Symptoms
- An endpoint continues to show Policy Violations for a tool you've already authorized.
Cause
Governance decisions are recorded at the organizational level and applied going forward. They aren't retroactively applied to historical events.
Resolution
- Check the timing of the violation. If a Policy Violation occurred before you made the governance decision, that historical event remains in the activity feed and is not retroactively cleared.
- Confirm new activity reflects the update. Access events that occur after the authorization decision will reflect the updated governance status.
Back to AIDR guide.