Scan Status & Freshness
Understand when data was last collected, what scan coverage means and how to interpret partial, failed and permission-limited results.
Securitain continuously assesses your AWS environment. The Scan Status page tells you the state of each scan cycle: whether it is running, completed, partial, or experiencing a problem. This information matters because a report or finding reflects the data last successfully collected — not necessarily the data collected at the moment you are looking at it.
Where to find Scan Status
The Scan Status page shows the current and recent scan state for connected accounts, scan errors, missing permissions and per-account collection freshness.
Scan status vs data freshness
Important
Current scan status
≠
Displayed data freshnessCurrent scan status — is a scan running right now? Has it succeeded or failed?
Data freshness — when was the most recent successful collection that produced the findings and analysis currently shown?
Both matter. For time-sensitive security decisions or before distributing a report, review both.
Scan statuses
The following statuses represent the states a scan cycle can be in. Not every status indicates a problem.
Queued
The scan has been scheduled and is waiting to start. No new data has been collected yet in this cycle.
Running
Data collection is in progress. Findings and analysis still reflect the prior completed scan until this scan completes successfully.
Completed
The scan finished and all available data was collected. The findings and analysis now reflect this scan's results. Per-account freshness timestamps should update.
Partial
The scan completed but coverage was incomplete. Some accounts, services or checks may not have been assessed in this cycle. The data shown reflects what was successfully collected.
Important
Failed
The scan did not complete. Depending on when the failure occurred, some data may have been collected before failure.
Permission denied
The Securitain cross-account role could not read one or more required resources. This may result in missing findings or gaps in coverage for the affected accounts or services. Review the missing-permissions section to understand what is affected.
Timed out / canceled
The scan was canceled or exceeded its allowed collection window. Data from the partial cycle may or may not be available. Prior successful scan data remains in place.
Failed before collection ≠ 0 findings
Important
Scan fails before collection
↓
Last successful scan data remains
↓
No new evidence collectedThis is an important distinction for security governance. A drop in finding count after a failed scan may represent a scan problem — not genuine remediation.
Partial ≠ passed
A partially completed scan did not assess the full scope. Findings and checks that were not reached in the partial cycle are still in the state from the previous completed assessment of that area. Do not interpret Partial as all-clear.
Unassessed ≠ passed
If an area, account, service or check was not assessed in the most recent scan, the current finding state for that area reflects the last time it was assessed — not a current confirmation that no issue exists. An unassessed check is not a passed check.
Not assessed recently
≠
Assessed and found cleanMulti-account scan display
For organizations with multiple connected AWS accounts, Securitain runs assessment across all connected accounts. The Scan Status page can display per-account scan state. Some accounts may complete successfully while others experience permission issues or partial coverage — the overall organization view should be understood in per-account context.
Connected accounts and per-account freshness
Each connected account has a data freshness timestamp showing the last time assessment data was successfully collected for that account. When evaluating a finding, the relevant freshness is the timestamp for the account that contains the affected resource or identity — not the organization-level scan timestamp.
An account with a stale freshness timestamp may have:
- a recent permission-denied error
- partial scan coverage
- a failed scan cycle
- a recently added account that has not yet completed its first full scan
Missing permissions
Securitain will report when the assessment role lacks the permissions required to collect specific data. Missing permissions produce coverage gaps, not false-negative findings. The areas affected by missing permissions will not appear as clean — they will be absent or flagged as not assessed.
Important
Review the missing permissions listed in Scan Status and update the cross-account role policy to restore coverage if the permission gap is unintentional.
Scan errors
The Scan Status page includes recent scan errors where available. Common sources include:
- AWS API throttling
- cross-account role configuration changes
- missing permissions on specific services
- accounts in restricted regions or with active SCPs
- AWS service-side errors during collection
Scan errors are informational. Review them to understand whether coverage has changed and whether the assessment data you are relying on is complete.
Freshness before using a report
Check before a time-sensitive decision
- Latest successful collection per account
- Scan status and any errors
- Partial or failed scan conditions
- Missing permissions
- Account coverage
Then evaluate the report
- Report generation timestamp
- Account scope of report
- Evidence freshness per finding
- First and last seen timestamps
- Lifecycle state of included findings
A report generated from stale or partial data can still be useful, but its limitations must be understood before using it for security decisions or audit evidence. See Reports & Evidence for the full distinction between report generation time and evidence collection time.
Evidence and limitations
Scan coverage depends on: connected account scope, cross-account role permissions, AWS API availability, regional scope and supported services. Assessment data reflects what Securitain could collect given these constraints.
Limitation
Related guides
Reports & Evidence
Report generation time vs evidence collection time — and what freshness means for reports.
Read moreFindings & Finding Lifecycle
How scan results transition findings through lifecycle statuses.
Read moreRemediation
Verification after remediation requires a successful capable scan.
Read moreConnect AWS
Cross-account role configuration that scan collection depends on.
Read moreCompliance Mapping
Scan freshness affects the evidence behind compliance mapping.
Read moreExceptions & Risk Acceptance
Understanding data freshness behind exception-related findings.
Read more