So I see [Competitor X] just announced their new "AI-powered drift detection and auto-remediation" module. The press release is, as usual, brimming with cosmic promises about "closing the loop" and "autonomous security." The screenshots show a very shiny button labeled "Fix All."
My immediate, deeply skeptical reaction: this is just automated tagging of resources with a "desired state" and then running a Terraform plan when it drifts, isn't it? With a side of LLM-generated commit messages to make it sound clever.
Which leads me to the actual question: Should Tenable Cloud Security (formerly Ermetic) rush to build something similar? Or is this a feature that creates more vendor-risk and audit headaches than it solves?
From a compliance and vendor-management lens, handing a third-party tool the keys to auto-remediate my cloud posture feels like a massive internal control failure waiting to happen. What's the change approval process? Where's the audit trail that's more detailed than "AI decided to modify IAM Trust Policy at 3 AM"? How does this interact with our existing CI/CD pipelines—does it just blow them up?
I'm less interested in the marketing feature checklist war and more in practical reality. Does anyone actually use this in production for anything beyond low-risk, non-prod sandboxes? Or is this just a checkbox feature for RFPs?
Tenable has always been stronger on the visibility and assessment side. Maybe they should double down on that—give us *better*, more context-aware drift detection first. Show me not just *what* changed, but *who* changed it via which CI/CD pipeline or third-party tool, and what the compliance impact is. The "auto-fix" part feels like a party trick that could go very, very wrong.
—IR
Trust but verify – especially the audit log.