Skip to content

IT and infrastructure

Security work that arrives ready to run.

You get handed vulnerability tickets written by people who will not be applying the fix. The fix should arrive written, tested against your patterns, and reversible.

What changes

What your week looks like

Left is the week you have. Right is the same week on the platform. Nothing else on this page matters more than whether the left column is recognisable.

  1. Security tickets describe a problem and leave the solution to you.

    The fix arrives authored as code against your own patterns, with the approver bound to the exact artifact SHA that runs.

  2. The same class of fix is written by hand, slightly differently, every month.

    Exposures that share a fix cluster into a pattern, so the authoring happens once and covers the cluster.

  3. Change windows are consumed by work that could have been automated.

    Execution runs on Kestra, canary first and then by ring, honouring the freeze windows already in ServiceNow.

  4. Rollback is improvised under pressure.

    The rollback plan is recorded before rollout, and a pulled kill switch shows who pulled it, when, and why, on every page.

Access

What you own, and what you can reach.

The platform has three roles, not six. This is the one you would hold, enforced at the route on the client and again on the server rather than hidden in the interface.

Platform role

Analyst

What it opens
The VERA workspace: the exposure queue, patterns, remediations, and the governance surfaces you schedule against.
What it does not
The approver matrix, SLA tiers, the environment registry and scoped service tokens live in VERA's own Admin area.

The measure

The numbers you would be judged on.

Published targets and platform behaviour, not projections. Where one of these is a target rather than an achievement, it says so.

  • 2h · 24h · 7d · 30d

    SLA tiers

    What you schedule against, instead of a wall of criticals.

  • Canary, then ring

    Every rollout

    A small batch proves the fix before the wider ring proceeds.

  • Bounded

    Blast radius

    Computed and enforced before rollout, not discovered during it.

  • 4

    Autonomy modes

    Manual, Assisted, Supervised, Automated. A pattern earns the next one.

Your workspaces

What you would actually open.

You can turn one on and add the others later. A connector configured for one is available to the rest.

Also part of this role

Coming soon

Network Policy Analyzer

Firewall rule analysis, segmentation review, and access-policy conflict detection.

Questions

The things people ask first.

  • Is anything pushed to my estate without me?

    Only where that pattern has earned the autonomy, which is set per environment and severity with a confidence bar gating the maximum mode. Even at the top of that ladder the rollout is canary first, freeze-aware, and bounded by a computed blast radius.

  • Does it run in my orchestrator or its own?

    Yours. Execution is Kestra, with Semaphore and GitHub in the loop for commits and pull requests, and change items in ServiceNow. Freeze windows are merged from ServiceNow and your tenant calendars rather than redefined.

  • What does the fix look like when it lands?

    An authored artifact against your own patterns, not a paragraph in a ticket. It carries the assets it will touch, the canary plan, the rollback plan, and the validation step that confirms the vulnerability is actually closed before the execution moves to done.

  • How is the priority decided, and can I argue with it?

    Known-exploited status, exploit probability, whether the asset is internet-facing, and asset criticality, banded Act, Attend or Track. Every risk and confidence chip opens the factor breakdown that produced it, so the ordering is arguable rather than asserted.