SaaS Security Posture Management continuously audits SaaS app resources to identify compliance rule violations. The Findings page provides the status check on all the compliance rules, and SaaS apps resources. To view the Findings page, log in to your Netskope tenant and navigate to API-enabled Protection > Security Posture SaaS > Findings.
Rules tab aggregates the list of predefined or custom rules and templates. Under the Rules tab, the table displays the following information:
- Rule Name: Name of the rule.
- Status: A rule can be checked against multiple resources. The status of the rule is defined as follows:
- if all resources pass, the rule passes.
- if any resources fails, the rule fails.
- if all resources are unknown, the rule is unknown.
- Pass Rate: Pass percentage of compliance rules against a resource. Pass rate is calculated as passed resources divided by total resources.
- App Suite: Name of the SaaS app.
- App: Name of the application of the SaaS app.
- Compliance Standard: Gives a brief description of the compliance standard.
- Rule Name: The compliance rule name.
- Severity: The level of severity of the violation. There are four levels: Critical, High, Medium, and Low.
- Resource Type: The cloud resource type.
- # Failed Findings: Total number of resources that failed the rule.
- # Passed Findings: Total number of resources that passed the rule.
- # Failed Muted Findings: Total number of failed resources that are muted.
- # Total Findings: Total number of resources checked against a rule.
- # Total Instances: Total number of cloud app instances that are impacted by this rule.
- Rule ID: Unique ID of the rule in use.
Rule Details
Click on a rule to view detailed information about the rule. The Rule Detail side panel provides a detailed information like severity, description, definition, remediation guidelines, rule category and change log.
Click the Raw Findings tab to view the compliance findings of your rules and resources. This page provides an aggregated list of all the rules and resources that have failed, passed, remediated, and muted.
You can select one or more rules using the checkbox to mute or unmute rule(s). Click a rule name to get a detailed view of the rule.
Under the Raw Findings tab, the table displays the following information:
-
Status: Status of the rule when checked against the resource. If the resource contains rule violations, the rule status shows Failed.
-
Policy: Name of the security posture policy.
-
Severity: The level of severity of the violation. There are four levels: Critical, High, Medium, and Low.
-
App Suite: Name of the SaaS app.
-
App: Name of the application of the SaaS app.
-
Rule ID: Unique ID of the rule in use.
-
Resource Type: The cloud resource type.
-
Last Evaluation Time: The last evaluation time indicated the timestamp when the last evaluation happened.
-
Muted: Status if the rule-resource pair is muted.
-
Compliance Standard: Gives a brief description of the compliance standard.
-
Failing Since / Status Since: The column displayed depends on the selected Time setting.
-
When using Latest Results:
-
The Status Since column is displayed, indicating the date when the rule status was last changed (for example, from Passed to Failed, from Failed to Passed or finding first discovered).
-
The exported Raw Findings report includes the Status Since column.
All Status Since findings are fully populated starting evaluation from 24 Oct 2025.
-
-
When using As of Date:
-
The Failing Since column is displayed, indicating the date since the rule has been in a Failed state.
-
The exported Raw Findings report does not include the Failing Since column.
-
-

Export Raw Findings
You can export the Raw Findings in the CSV file format:
- Click on the Export button.
- Choose the columns to export, number of rows and name of the report in side panel.
- Click export to save the report. It will download the filtered data in a CSV format file on your system.

Click the Resources tab to view information on the cloud resources.

Under the Resources tab, the table displays the following information:
- Status: Status of the resource when checked for compliance. If the resource contains rule violations, the resource status shows Failed.
- Pass Rate: Pass percentage of the cloud resource against a rule.
- Resource Name & ID: The name and ID of the cloud resource.
- Resource Type: The cloud resource type.
- App Suite: Name of the SaaS app.
- App: Name of the application of the SaaS app.
- # Failed Findings: The total number of rules that failed against a resource.
- # Passed Findings: The total number of rules that passed against a resource.
- # Total Findings: The total number of rules checked against a resource.
- # Failed Muted Findings: Total number of failed rules that are muted.
You can click a resource name to get a detailed view of the cloud resource like resource type, cloud provider, Netskope instance name, region, compliance data, etc. See Resource Details to learn more.

Filters
Filters are individual to the tab. By default, the Rules, Raw Findings, and Resources tabs display the latest audit results. You can choose to view the results for a specific date.
You can filter the result displayed on the page by selecting Resource Type, Tags, and App Suite. To further narrow the result on the page, click Add Filter and select an option from the list.
You can choose to filter based on the following options:
- Status: Select Failed, Passed, or Unknown.
- Muted: Select Yes or No.
- Rule name: Select Rule Name and enter a rule name in the search field.
- Policy: Select security assessment policy from the list.
- Severity: Select a severity level. There are four levels: Critical, High, Medium, and Low.
- Compliance Standard: Select or search for a compliance standard. For example, NIST-CSF-1.1.
- Resource ID: Enter the resource ID of the cloud app. You can get the resource ID from the Raw Findings tab, then look for Resource Name & ID field.
- Resource Name: Select Resource Name and enter a resource name in the search field.
- App: Select the app of the cloud service provider.
- Instance ID: Unique ID of the SaaS account
- Instance Name: Select the name of the SaaS account instance that is used to connect the cloud app with Netskope.
Save Filters
- Click the Save as button to the right of the filter attributes to save the selected filetrs, give a filter name and save the filter.
- Click on Saved Filters > My Saved Filters to see the list of saved filters and use them.
- Click on Saved Filters > Shared With Me to see shared filters.
Mute Findings
You can mute failed assessments to indicate false positives or allow the DevOps team some time to remediate. The mute feature does the following:
- Automatically acknowledges any alerts generated from an assessment. The alerts are muted indefinitely, until you unmute or for a specific period of time. This allows you to grant a DevOps team a window of time to remediate the service configurations to get compliant.
- Excludes the failed resources (when muted) in computing the compliance score for a profile.
You can access the mute and unmute capabilities under API-enabled Protection > Security Posture IaaS > Compliance.
To mute a rule-resource pair,
- Click on Raw Findings tab.
- Click the More Options icon (…) to the right of the rule name and click Mute.
- In the Mute window, select how long you want to mute this finding. You can add a short label under Justification Label to justify why you’re muting this finding.
- Click Mute.
Since every finding has a corresponding Skope IT alert, muting a finding auto acknowledges the corresponding alert. You will stop receiving alerts related to failed rule-resource pairs until you click Unmute.


