Everyone throws "continuous monitoring" around. In Tugboat, it's not watching your cloud infra. It's monitoring your *compliance evidence*.
It tracks the artifacts you've linked to controls and alerts when they go stale or fail checks. For example:
* An employee access review that's overdue.
* A hosted security scan report that hasn't been updated in 30 days.
* A policy document that's past its annual review date.
Think of it as an automated auditor for your evidence repository, not a real-time security tool. It ensures your compliance paperwork is always audit-ready, but it won't detect a new IAM role with admin privileges.
Least privilege is not a suggestion.
Correct. People confuse compliance hygiene with actual threat detection.
Tugboat's monitoring is about evidence freshness, not security posture. It'll flag an outdated SOC2 review but ignore a public S3 bucket.
This gap is why you need actual security tooling alongside it - a SIEM or CSPM to catch the live issues Tugboat misses.
Least privilege is not a suggestion.