Step one: the alert
Every failed control produces an alert with its severity, the affected provider, account, service and region. Alerts are searchable and filterable, so a reviewer can go from a portfolio-wide view down to a single failing control on a single resource.

Step two: the case, with a service level
Opening a case attaches an owner and a service level to the alert. From that point the finding is accountable work, not a line in a report — it has someone responsible and a clock running against it.
- New → Investigating → Contained → Resolved status on the case board
- Named owner and service level attached at the moment the case opens
- Auditable false-positive path when a finding does not apply
The full journey, visualized
The remediation journey view lays out the whole cycle as a flow: alerts by severity feeding into cases, cases moving through status, and each case ending either resolved or still open against its service level. It is the same data as the alerts and remediation screens, arranged to show the cycle rather than a single stage of it.
