Availability
The implementation status of every Discovery capability as of 24 September 2026 — available, partially available or planned.
Preview — not yet field-tested
Discovery has been built and tested with simulated data only. No real vendor tenant (scanner, Intune, cloud) has been connected in a customer environment yet. Run a pilot in a test tenant with two independent sources before you use Discovery for production decisions or audit evidence.
This table is the source of truth for what you can use today. Elsewhere in this section, capabilities marked Partially available carry their limitation next to the description, and capabilities marked Planned are not described as working.
Implementation status
Status on the main code line as of 24 September 2026:
| Capability | Status | Notes |
|---|---|---|
| Feature flag, menu entries, five Discovery pages | Available | Sources, Deviations, Review inbox, Absent CIs, Attestation. |
| Commissioning: connection test, observe-only approval, pause, retry | Available | Moving a source to active is supported by the service but has no button yet. |
| Run ledger with quarantine and change caps | Available | Tables are not yet paginated or filterable. |
| Vulnerability scanner source (Tenable, Qualys, Rapid7) | Partially available | Pulls all pages and records CVEs; does not yet use the run ledger and commissioning gate. |
| Microsoft Intune source with consent check | Partially available | Pulls, stages and uses the run ledger; not yet linked to CIs by the apply sweep. |
| Storing integration credentials in the UI | Partially available | Credentials are stored encrypted; the integrations screen does not yet offer a field to enter them. |
| Cloud inventory (AWS, Azure, GCP) | Planned | Mapping and residency rules exist; no live cloud connection yet. |
| Entra, Citrix Cloud, on-premises AD sources | Planned | In development. |
| On-premises collector | Partially available | Enrollment and heartbeat exist behind discovery_collectors; minting tokens, management UI and all scan tiers are planned. |
| Reconciliation, precedence defaults, apply or review | Available | Runs for scanner sources in the hourly sweep. |
| Tenant precedence overrides | Planned | Service exists; no screen or API yet. |
| Bounded production apply (activate, preview, commit, compensate) | Partially available | Service and API exist; no screen yet. |
| Deviations with SLA and decision dialog | Available | Created automatically by the sweep; decisions require a reason. |
| Independent verification of CIs | Partially available | Rules and staleness exist; confirmations are not yet written by the sweep, so the attestation shows no verified CIs. |
| Per-CI verification panel on the CI page | Planned | — |
| Attestation report and sealing | Available | Verification-window policy has no screen yet. |
| Absence counting and retirement | Available | — |
| Topology links to CI relationships | Available | — |
| Review inbox | Partially available | Lists software, CPE and lifecycle items, which cannot yet be decided in the UI. |
| Software normalisation, CPE and CVE correlation, EoL enrichment | Partially available | Built and tested; not yet scheduled in the sweep. |
| EU feed mirror (NVD, endoflife.date) | Available | — |
| Cloud region acknowledgement register | Partially available | Recorded, but not yet enforced before the first pull. |
| Works council / GDPR discovery package | Planned | Part of the collector plan. |
What this means for a pilot
Reading the table together, these are the practical consequences for a pilot today:
- Scanner sources are the path that runs end to end through reconciliation, precedence and apply or review, and they record CVEs. They do not yet pass through the commissioning gate or appear in the run ledger.
- Intune exercises the commissioning ladder and the run ledger, but its observations are not yet linked to CIs.
- Deviations, absent-CI decisions, topology links and sealing are available in the UI.
- The attestation can be read and sealed, but it shows no verified CIs until independent confirmations are written by the sweep.
- Production apply, the verification-window policy and tenant precedence overrides have no screen yet. Production apply is available through its service and API; tenant precedence overrides have no API either.
- Do not present K4 Soll/Ist figures to an auditor before your pilot is complete — see Compliance.
Where each capability is described
| Capability | Page |
|---|---|
| Sources, commissioning, run ledger, collector | Sources and commissioning |
| Reconciliation, precedence, apply or review, production apply | Reconciliation and apply |
| Deviations, verification, attestation, absence, review inbox, software and CVEs, topology | Deviations and attestation |
| Flags, data protection, background jobs | How it works |