Findings
Findings surfaces specific, actionable posture gaps computed live from your consolidated asset data, each with an explanation of why it matters and a suggested remediation. This is distinct from the raw Vulnerabilities list, which shows scanner/EDR-reported CVEs specifically; Findings looks at coverage, configuration, lifecycle, and identity gaps across everything Navigator knows about your environment.
What’s checked today
- Coverage gaps: devices missing EDR, missing vulnerability scanner coverage, unmanaged (no MDM), no RMM coverage, or missing all three (“zero tooling”).
- Configuration: devices with disk encryption disabled.
- Lifecycle: devices running an unsupported/end-of-life OS, and devices that haven’t checked in recently (stale).
- Vulnerability: CVEs on CISA’s or VulnCheck’s Known Exploited Vulnerabilities (KEV) list, Critical/High severity vulnerabilities with an elevated EPSS exploitation-probability score, and the combination of both on the same finding.
- Identity: domain admin accounts without MFA enrolled.
Each finding lists exactly which of your assets triggered it, with a link straight to that asset’s own detail page.
A note on coverage-gap findings with no connector behind them yet
Some coverage findings, most notably “no RMM coverage,” don’t have a corresponding connector built in Navigator yet. Rather than hide these findings until that connector exists, Navigator shows them honestly: every device correctly appears as uncovered, since Navigator genuinely can’t see any RMM tooling on it. The count will start reflecting real coverage the moment you connect (or Navigator adds support for) a tool in that category. This is deliberate, not a bug: the goal is to make a real gap visible, not to hide it behind an artificial “not tracked yet” state.
Related pages
- Dashboard: the exposure breakdown that several of these same coverage gaps also feed.
- Devices, Users, Vulnerabilities: the underlying asset pages a finding’s affected assets link back to.