Use policies, filters, and reports

Last updated: July 23, 2026

Use this article when you need to understand policy violations, narrow a view with filters, customize table columns, or find the right report.

Availability depends on your Cysmiq plan.

Policy basics

  • Policies: reusable rules Cysmiq evaluates against security data in a workspace.
  • Policy violations: records created when a policy matches a target.
  • Enforcement: Monitor records violations, Warn surfaces warning-level enforcement, and Block surfaces blocking enforcement for connected workflows.
  • Exceptions: waiver or accepted-risk states that explain why a violation is not handled normally.

How dependency policy results are scoped

  • Package-version and manifest results are evaluated separately for each repository, including repositories that share an application or environment.
  • Only current manifests, references, and dependency relationships contribute to dry-run and enforcement results.
  • A waiver or accepted-risk exception applies to every matching active violation for the same policy, scope, and target. Violations that were already resolved remain resolved.

Filters, columns, and saved views

  • Open Filters from table toolbars to narrow repositories, vulnerabilities, packages, manifests, scans, and other list views.
  • Use the column selector to show or hide fields for a table.
  • Use saved filters for recurring vulnerability workflows such as assigned work, exploitable findings, or high-priority triage.
  • Clear filters when counts or rows look unexpectedly empty.

Insights and reports

  • Insights brings security reports and trends together across repositories, applications, organizations, teams, and developers.
  • Use report controls such as report type, scope, scope item, time period, and comparison.
  • Some report results depend on the viewer's repository and organization permissions.

Canonical docs

For the maintained reference, see Policies, Policy violations, Package and manifest policies, Custom policies, Environments, Filtering, Managing columns, Saved filters, and Insights.

Contact support if

  • A policy violation does not match the policy behavior you expected.
  • Filters, saved filters, or columns do not persist or show the expected data.
  • A report is empty, missing scope options, or shows different counts for different users.