Skip to main content
Discovery

Guides for CMDB reviewers and auditors

Step-by-step procedures for working the review inbox, deciding topology links, deviations, ambiguous identities and absent CIs, and reading and sealing the attestation.

These guides are for the people who decide what Discovery proposes — CMDB administrators and platform owners — and for auditors, who read the results. Auditors hold read permissions only: every decision button is permission-checked on the server and refused for the auditor role. Source commissioning and access management are in Guides for administrators.

A typical daily round for a CMDB administrator is: review inbox → deviation queue (breaching first) → absent CIs → topology links → source health.

Work the review inbox

Purpose: see every discovery decision that waits for a person. Prerequisite: discovery.source.read.

  1. Open Assets & Risk → Discovery sources → Review inbox.
  2. Read the table: Decision (Software name, CPE mapping, Lifecycle mapping, Topology link), Subject, Waiting since, Assignee and From run.
  3. If a note says queues are hidden because your role cannot read them, ask an administrator for the missing permission.
  4. If the list is truncated, filter to see the rest.
  5. Work topology links on the same page (see Decide observed topology links).

Current limitation. Software-name, CPE-mapping and lifecycle-mapping items are listed but cannot yet be decided in the UI. Software normalisation, CPE and CVE correlation and end-of-life enrichment are not yet scheduled in the sweep.

Purpose: turn observed connections into governed CI relationships. Prerequisite: discovery.topology.decide.

  1. Open Assets & Risk → Discovery sources → Review inbox and go to Observed topology links.
  2. Check Observed edge, Type, From CI, To CI and Last seen.
  3. To accept one link, select Accept.
  4. To reject one link, select Reject, enter Reason (recorded with the decision) and confirm with Reject edge. Select Keep pending to leave it open.
  5. For several links, select their rows and choose Accept selected or Reject selected.

Afterwards: an accepted link appears as a relationship in the CMDB and the topology graph (see Relationships and impact). A rejected link is sealed in the audit chain and a later observation of the same edge does not reopen it.

Review and decide deviations

Purpose: decide which value is right when the CMDB and a source disagree. Prerequisite: discovery.deviation.manage (reading needs discovery.deviation.read).

  1. Open Assets & Risk → Discovery sources → Deviations. The page Verification and drift shows the Deviation queue.
  2. Read Configuration item, Attribute, CMDB says (Soll), Observed (Ist), Severity, State, Detected and Due. Select Open CI to look at the CI.
  3. To take ownership, select Acknowledge.
  4. To decide, select Resolve. Under Which value is right? choose Keep CMDB value or Accept observed value.
  5. Enter Why (required) and confirm with Resolve.
  6. If the deviation is a false alarm, select Not a deviation, enter the reason and confirm.

Afterwards: the deviation closes and TENSOR shows Decision recorded. Accepting the observed value updates the CI; keeping the CMDB value changes nothing. Both decisions and the reason are in the audit chain.

Tip. Keep CMDB value is preselected. If the system still differs, the next run opens a new deviation, so keeping the CMDB value is only final when you also fix the device or the source.

Find deviations that breach their SLA

Purpose: work the most urgent drift first. Prerequisite: discovery.deviation.read.

  1. Open Assets & Risk → Discovery sources → Deviations.
  2. Switch on Open only and Breaching SLA only.
  3. Work the rows marked SLA breached from the oldest Due date.

Note. An empty queue does not prove agreement. Either the estate matches the CMDB, or no source has observed it yet. Check source health before you read an empty queue as good news.

Resolve an ambiguous identity

Purpose: settle two CIs that claim the same identity so discovery can link its observations again. Prerequisite: CMDB reconciliation rights (for example cmdb_admin).

  1. Open Assets & Risk → Configuration Items → Reconciliation.
  2. Filter Status to Pending. Candidates raised by discovery carry the matching identifiers in Match basis.
  3. Select Review to open Compare candidates and read Why this was flagged.
  4. Choose Merge if both are the same asset (A is kept, B is retired, identifiers are combined), Mark distinct if they are different assets, or Dismiss.
  5. Optionally enter a Resolution note and confirm.

Important. Merging is audited and cannot be undone. Mark distinct is remembered: discovery will report later observations as blocked by split instead of raising the same question again.

The CMDB side of the queue is described in Reconciliation and import.

Decide absent CIs

Purpose: retire CIs that discovery no longer sees, or keep them. Prerequisite: discovery.tombstone.decide (reading needs discovery.tombstone.read).

  1. Open Assets & Risk → Discovery sources → Absent CIs. The page is titled Absent assets.
  2. Keep Undecided only switched on.
  3. For each row read Configuration item, Source record, Missed runs, Corroboration (Also absent from or Only source for this item) and Proposed.
  4. Select Retire to confirm the absence, or Keep if the absence was caused by the source.
  5. Confirm the dialog.

Afterwards: a retired CI moves to the retired lifecycle state. Its record, full history and discovery provenance stay. You can reverse it by setting the lifecycle state back on the CI.

Read the CMDB attestation

Purpose: answer how you know the CMDB reflects reality. Prerequisite: discovery.report.read (auditors hold it).

  1. Open Assets & Risk → Discovery sources → Attestation. The page is titled CMDB attestation.
  2. Read Denominator policy first: it states what is counted and why, and whether the tenant has ever changed the verification window.
  3. Compare Coverage at the effective window with Coverage at the seeded default window. If they differ, the window was widened.
  4. In Coverage by CI class, read In scope, Window (days), Verified (effective N), Verified (default N), Stale, Single-sourced and Excluded (open deviation).
  5. Check Single-sourced by construction: every CI is listed with its justification.
  6. Check Deviations (open deviations, Mean time to resolve) and Source freshness (last successful run, quarantined sources).

Current limitation. Independent confirmations are not yet written by the sweep, so the attestation shows no verified CIs. The verification-window policy has no screen yet. Do not present K4 Soll/Ist figures to an auditor before your pilot is complete — see Compliance.

Seal the attestation

Purpose: freeze the current attestation as immutable evidence for an audit. Prerequisite: discovery.report.export (not held by auditors).

  1. Open Assets & Risk → Discovery sources → Attestation and check the figures.
  2. Select Seal attestation.
  3. Read the confirmation: the report is stored as an immutable, hash-chained artifact and cannot be changed or deleted afterwards.
  4. Confirm.

Afterwards: the page shows that the report is sealed and the Audit chain head it is anchored to. The discovery_sources flag becomes sticky: switching it off now needs a dual-approval request.