Remediation is the process of responding to a violation to stop further data exposure or disruption. The Remediation page lets you act on violations, review what has already been done, and see which users have been revoked.

Remediation metrics

The metrics across the top summarise your security posture and response activity:

  • Security posture — total violations, open violations, remediated violations, and the overall remediation rate.
  • Active threats — count of Critical-severity violations.
  • Resolution efficiency — automated vs. manual remediations, plus deleted syncs, ignored violations, and failed attempts.
  • Risk profile — active critical and medium threats, high-risk users, tokens revoked, and cancelled jobs.
Remediation metrics dashboard

Remediation actions

The page is organised into tabs — Violations, Remediation History, and Revoked Users. From the Violations tab you can apply one of the following actions:

ActionWhat it does
Delete Syncs / Delete Query JobPermanently removes the affected data sync (Eloqua) or Salesforce Bulk API query job to stop the data transfer.
Revoke TokenSuspends the user's credentials so the integration can no longer access the platform.
IgnoreMarks the violation as ignored; no further action is taken.
Enable UserRe-activates a user whose token was previously revoked.
Remediation action menu

Actions can be applied individually to a selected violation, or in bulk across every violation that matches the current filters.

Manual vs. automatic

  • Automatic remediation runs without intervention when a violation is detected, based on the response actions configured for each severity in Threshold & Rules.
  • Manual remediation is started by an administrator. Before a manual action runs, an impact preview shows the affected syncs, violations, and users so you can confirm the scope.

Both modes are tracked separately in the metrics and history.

Manual remediation impact preview

History & trends

The Remediation History tab logs every action with its timestamp, application, action type, execution mode (auto or manual), who executed it, and the result (success or failed). Opening a history entry shows the original violation context and the platform's API response. A trend chart compares automated and manual remediation activity over time, and user-level history shows recent actions for an individual user.

Remediation history and trend