Skip to main content
{ Reporting and Compliance / Vulnerability Management }

Aikido Posture Report

Delivers a weekly report on Aikido coverage, what changed, and anything in the workspace that needs attention, from failing scans to plan limits.

What this agent does

This read-only agent checks the health of an Aikido Security workspace every week. It compares the repositories in the source code provider it is connected to with the repositories Aikido scans, and it finds repositories that are missing, disconnected, or no longer scanned. It summarizes the issues that appeared, were solved, or were ignored or snoozed since last week. It flags anything that needs an admin, such as a broken connection or usage close to the plan's limits.

The challenge

Aikido only protects the repositories and clouds it is connected to, and gaps in coverage are easy to miss. New repositories are never connected, a connection loses access, and scans stop without anyone noticing. Plan limits run out when the team grows. Admins find out when something breaks, not before.

The solution

The agent checks coverage, activity, and workspace limits in one pass each week and compares them with the previous week. It lists what changed and what someone needs to act on, with the fix for each item. Provides a weekly briefing an admin can read in a few minutes.

Workflow

  1. 01

    Check coverage

    Compare the organization's repositories with the repositories Aikido scans, and find the ones missing, disconnected, or not scanned recently.

  2. 02

    Check activity

    Summarize issues that appeared, were solved, or were ignored or snoozed since last week.

  3. 03

    Check the workspace

    Check source code and cloud connections, and usage against the plan's limits.

  4. 04

    Report

    Publish what changed and what needs action, with the fix for each item.

Agent template

# Aikido Posture Report

## Measurable outcomes

Every week, the admin knows which repositories Aikido is not covering, what changed in the workspace, and what needs action before it breaks. Track covered and uncovered repositories and open action items on every run.

## Procedure

Once a week, compare the active repositories in the connected source code provider, such as a GitHub organization, GitLab group, or Bitbucket workspace, with the repositories Aikido scans. List the repositories that are not connected, lost their connection, or have not been scanned in the last week, unless I set another window. Summarize the new Critical and High issues, the issues solved, and the issues ignored or snoozed since the last report, with the reason for each. Check each source code and cloud connection, and flag any that are failing. Compare usage with the plan's limits, and flag anything above 80 percent. Compare everything with last week's report, and lead with what changed. Give every action item the specific fix. Report a check it cannot run as not checked, never as fine.

## Requirements

It needs read-only Aikido API access to the workspace and read access to the list of repositories in that source code provider, and nothing more. It never changes Aikido settings, connections, or issues.