SLA Policy
Path: /admin/sla · Sidebar: Administration → SLA Policy
SLA policy defines how long you have to remediate a finding based on its severity. These deadlines drive the SLA-breached KPIs and the remediation reports.
Configure SLAs
Set a remediation window per severity, for example:
| Severity | Example SLA |
|---|---|
| Critical | 7 days |
| High | 30 days |
| Medium | 90 days |
| Low | 180 days |
You can vary SLAs by environment/criticality so production-critical apps get tighter deadlines.
How SLAs are used
- Each vulnerability gets a due date = discovery date + SLA window.
- SLA-breached counts appear on the Dashboard and Priorities.
- The Remediation & SLA report tracks overdue items and MTTR by team.
Make SLAs achievable
SLAs only help if teams can meet them. Set windows your teams can realistically hit, then tighten as MTTR improves - perpetually-breached SLAs lose their meaning.