Patching is table stakes. Proving it — per campaign, per endpoint, in a form an auditor accepts — is the job. Every lifecycle step in Shield-DM writes a record, so an evidence pack is one click, not one week.
Generated from live data, filterable, exportable to CSV and PDF.
Hardware, OS, owner, department, last seen and completeness — your system of record for endpoints.
Every package and application across the fleet, with version, source and affected-endpoint counts.
Compliant vs exposed, by OS, group and SLA — the headline an auditor or board wants first.
Scope, approval, execution timeline, per-endpoint outcome, failures, reboots, exceptions, sign-off.
Time-to-patch against policy, with breaches surfaced and justified by exception where accepted.
What's installed but not yet effective, with policy, deferrals used and SLA status per endpoint.
Failures with stage, code, message, category and retry count — the diagnostics, not just the red flag.
Accepted risks: reason, owner, approver, compensating control, expiry and review date.
The full per-machine timeline — every scan, job, result and reboot, retained for audit.
A campaign closes only when every target is successful, exception-approved, manually remediated, or explicitly excluded — and the pack proves which.
| When | Actor | Action |
|---|---|---|
| 09:14 | p.rao | Approved campaign #042 |
| 09:15 | system | Issued 214 signed jobs |
| 11:02 | a.menon | Approved exception · LEGACY-APP |
| 14:40 | p.rao | Closed campaign · evidence exported |
| 14:41 | auditor | Downloaded pack (read-only) |
USER · ACTION · TIMESTAMP · TARGET · OUTCOME — LOGGED FOR EVERY MATERIAL EVENT
Stand up the controller, enrol two endpoints, run a scan, and generate inventory and patch-compliance evidence — on your own infrastructure.