Docs

Baselines

Create, approve, and refresh known-good integrity baselines.

Baselines

Baselines define the trusted state for scoped paths. Strong baseline hygiene is the difference between high-signal alerts and noisy change feeds.

Create a baseline policy

  1. Choose target hosts or groups.
  2. Define include and exclude path patterns.
  3. Run an inventory scan.
  4. Review unexpected files before approval.

Approval workflow

Require dual control for production baselines. Capture who approved the change and why, then keep that context attached to future drift events.

Re-baselining

Schedule or manually refresh baselines after planned releases. Correlate re-baseline windows with change tickets so intentional updates do not open incidents.