Review the infrastructure definitions already in your project source.

IaC checks operate on authorized infrastructure and CI configuration brought into Workbench with the project source. They do not claim a live cloud-account inventory.

Keep configuration review inside the source boundary.

Provide the project source and select the approved coverage. Infrastructure and CI definitions in that source are evaluated in the same project context as the application assessment.

Workbench extensions and configured assessment modules

Review configuration findings with their source context.

A configuration result is reviewed with the project and source context that produced it. The result is not presented as proof that a remote account is currently exposed.

Read the infrastructure and CI source coverage

Workbench findings inventory for reviewing assessment results

Three steps from approved scope to a reviewable result.

  1. 1

    Provide authorized project source containing infrastructure or CI definitions.

  2. 2

    Select the enabled infrastructure coverage in Workbench.

  3. 3

    Review the source context before applying remediation.

Request the workspace that keeps assessment and evidence together.