Automatic Findings Validation
How Cato auto-triage selects findings by source and severity, why empty selections cannot be enabled, and when validation pauses.
Automatic Findings Validation on Settings → AI controls Cato, Guard's automated triage agent. Card copy: Cato automatically validates new findings that match these criteria. Findings that were already in the queue are not re-evaluated.
What you configure
Expand the card to edit it.
- Sources: which capabilities' findings Cato may validate. The list is every Guard capability plus Hannibal and Romulus. If nothing has been saved, the source is nuclei.
- Severities: Critical, High, Medium, Low, Info. If nothing has been saved, only Critical is selected.
Findings from a source or severity you did not select are left for manual triage.
Enable rules
- You cannot turn the switch on with no sources or no severities. The card shows Automatic validation needs at least one severity and one source and keeps the switch off.
- While the switch is on, removing the last source or the last severity is refused and the previous selection is kept.
- Each change saves immediately. Turning the switch on shows a toast with the saved scope, for example Automatic validation on — Critical findings from 1 source.
Budget
Cato spends from the Vulnerability Validation slice of Category Allocation. When that slice is $0, the card shows Paused — category budget is $0 and validation stops. The switch stays on.
Who can edit
Users with permission to manage settings.