Categories
The category is the deterministic reason the finding was raised, and each one points at a different kind of problem.Statuses
The public API reports three statuses, and the dashboard’sacknowledged and
investigating steps stay internal to investigation.
openmeans the finding still needs attention.resolvedmeans the expected evidence arrived on time.resolved_latemeans the evidence arrived after the deadline, and the breach stays in the history.
Investigate a finding
Investigation lives in the dashboard, which means your event sender implements none of this workflow. The evidence reads in a fixed order:1
Confirm the reference
The issue matches one operation reference and one affected target.
2
Read the timeline
Event types, occurred times, received times, and expected stages sit side by side.
3
Choose the next action
The outcome is a corrected source workflow, a pending event worth waiting for, or an
investigation recorded through the dashboard or a supported API operation.