On this page
1. Register the Application and its Instances
Create or select the Company, register the business-level Magento Application, and add each deployable Instance. An Instance represents production, staging, development, or another environment; it is not the top-level business Application.
- Record the Application owner, business criticality, data classification, internet exposure, and lifecycle.
- Record each Instance environment, hosting type, Magento version, expected scan frequency, and current deployment Revision.
- Grant Company-defined Roles either Company-wide access or scope them to selected Instances.
2. Create and configure the required Baseline
Start from an appropriate system Profile, configure the included Rules and verification expectations as a Company Baseline, then manually assign that required Baseline to the Application.
3. Start an assessment
Create an independent Assessment for the selected Instance and required Baseline. Set its type, scope, owner, reviewer, due dates, and review window. Initial, periodic, release, compliance, incident follow-up, and ad hoc Assessments each process their Items independently.
Pair Magebean CLI Agent with the Instance and submit a Scan Run for its current deployment Revision. The Agent is not paired with an Assessment. One Instance scan may update matching automated Items in multiple relevant active Assessments.
Run a first CLI scan →4. Process automated and human-required verification
Process each automated and human-required Assessment Item again. A new Assessment does not copy verification results or Evidence from another Assessment. A new production Revision makes older automated results visibly stale and requires a current full scan.
Assign human-required Items to permitted users. Evidence should identify the Instance, date, method, and scope. User-submitted Evidence requires independent approval; the submitter cannot be the sole approver.
5. Manage findings and decisions
A failed security condition creates a Finding requiring treatment. Include the affected Item, evidence, severity, owner, remediation SLA, expected fix, and independent reverification criteria.
Remediate
Complete the one MVP Remediation Ticket, submit the fix, then independently verify the Item before resolving the Finding.
Accept risk
Submit a Risk Request for independent approval with rationale, scope, and a mandatory review date.
Defer
Temporarily postpone action with an owner and required future expiry date.
6. Complete, snapshot, and monitor
Complete the initial Assessment only when every applicable Item satisfies the completion rules. There is no separate overall Assessment approval workflow in the MVP. Export an immutable Report snapshot when stakeholders need a point-in-time record.
Monitoring is the continuing state of that living Assessment. Continue receiving scans, track stale or expired verification, overdue Agent activity, risk reviews and deferrals, and create new Findings when later verification fails.