Findings
In progressTechnical details
brand_pointerpartner://innovate/brand/lab/v2026-05-01asset_pointerhttps://assets.innovate.test/pci/brand_reasonsnone
Partner brand service
Loading partner-owned brand manifest from /api/session/brand.
- Brand API
/api/session/brand- Boundary
- No browser tenant authority, brand override authority, theme mutation, asset upload, endpoint value, account identifier, physical id, secret, live-data path, or fallback browser storage.
Trusted tenant context
Tenant authority: trusted API session
Tenant: pci_tnt_innovate_lab; partner: innovate; stage: lab; registry version: 3.
No viewer authority inputs were used.
auth.session_refreshed
Module status
- Data Collection enabled / primary Data Collection is enabled by trusted session context.
- Monitoring enabled / integrated Monitoring is enabled by trusted session context.
Review findings and remediation workbench
Work reviewer findings and remediation steps from server-owned review APIs. The browser renders finding and plan metadata, but cannot choose tenant, finding, remediation, workflow task, evidence, or document authority.
Open findings
Needs attentionBlockers
Blocked — action neededAssessment readiness
Blocked — action needed| Finding guidance | Severity | State | Remediation plan | Action |
|---|---|---|---|---|
Review cannot complete until the trusted evidence metadata ref is present.Finding refs and controls
| Needs attentionmedium | Blocked — action neededunresolved blocker | In progressplanned pci_operator · Lab sample due date: 2026-05-15 Remediation refs
| Open remediation actions |
Service-backed review findings and remediation
Loading review findings and remediation plan from same-origin APIs.
Review service seams
read_api_findings/api/review/findingsread_api_remediation/api/remediation/planfinding_action_api/api/review/findings/acknowledgeremediation_action_api/api/remediation/plan/actionsrequest_policytrusted-session-no-query-no-body-no-viewer-finding-or-remediation-authorityboundaryNo browser tenant, entity, cycle, finding, remediation, workflow task, evidence, document, endpoint, account, physical id, restricted text, queue, notification, or live-data authority; no request bodies on read paths and no browser storage fallback.
| Finding guidance | Severity | State | Task refs | Action |
|---|
| Step | Status | Guidance | Action |
|---|
Resolve findings and move remediation
Operators can acknowledge the current review finding and queue the next remediation step through the same-origin API. The client submits action intent only; finding, plan, task, evidence, tenant, and cycle refs are server-derived.
Review action refs
finding_action_api/api/review/findings/acknowledgeremediation_action_api/api/remediation/plan/actionscsrf_cookie__Host-pt_pci_csrf
Last review API result
Waiting for operator action.