Magebean Documentation

Security Dashboard Workflow

Manage a Magento Application from inventory and required Baselines through independent Assessment, verification, Findings, remediation, Monitoring, and Report snapshots.

On this page

1. Register the Application and its Instances

Create or select the Company, register the business-level Magento Application, and add each deployable Instance. An Instance represents production, staging, development, or another environment; it is not the top-level business Application.

  • Record the Application owner, business criticality, data classification, internet exposure, and lifecycle.
  • Record each Instance environment, hosting type, Magento version, expected scan frequency, and current deployment Revision.
  • Grant Company-defined Roles either Company-wide access or scope them to selected Instances.

2. Create and configure the required Baseline

Start from an appropriate system Profile, configure the included Rules and verification expectations as a Company Baseline, then manually assign that required Baseline to the Application.

Assessment snapshot. Creating an Assessment snapshots its Baseline configuration. Later Baseline changes do not modify existing Assessments. Baseline version history and automatic migration are outside the MVP.

3. Start an assessment

Create an independent Assessment for the selected Instance and required Baseline. Set its type, scope, owner, reviewer, due dates, and review window. Initial, periodic, release, compliance, incident follow-up, and ad hoc Assessments each process their Items independently.

Pair Magebean CLI Agent with the Instance and submit a Scan Run for its current deployment Revision. The Agent is not paired with an Assessment. One Instance scan may update matching automated Items in multiple relevant active Assessments.

Run a first CLI scan →

4. Process automated and human-required verification

Process each automated and human-required Assessment Item again. A new Assessment does not copy verification results or Evidence from another Assessment. A new production Revision makes older automated results visibly stale and requires a current full scan.

Assign human-required Items to permitted users. Evidence should identify the Instance, date, method, and scope. User-submitted Evidence requires independent approval; the submitter cannot be the sole approver.

5. Manage findings and decisions

A failed security condition creates a Finding requiring treatment. Include the affected Item, evidence, severity, owner, remediation SLA, expected fix, and independent reverification criteria.

Remediate

Complete the one MVP Remediation Ticket, submit the fix, then independently verify the Item before resolving the Finding.

Accept risk

Submit a Risk Request for independent approval with rationale, scope, and a mandatory review date.

Defer

Temporarily postpone action with an owner and required future expiry date.

6. Complete, snapshot, and monitor

Complete the initial Assessment only when every applicable Item satisfies the completion rules. There is no separate overall Assessment approval workflow in the MVP. Export an immutable Report snapshot when stakeholders need a point-in-time record.

Monitoring is the continuing state of that living Assessment. Continue receiving scans, track stale or expired verification, overdue Agent activity, risk reviews and deferrals, and create new Findings when later verification fails.