Skip to main content
Discovery

Availability

The implementation status of every Discovery capability as of 24 September 2026 — available, partially available or planned.

Preview — not yet field-tested

Discovery has been built and tested with simulated data only. No real vendor tenant (scanner, Intune, cloud) has been connected in a customer environment yet. Run a pilot in a test tenant with two independent sources before you use Discovery for production decisions or audit evidence.

This table is the source of truth for what you can use today. Elsewhere in this section, capabilities marked Partially available carry their limitation next to the description, and capabilities marked Planned are not described as working.

Implementation status

Status on the main code line as of 24 September 2026:

CapabilityStatusNotes
Feature flag, menu entries, five Discovery pagesAvailableSources, Deviations, Review inbox, Absent CIs, Attestation.
Commissioning: connection test, observe-only approval, pause, retryAvailableMoving a source to active is supported by the service but has no button yet.
Run ledger with quarantine and change capsAvailableTables are not yet paginated or filterable.
Vulnerability scanner source (Tenable, Qualys, Rapid7)Partially availablePulls all pages and records CVEs; does not yet use the run ledger and commissioning gate.
Microsoft Intune source with consent checkPartially availablePulls, stages and uses the run ledger; not yet linked to CIs by the apply sweep.
Storing integration credentials in the UIPartially availableCredentials are stored encrypted; the integrations screen does not yet offer a field to enter them.
Cloud inventory (AWS, Azure, GCP)PlannedMapping and residency rules exist; no live cloud connection yet.
Entra, Citrix Cloud, on-premises AD sourcesPlannedIn development.
On-premises collectorPartially availableEnrollment and heartbeat exist behind discovery_collectors; minting tokens, management UI and all scan tiers are planned.
Reconciliation, precedence defaults, apply or reviewAvailableRuns for scanner sources in the hourly sweep.
Tenant precedence overridesPlannedService exists; no screen or API yet.
Bounded production apply (activate, preview, commit, compensate)Partially availableService and API exist; no screen yet.
Deviations with SLA and decision dialogAvailableCreated automatically by the sweep; decisions require a reason.
Independent verification of CIsPartially availableRules and staleness exist; confirmations are not yet written by the sweep, so the attestation shows no verified CIs.
Per-CI verification panel on the CI pagePlanned—
Attestation report and sealingAvailableVerification-window policy has no screen yet.
Absence counting and retirementAvailable—
Topology links to CI relationshipsAvailable—
Review inboxPartially availableLists software, CPE and lifecycle items, which cannot yet be decided in the UI.
Software normalisation, CPE and CVE correlation, EoL enrichmentPartially availableBuilt and tested; not yet scheduled in the sweep.
EU feed mirror (NVD, endoflife.date)Available—
Cloud region acknowledgement registerPartially availableRecorded, but not yet enforced before the first pull.
Works council / GDPR discovery packagePlannedPart of the collector plan.

What this means for a pilot

Reading the table together, these are the practical consequences for a pilot today:

  • Scanner sources are the path that runs end to end through reconciliation, precedence and apply or review, and they record CVEs. They do not yet pass through the commissioning gate or appear in the run ledger.
  • Intune exercises the commissioning ladder and the run ledger, but its observations are not yet linked to CIs.
  • Deviations, absent-CI decisions, topology links and sealing are available in the UI.
  • The attestation can be read and sealed, but it shows no verified CIs until independent confirmations are written by the sweep.
  • Production apply, the verification-window policy and tenant precedence overrides have no screen yet. Production apply is available through its service and API; tenant precedence overrides have no API either.
  • Do not present K4 Soll/Ist figures to an auditor before your pilot is complete — see Compliance.

Where each capability is described

CapabilityPage
Sources, commissioning, run ledger, collectorSources and commissioning
Reconciliation, precedence, apply or review, production applyReconciliation and apply
Deviations, verification, attestation, absence, review inbox, software and CVEs, topologyDeviations and attestation
Flags, data protection, background jobsHow it works