 adjudication rejected twice; a person decides 2026-08-27 03:43
RZ-0216 adjudication rejected twice; a person decides 2026-08-27 03:42
RZ-0216 adjudication rejected twice; a person decides 2026-08-27 03:41
RZ-0216 adjudication rejected twice; a person decides 2026-08-27 03:39
RZ-0312 adjudication rejected twice; a person decides 2026-08-27 03:16
RZ-0330 acceptance expired Risk acceptance lapsed after 90 simulated days. Accepted by own-004 because: Host isolated on an air-gapped segment, decommission scheduled. The finding was never remediated and returns for re-adjudication. 2026-08-27 03:142026-11-30 03:14simulation ahead by 95d
RZ-0330 acceptance refused This CVE is in the CISA KEV catalog, meaning it is being exploited in the wild. The fleet does not accept that risk on its own. Route to a person for approval. 2026-08-27 03:14
RZ-0320 adjudication rejected twice; a person decides 2026-08-27 02:58
RZ-0311 adjudication rejected twice; a person decides 2026-08-27 02:40
RZ-0310 adjudication rejected twice; a person decides 2026-08-27 02:40
RZ-0302 adjudication rejected twice; a person decides 2026-08-27 02:37
RZ-0301 adjudication rejected twice; a person decides 2026-08-27 02:37

SLA clocks

6 tracked

Deadlines run in scenario time so a six-week window can be demonstrated in minutes. The start time is recorded in both clocks and the wall-clock reading is never adjusted to match.

FindingOwnerStatusDeadlineStarted
RZ-0050 own-005 breached due 2026-09-07 22:10 2026-08-31 22:10
RZ-0042 own-010 open due 2026-09-14 21:22 2026-08-31 21:22
RZ-0046 own-005 breached due 2026-09-14 22:07 2026-08-31 22:07
RZ-0047 own-006 open due 2026-09-14 22:10 2026-08-31 22:10
RZ-0048 own-012 breached due 2026-09-14 22:10 2026-08-31 22:10
RZ-0049 own-004 breached due 2026-09-14 22:10 2026-08-31 22:10

Decision log

107 recorded

Triage runs on Gemini and proposes. The reviewer runs on Gemma, a different model family, and must ratify or reject with a stated reason. The rejections are kept: a decision log containing only agreements would be indistinguishable from one produced without a reviewer.

FindingOutcomeProposal and adjudicationRecorded
RZ-0054
cycle 1076
human queue critical · SLA 7d
Upgrade PAN-OS to a version later than 7.1.18, 8.0.11-h1, or 8.1.2 to patch the Remote Code Execution vulnerability in GlobalProtect.
cites: CISA KEV catalog, FIRST EPSS, NVD
reviewer · rejected

The proposed severity of critical is not supported by the evidence, as the CVSS base score is 8.1 (High) and the scanner rated it medium.

reviewer · rejected

The proposed severity of critical is not supported by the evidence, as the CVSS base score is 8.1 (High) and the scanner rated it medium.

2026-08-31 22:13
RZ-0053
cycle 1076
human queue high · SLA 7d
Apply the appropriate vendor security updates to patch CVE-2021-33742.
cites: CISA KEV catalog, FIRST EPSS, NVD
reviewer · rejected

The remediation is vague and does not provide specific version information or actionable steps.

reviewer · rejected

The remediation is vague and does not provide specific version information or actionable steps.

2026-08-31 22:13
RZ-0052
cycle 1076
human queue high · SLA 14d
Apply the vendor-provided security patch for CVE-2026-21513 and restrict access to port 5432.
cites: CISA KEV catalog, FIRST EPSS, NVD
reviewer · rejected

The remediation is vague and does not specify the required version or package to upgrade.

reviewer · rejected

The remediation is vague and does not specify the required version or package to upgrade.

2026-08-31 22:13
RZ-0051
cycle 1076
human queue high · SLA 14d
Upgrade Exim to version 4.70 or later to resolve the heap-based buffer overflow vulnerability.
cites: CISA KEV catalog, FIRST EPSS, NVD
reviewer · rejected

The proposed SLA of 14 days exceeds the CISA KEV due date of 2022-04-15.

reviewer · rejected

The proposed SLA of 14 days exceeds the CISA KEV due date of 2022-04-15.

2026-08-31 22:12
RZ-0050
cycle 1076
ratified critical · SLA 7d
Apply the vendor-provided security updates for CVE-2024-55591 immediately, or isolate the workstation from the production network until it can be patc
cites: CISA KEV catalog, FIRST EPSS, NVD
reviewer · rejected

The remediation is vague and does not specify the required version or package to upgrade.

reviewer · ratified

The critical severity is justified by the high CVSS, extremely high EPSS, and CISA KEV status, while the remediation provides actionable steps.

2026-08-31 22:10
RZ-0049
cycle 1076
ratified high · SLA 14d
Apply the appropriate firmware updates provided by SonicWall for SMA100 to patch the CVE-2019-7483 directory traversal vulnerability.
cites: CISA KEV catalog, FIRST EPSS, NVD
reviewer · ratified

The severity and SLA are consistent with the KEV status and CVSS score, and the remediation provides specific guidance for the affected device.

2026-08-31 22:10
RZ-0048
cycle 1076
ratified high · SLA 14d
Upgrade the Linux kernel to version 3.8.9 or later, or apply the appropriate vendor security patch.
cites: CISA KEV catalog, FIRST EPSS, NVD
reviewer · ratified

The severity and SLA are appropriate given the CISA KEV status and high EPSS score, and the remediation provides specific version requirements.

2026-08-31 22:10
RZ-0047
cycle 1076
ratified high · SLA 14d
Upgrade macOS to Mojave 10.14 or later, or apply the appropriate security updates for the affected operating system.
cites: CISA KEV catalog, FIRST EPSS, NVD
reviewer · ratified

The severity is supported by the CISA KEV status and CVSS score, and the remediation provides specific OS versions to upgrade to.

2026-08-31 22:10
RZ-0046
cycle 1076
ratified high · SLA 14d
Apply the latest security updates provided by Trend Micro for Apex One, Apex One as a Service, OfficeScan, and Worry-Free Business Security to patch t
cites: CISA KEV catalog, FIRST EPSS, NVD
reviewer · rejected

The remediation is vague and does not specify the required version or package to upgrade to.

reviewer · ratified

The severity is justified by the CISA KEV status despite low asset criticality, and the remediation provides clear guidance for the identified vulnerability.

2026-08-31 22:07
RZ-0045
cycle 1076
human queue critical · SLA 7d
Apply the official Adobe security patches (such as MDVA-43395) or upgrade Adobe Commerce to a secure, supported version.
cites: CISA KEV catalog, FIRST EPSS, NVD
reviewer · rejected

The remediation is vague and does not specify the required version upgrade to resolve the vulnerability.

reviewer · rejected

The finding reports a vulnerability in Adobe Commerce (web application) on port 3389 (RDP), which is a mismatch of service and vulnerability.

2026-08-31 22:07
RZ-0044
cycle 1076
human queue high · SLA 14d
Apply vendor-provided security patches for CVE-2025-15556.
cites: CISA KEV catalog, FIRST EPSS, NVD
reviewer · rejected

The remediation is vague and does not provide specific version information or actionable steps.

reviewer · rejected

The remediation "Apply vendor-provided security patches" is too vague to be actionable.

2026-08-31 22:07
RZ-0043
cycle 1096
human queue high · SLA 14d
Apply the latest Linux kernel security updates to resolve the HID core report buffer information disclosure vulnerability (CVE-2024-50302).
cites: CISA KEV catalog, FIRST EPSS, NVD
reviewer · rejected

The proposed severity of "high" is not supported by the evidence, as the scanner's own CVSS is 6.1 (Medium) and the EPSS is low.

reviewer · rejected

The proposed high severity is not supported by the evidence, as the CVSS is medium and the asset is a low-criticality development machine.

2026-08-31 21:23
RZ-0042
cycle 1096
ratified high · SLA 14d
Apply the appropriate Microsoft security updates for CVE-2019-1215 to patch the ws2ifsl.sys driver.
cites: CISA KEV catalog, FIRST EPSS, NVD
reviewer · ratified

The high severity is justified by the CISA KEV status and ransomware association, and the remediation is actionable.

2026-08-31 21:22
RZ-0041
cycle 1096
human queue high · SLA 14d
Apply the relevant security updates or patches provided by the vendor to address CVE-2016-3643.
cites: CISA KEV catalog, FIRST EPSS, NVD
reviewer · rejected

The remediation is vague and does not provide specific version information or actionable steps.

reviewer · rejected

The remediation is vague and does not specify the required package or version to upgrade.

2026-08-31 21:22

Ticket lifecycle

6 recorded

What chase did, and how long it really took. The two figures in the last column are the honest pair: minutes actually elapsed, against the days of scenario being demonstrated.

FindingOwnerStatusTrailElapsed
RZ-0042 own-010 resolved open_ticket → close_ticket → nudge → nudge 5.6 min real 8 days simulated
RZ-0046 own-005 with human open_ticket → nudge → nudge → nudge → escalate → human_queue 22239.6 min real 15 days simulated
RZ-0047 own-006 resolved open_ticket → close_ticket → nudge → nudge 5.7 min real 8 days simulated
RZ-0048 own-012 with human open_ticket → nudge → nudge → nudge → escalate → human_queue 22239.6 min real 15 days simulated
RZ-0049 own-004 with human open_ticket → nudge → nudge → nudge → escalate → human_queue 22239.6 min real 15 days simulated
RZ-0050 own-005 with human open_ticket → nudge → nudge → nudge → escalate → human_queue 5.7 min real 10 days simulated