Wiz found it. Tamnoon refuses, or proves it safe and closes it.

Add context and correlate Wiz alerts to trace them back to their root cause, offering clearer insights for resolving the underlying issues.

No scanner to replace. No contract to end.
Nothing to install in production.

Wiz Issues, plus the context that decides them Safe
Risky
Awaiting data

Wiz found it in minutes. The finding is still open in month five.

53 percent of everything ever detected is still open. The State of Cloud Remediation 2026, 14.86M detections across hundreds of enterprise environments.

Wiz alone

Wiz plus Tamnoon

A toxic combination surfaces

Attack path drawn on the Security Graph, severity set

The finding
The probe column

The path is walked read-only, each hop rated

Identical Issues

One rule, one answer

The finding

Six buckets, three answers

Safe: the repair seam

Safe

Risky: the boundary buoy

Risky

Awaiting data: the observation disc

Awaiting data

What cannot be proven safe

Stays in the queue

The finding
Risky: the boundary buoy

Risky

Declined, with the reason attached

What can

Waits for an engineer

The finding
Safe: the repair seam

Safe

Closed on your execution plane

Next month

The same 8 findings

The finding
The guardrail closing

Guardrail closed the class

After detection, three questions are left standing:

What is left in the Issue queue is the residue: findings where the safe answer depends on live traffic, an unresolved owner, or a dependency no rule can see. It reads the Issue, investigates read-only, and returns one of three answers, each carrying its evidence.

The probe column at the waterline

Is this fix safe here?

The owner current

Who answers for it?

The guardrail arc

Will it stay closed?

A Wiz Issue, after the engine has read it.

The queue carries the environment facts that decide the answer. The record carries the change, the owner, the rollback and where it lands in your ticketing.

RecommendationRestrict public access on a production database
Made with Tamnoon
Environment
PROD
Exposure
Public
Encryption
True
Resource
RDS
Crown jewel
1
Owner
J. Doe
ScannerSeverityFindingEnvironment factVerdict
WizCriticalPublicly exposed database in productionno requests in 90 daysSafe
WizHighToxic combination: exposed workload, permissive service account2 services, live trafficRisky
WizMediumStale IAM access key on the owning roleowner unresolvedAwaiting data
Create an initiative from this recommendation? AcceptReject
TMN-30117 · Storage bucket missing data protectionSafe to remediate
RecordEvidenceTicket
PriorityInvestigatedCloud providerAssetStatusLands in
Mediumread-only, 07:40AWSs3-media-prod-041Safe
Jira

Read-only investigation runs before anything is proposed, and it is the evidence attached to whichever answer comes back. Identifiers on this page are fictional.

Three Wiz Issues. Three different answers.

TMN-30114Wiz
Wiz Issue: S3 bucket allows public read. The graph shows no attached policy, and access logs show no requests in 90 days.
Investigatedread-only, 07:40
ChangePUBLIC → PRIVATE
Rollbackready before execution
Safeclosed 07:41

Closed at machine speed on your audit trail. Rescan clean.

TMN-30114
Wiz
Wiz Issue: S3 bucket allows public read. The graph shows no attached policy, and access logs show no requests in 90 days.
Investigated
read-only, 07:40
Change
PUBLIC → PRIVATE
Rollback
ready before execution
Safe closed 07:41

Closed at machine speed on your audit trail. Rescan clean.

TMN-30115Wiz
Identical rule, identical severity. This bucket sits on a live attack path: two services read it over HTTP right now.
Investigatedread-only, 07:40
Dependents2 services, live
Changenot executed
Riskydeclined 07:41

Refused, with the reason. The change that would have caused the 3am page was refused at two.

TMN-30115
Wiz
Identical rule, identical severity. This bucket sits on a live attack path: two services read it over HTTP right now.
Investigated
read-only, 07:40
Dependents
2 services, live
Change
not executed
Risky declined 07:41

Refused, with the reason. The change that would have caused the 3am page was refused at two.

TMN-30116Wiz
Toxic combination: EC2 instance on IMDSv1 with a permissive instance role. The owning team cannot be resolved from tags.
Investigatedread-only, 07:40
Ownerunresolved
Changenothing touched
Awaiting dataasked 07:41

A third answer, chosen. Ownership could not be resolved, so nothing was touched and the missing context was requested. It does not guess.

TMN-30116
Wiz
Toxic combination: EC2 instance on IMDSv1 with a permissive instance role. The owning team cannot be resolved from tags.
Investigated
read-only, 07:40
Owner
unresolved
Change
nothing touched
Awaiting data asked 07:41

A third answer, chosen. Ownership could not be resolved, so nothing was touched and the missing context was requested. It does not guess.

Identifiers fictional · one healed never travels without the declines beside it

Tamnoon reads Wiz findings.

Through the Wiz integration, read scope only. No scanner change, no re-scan, no second agent in production.

Tamnoon investigates before it touches anything.

Live traffic, usage, dependencies and ownership, all read-only.

Tamnoon executes through your change process.

Under your IAM policies, on your audit trail, with rollback defined first.

Tamnoon carries over when you switch.

Move to or from Wiz and every judgment already made comes with you.

Tamnoon executes through your change process, not around it.

Findings from your scanner, context from your cloud, changes on your execution plane.

Moving to Wiz? The judgments move with you.

Tamnoon ran the migration: custom Wiz policies, alerting rules and workflows written on the way in, and every judgment already made carried over, published February 2025. Read the published case study.

What teams running Wiz ask first.

How is this different from self-healing infrastructure?
+

Self-healing infrastructure restores desired state: a pod restarts, an instance is replaced, a group scales back up. It is availability automation and it exercises no judgment about safety. Tamnoon heals the security posture instead: it investigates the finding in context, decides whether a change is safe to make at all, refuses what it cannot prove, and leaves the receipt behind. Restarting a pod is not the same as knowing which bucket must stay public.

How is this different from Wiz’s own remediation?
+

Wiz automates hygiene on its own findings. Tamnoon works on what remains after that. It investigates each Issue read-only in your live environment, groups things together to increase efficiency of each action instead of going a single Issue at a time, closes what it can prove safe through your own change process, declines what it cannot with the evidence why, and answers for the outcome.

Do we have to change our Wiz setup?
+

No. Tamnoon sits downstream of the Wiz you already run, reading Issues through the integration with read scope. No scanner to replace, no contract to end, no second agent in production.

Does it understand toxic combinations and attack paths?
+

Tamnoon reads them. When Wiz draws a path, Tamnoon walks it hop by hop, read-only, and rates the fix at each hop. A change that breaks the attack path is only safe if it breaks nothing else, and that second condition is exactly what the investigation exists to prove.

We were burned by auto-remediation. Why is this different?
+

A tool that fires fixes blind is an autoimmune reaction: it attacks the body it is supposed to protect. Tamnoon starts from the opposite premise. Every fix is investigated read-only first, against live traffic, usage, dependencies and ownership. What it cannot prove safe it refuses, and the refusal ships with the evidence why. You were not wrong to pull the plug on a tool that could not tell you why a change was safe.

What do I tell my change advisory board?
+

They approve a change class, not a black box. Starting mode is SAFE-only: the engine closes only the class of change your board has approved, through your own change process, under your IAM policies, on your audit trail. Autonomy widens on evidence, class by class, and every decision leaves a record your auditor can read.

See the engine run against your own Wiz account.

Read-only, in the first meeting. Live discrimination, a live refusal, and a live safe heal.