There is a quiet temptation in security tooling, and most products eventually give in to it: only show the user what you can resolve. It makes the demo cleaner. It makes the dashboard feel actionable. It avoids the awkwardness of surfacing a problem and then admitting you cannot, by yourself, make it go away. We have decided not to give in to it. This is a note about why.
The unfixable is still your risk
Consider an OAuth integration with a third-party SaaS vendor. TrustFix can show you exactly what that connected app can reach inside your environment and how much would be exposed if it were abused. What TrustFix cannot do is reach into the vendor’s infrastructure and stop them from being compromised. That part is genuinely outside our control.
The wrong response to that limit is to stay quiet about the integration because there is no one-click fix. The blast radius is real whether or not we can sever it for you. Hiding it would make our dashboard look more capable and leave you less safe. So we surface it, we quantify it, and we say plainly: this is exposure you should decide about, and here is what it would cost you if it went wrong.
A risk you cannot fix today is still a risk you are entitled to know about today.
Honesty about limits is a feature, not an apology
We treat the boundary of what we can fix as information worth shipping, not an embarrassment to bury. When a finding is remediable, we aim to close it — proven, scoped, and recorded. When it is not, we tell you why, what it would take, and who actually holds the lever. A maintainer being phished, an upstream provider being breached, a deliberate decision by someone with legitimate authority — these are real categories, and pretending otherwise would erode the one thing a security product cannot afford to lose: your trust in what its silence means.
There is a practical payoff too. A tool that only shows fixable issues quietly trains you to believe that its empty states mean safety. A tool that shows you the unfixable alongside the fixable lets you reason about your actual exposure — and decide, with eyes open, which residual risks you are choosing to accept.
What this looks like in the product
In practice it means our inventory does not filter out the identities we cannot remediate for you, and our risk views do not stop at the edge of our automation. It means a finding can carry an honest verdict of “this is real, here is the reach, and the fix is not ours to apply.” It means we would rather notify you of something we cannot close than let you discover it from an attacker.
None of this is a pose. It is the design test we hold every screen to: would a security leader who reads carefully come away with a truer picture of their risk, or a more flattering one? We are building for the first. That choice is the soul of the product, and it is the one we are least willing to trade away for a cleaner demo.