Skip to main content

Governance intelligence for access, cloud, and SaaS. Now in early access

Nuxari
Platform Operations

Remediation

Learn how to create, approve, execute, and close remediation plans for governance findings.

Last updated: June 2026

Who this is for

Admins and approvers managing governance findings and corrective actions in connected systems.

Before you start

A finding must exist before you can create a remediation plan. Findings are produced by control pack evaluations or detected as access drift. You need an admin role to create plans and an approver role (or higher) to authorize them.

What a remediation plan is

A remediation plan is a structured record of a corrective action. It defines what change will be made, in which system, for which user or resource, by whom, and with what authorization. Plans must be approved by a designated approver before Nuxari executes any action in a connected system.

The remediation lifecycle

  1. 1

    Create the plan from a finding

    Navigate to Governance > Findings. Click a finding to expand it, then click Create Remediation Plan. Nuxari pre-fills the proposed action based on the finding type. Review and confirm the details.

  2. 2

    Assign an approver

    Select an approver from your team. Only users with the approver role or higher appear in the list. The approver will receive a notification with the plan details and a link to review it.

  3. 3

    Approval review

    The approver reviews the plan, the finding context, the proposed action, and the affected resource. They can authorize or reject the plan. Nuxari records their decision as part of the audit trail.

  4. 4

    Snapshot before execution

    After approval, Nuxari takes a before-state snapshot of the affected resource in the connected system. This captures the exact state prior to any change.

  5. 5

    Execution

    Nuxari executes the approved action in the connected system. You can monitor progress in real time in Governance > Remediation.

  6. 6

    Validation

    After execution completes, Nuxari re-evaluates the finding to confirm the correction has held. If the finding is still present, the plan status updates to indicate partial or failed remediation.

  7. 7

    Evidence captured

    The complete workflow, finding, approval, before state, execution result, and after state, is bundled into an evidence record automatically. No manual documentation is required.

  8. 8

    Closure

    When validation confirms the finding is resolved, the plan is marked Completed and the finding is closed. The evidence record is finalized and available for export.

All high-impact actions require explicit approval before execution. The workflow engine will not proceed without a completed authorization record. This applies to any action that modifies access, removes users, rotates credentials, or changes configuration in a connected system.

What happens if execution fails

If Nuxari cannot complete the action in the connected system, for example, because a connector is temporarily unavailable or the system returns an error, the plan status updates to Failed. The failure is recorded in the audit log with the error context. Your team can review the failure, resolve the underlying issue, and re-attempt execution without needing to go through the approval process again.

Was this page helpful?