Baselines
Baselines define the trusted state for scoped paths. Strong baseline hygiene is the difference between high-signal alerts and noisy change feeds.
Create a baseline policy
- Choose target hosts or groups.
- Define include and exclude path patterns.
- Run an inventory scan.
- Review unexpected files before approval.
Approval workflow
Require dual control for production baselines. Capture who approved the change and why, then keep that context attached to future drift events.
Re-baselining
Schedule or manually refresh baselines after planned releases. Correlate re-baseline windows with change tickets so intentional updates do not open incidents.