Skip to content

Monitors

Monitors are automated checks that Oneleet runs on a schedule against your workspace’s assets, such as cloud resources, user accounts, devices, and vendors. Each monitor checks every asset it covers, reports a single status, and feeds the status of the compliance controls it backs.

Every compliance package includes monitors. Members and Auditors can view them, and Members can rerun them. Snoozing, disabling, changing settings, and ignoring or snoozing assets require the Admin role.

Monitors are listed on the Monitors page in the sidebar, grouped by status. To group them by the integration their assets come from, set Group by to Integration. Monitors whose assets come from Oneleet itself appear under Oneleet. Those assets include your compliance program data, domains, pentest engagements, and devices running the Oneleet agent. Monitors also appear on each integration’s page, on the Monitors tab of the Devices page, and on each device’s page.

You don’t create monitors yourself. Oneleet adds a monitor for each check behind your workspace’s controls once your workspace has a source for the assets it checks: an integration you’ve added or Oneleet itself. If no matching assets have been found yet, the monitor still appears, with the status No applicable assets.

When Oneleet introduces a new check, monitors added for it during its first week start out snoozed until the check is a week old, and the snooze reason gives the date the check was introduced. If your workspace is in an audit observation period, every newly added monitor starts out snoozed until 28 days after the observation period ends.

Monitors run every hour, and some also run when a relevant change happens in a connected integration.

A monitor’s status comes from its latest per-asset results:

  • Breaching SLA: at least one asset has been failing past its SLA deadline.
  • Alerting: at least one asset is failing.
  • Passing: every asset is passing.
  • No applicable assets: the monitor found no assets to check, or every asset it found is ignored or snoozed.
  • Pending: the monitor hasn’t run yet.
  • Snoozed: you’ve paused the monitor until a set date.
  • Disabled: the monitor is turned off until someone re-enables it.

Each asset has its own result using the same labels: Breaching SLA, Alerting, Passing, Ignored, or Snoozed.

The status flows through to your controls. A passing monitor counts as a passing check on each control it backs, and an alerting or breaching monitor counts as a failing one. When a monitor is snoozed, disabled, or has no applicable assets, its checks become inactive and don’t count either way.

Some monitors show a Passes by default badge. These check a property the provider already guarantees, so they always pass and have nothing to configure.

If your workspace has SLAs set up, each failing asset gets a deadline: the time it started alerting plus the number of hours your workspace allows for that kind of issue. You set those hours on the SLAs page. When no hours are set for an asset’s SLA type, its row says no SLA is set instead of showing a deadline.

A monitor is at risk once its earliest asset deadline is less than two days away. The Monitors page shows how long each monitor has until it breaches, and its default Most urgent sort puts the closest deadlines first. On a monitor’s page, a warning above the details links to the alerting assets.

Oneleet notifies subscribed workspace members when a monitor starts alerting, when it starts breaching SLA, and when a run finds it at risk of breaching. The at-risk warning is sent once per alerting period, so a monitor that stays alerting for a long time won’t warn again before a later deadline. For the full list of notifications, see Notifications.

  1. On the Monitors page, click Alerting or Breaching SLA to show only failing monitors.

  2. Click a monitor to open its page.

  3. Read How to remediate, then click Review issues to jump to the asset list filtered to Alerting. On a monitor that’s breaching SLA, this filter hides the breaching assets, so switch it to Breaching SLA to see them.

  4. In each asset row, hover over or click the Result or Results link to read why that asset failed. If the row has a View link, it opens the asset in the system it comes from.

  5. After you’ve fixed the issue, click Rerun monitor. The page updates on its own until the run finishes.

You can’t rerun Code security, Dependency scanning, Application security, or Attack surface monitors by hand. They update from Oneleet’s scans, and the tooltip on Rerun monitor links to the scan that feeds them.

To see how a monitor has changed over time, click View history. The history shows the outcome of recent runs and lists each time the monitor started alerting, passing, or breaching SLA, or was snoozed, along with the assets involved.

Snoozing pauses a monitor until a date you choose, then it resumes on its own. Disabling turns a monitor off until someone re-enables it, and asks you to set a date to review that decision. Both make the monitor’s checks on its controls inactive.

You can snooze or disable one monitor from the menu on its page, or several at once by selecting them on the Monitors page and using the action panel. Each snooze, unsnooze, enable, and disable is recorded in the workspace’s audit log.

  1. On the monitor’s page, open the menu and choose Snooze monitor.

  2. Pick a preset such as Next week, or Choose date… to pick a day on the calendar. Snoozes end at 9:00 AM your local time on the chosen day.

  3. Enter a Reason for snoozing and click Snooze monitor.

A snoozed monitor skips its scheduled runs, and its page shows when the snooze ends, who set it, and why. To end it early, click Unsnooze, which reruns the monitor right away. When a snooze ends on its own, the monitor shows Pending until its next scheduled run.

  1. On the monitor’s page, open the menu and choose Disable monitor.

  2. Enter a Reason for disabling.

  3. Under Review reminder, pick when you want to be reminded to review the monitor.

  4. Click Disable monitor.

When the review date arrives, Oneleet sends subscribed workspace members a reminder, and the monitor’s page says it’s due for re-review. Click Re-monitor now to turn it back on, or Keep disabled to update the reason and choose a new review date.

To re-enable a disabled monitor at any other time, open the menu and choose Re-enable now. Re-enable in… instead snoozes the monitor until the date you pick, after which it runs again.

When one asset shouldn’t count against a monitor, you can exclude it instead of pausing the whole monitor. Ignore removes the asset from the monitor’s results until you re-enable it. Snooze pauses alerts for the asset until a date you choose.

  1. On the monitor’s page, find the asset in the Assets section and open its action menu. To act on several assets, select their rows and use the action panel.

  2. Choose Ignore, or choose Snooze and pick a date.

  3. Enter a reason.

  4. To apply the change to every other monitor that currently checks the asset, switch on Ignore for all monitors or Snooze for all monitors. Snoozing across all monitors works on one asset at a time.

  5. Click Ignore asset or Snooze asset.

An asset can’t be ignored and snoozed at the same time, so choosing one clears the other. Either change reruns the monitor.

To bring an asset back, use Unsnooze or Re-enable now from its action menu. For an ignored asset, Re-enable in… snoozes it until the date you pick, after which it counts again. Expired asset snoozes clear on the monitor’s next run.

Some monitors have thresholds you can change, such as how many days an account can go without signing in before it counts as dormant, or how old a key can get before it should be rotated. To change one, edit the value in the Settings section of the sidebar on the monitor’s page and click Save.

  • Integration is missing permissions to run this monitor: the last run couldn’t read what it needed from the integration. Click Check connection status to review the connection.
  • Internal error: the last run didn’t finish. Check the connection status first. If the problem continues, contact Oneleet support and include the monitor’s URL, which the message lets you copy. If there’s an active status update for the integration, the message links to it, and problems on Oneleet’s side don’t count against your audit.
  • This monitor has been disabled for your organization by Oneleet: the monitor is disabled but is missing a reason or a review date. Checklist monitors show this message after someone turns off Employee checklists on the workspace’s Settings page.
  • Integration service disrupted or degraded, or Permissions update required: the integration behind the monitor has a known problem. Click View details to see the integration’s status.

When you remove a framework, monitors used only by that framework’s controls are archived, and monitors shared with other controls keep running. Past results stay on record either way.