Automatic Findings Validation

How Cato auto-triage selects findings by source and severity, why empty selections cannot be enabled, and when validation pauses.

Automatic Findings Validation

Automatic Findings Validation is Cato: Guard's automated triage agent. When on, Cato evaluates new findings that match the sources and severities you select. It does not re-run the backlog.

This card is on Settings → AI.

What you configure

Expand the card.

Sources — which finding producers Cato may touch. The list is the live capabilities registry plus Hannibal and Romulus. If nothing has been saved, the default is nuclei.

Severities — Critical, High, Medium, Low, Info. Default is Critical only. Cato matches the selected severities exactly against the finding's status. Unselected severities stay on manual triage.

Enable rules

You cannot turn the switch on with zero sources or zero severities. The editor expands and tells you to pick at least one of each. Removing the last source or last severity while the feature is already on is also refused — the previous selection is kept.

Config edits autosave. The enable/disable flip is the change that toasts, and the toast states the scope that was saved.

Changes apply to findings that arrive after the save. Queued findings are not retroactively re-evaluated.

Budget

Cato spend is the Cato slice of Category Allocation, not Marcus and not Hannibal. A 0% Cato allocation pauses automatic validation the same way a $0 Hannibal slice pauses scheduled hunts. The switch is not flipped off.

Who can edit

Manage settings (Admin).

This article is only the Settings controls that decide which new findings Cato may pick up. Cato's promote/reject behavior is documented under AI Enablement.