Deciding What a Client Sees from a Scan
Two settings decide whether scan results go straight to the customer or wait for a tester to read them first, and one control fixes a run that landed on the wrong side of that choice.
A scan produces findings on an engagement. Whether the customer can see those findings is a decision your firm makes once, in settings, and can override on any individual finding. This guide is the two settings and the one control.
1. Where results land
Settings, then Scanning. The setting is where a self-service scan lands: straight to the customer, or in a holding area for a tester to read first.
| The choice, and what it costs | |
|---|---|
| Straight to the customer | A scan a customer runs appears in their portal when it finishes. Fastest, and right when the customer is running routine scans against their own approved assets. |
| Hold for review | Results wait until somebody at your firm releases them. Slower, and right if raw scanner output on your letterhead is a problem, which for most consultancies it is. |
Under hold for review, the Scans area shows a count of runs waiting and a Release to them button on each. Releasing records who did it and when, says what becomes visible before it does, and reports a partial release as partial.
Releasing changes visibility, not data. Nothing is rewritten, nothing is deleted, and a run cannot be released twice.
2. What an uploaded file does
Different setting, same screen: whether an imported file is visible to the client by default. This is a separate decision because it is a different situation. A tester uploading raw scanner output onto an engagement usually wants to write it up before anybody reads it, so the shipped default is not visible, and the per-finding switch is how individual results are published.
3. The lowest severity you keep
Also on that screen. Anything below the level you pick is not kept from a scan Pental runs, including the ones your customers start and anything on a schedule. An uploaded file is exempt and keeps everything in it, because you chose the file; the import screen lets you change the floor for that one upload and remembers it per client.
The default discards informational. If you want everything, say so here rather than assuming: informational findings are most of the volume from a web scanner and a client portal full of them is worse than no portal.
4. Fixing a run that landed wrong
On any finished run, when your firm does not hold results, the run page offers Show all to the client and Hide all from the client. That is how a scan imported under an older setting, or before you changed your mind, gets published or pulled back in one action rather than one row at a time. It tells you how many findings it changed, and reports a partial result as partial.
5. Per finding, always
Whatever the settings say, every finding carries its own Client Visible switch on the run and on the engagement. The settings decide the starting position; the switch is the final word. A finding you are still writing up stays off until you are ready.
A client sees a run and its findings only through their own portal login, and only the findings marked visible. There is no link that bypasses that, and no email that carries the detail: a scan notice sent to a customer carries counts and nothing else.
Run a Scan and Decide What They See
Scanning, the holding area and the client portal are all in the trial, on your own database.
Also Worth Reading
Creating Your Database and Installing the Schema
Four steps: create a Postgres project in your own account, run the setup SQL, register one auth hook, then connect the project to Pental. The hook is the step people miss.
SetupPutting Your Portal on Your Own Domain
One DNS record, then the portal verifies it and issues a certificate. Most failures are the same three causes, and the setup screen tells you which one you have hit.
ReportingMaking Your Word Template the One Pental Fills
Open the Document Builder, upload any document you already send, and let the AI take the last engagement out and place the fields; you check what it did and see the real pages before you save. Nothing asks you to know how a Word file is put together.