Workflow

Deciding What a Client Sees from a Scan

Two settings decide whether scan results go straight to the customer or wait for a tester to read them first, and one control fixes a run that landed on the wrong side of that choice.

3 min read

A scan produces findings on an engagement. Whether the customer can see those findings is a decision your firm makes once, in settings, and can override on any individual finding. This guide is the two settings and the one control.

1. Where results land

Settings, then Scanning. The setting is where a self-service scan lands: straight to the customer, or in a holding area for a tester to read first.

The choice, and what it costs
Straight to the customerA scan a customer runs appears in their portal when it finishes. Fastest, and right when the customer is running routine scans against their own approved assets.
Hold for reviewResults wait until somebody at your firm releases them. Slower, and right if raw scanner output on your letterhead is a problem, which for most consultancies it is.

Under hold for review, the Scans area shows a count of runs waiting and a Release to them button on each. Releasing records who did it and when, says what becomes visible before it does, and reports a partial release as partial.

Releasing changes visibility, not data. Nothing is rewritten, nothing is deleted, and a run cannot be released twice.

2. What an uploaded file does

Different setting, same screen: whether an imported file is visible to the client by default. This is a separate decision because it is a different situation. A tester uploading raw scanner output onto an engagement usually wants to write it up before anybody reads it, so the shipped default is not visible, and the per-finding switch is how individual results are published.

3. The lowest severity you keep

Also on that screen. Anything below the level you pick is not kept from a scan Pental runs, including the ones your customers start and anything on a schedule. An uploaded file is exempt and keeps everything in it, because you chose the file; the import screen lets you change the floor for that one upload and remembers it per client.

The default discards informational. If you want everything, say so here rather than assuming: informational findings are most of the volume from a web scanner and a client portal full of them is worse than no portal.

4. Fixing a run that landed wrong

On any finished run, when your firm does not hold results, the run page offers Show all to the client and Hide all from the client. That is how a scan imported under an older setting, or before you changed your mind, gets published or pulled back in one action rather than one row at a time. It tells you how many findings it changed, and reports a partial result as partial.

5. Per finding, always

Whatever the settings say, every finding carries its own Client Visible switch on the run and on the engagement. The settings decide the starting position; the switch is the final word. A finding you are still writing up stays off until you are ready.

A client sees a run and its findings only through their own portal login, and only the findings marked visible. There is no link that bypasses that, and no email that carries the detail: a scan notice sent to a customer carries counts and nothing else.

Run a Scan and Decide What They See

Scanning, the holding area and the client portal are all in the trial, on your own database.


Also Worth Reading