Integration drift is the biggest bucket and the least scary. An OAuth token expired, a connector lost a permission scope after a vendor API change, your HR system and identity provider disagree about who works here, or a decommissioned server is still cached in inventory. The control is fine — the plumbing that observes it isn’t. These reds clear without anyone touching production.
Real control gaps are the tests doing their job: MFA genuinely unenforced for two contractors, a storage bucket that really is unencrypted, an offboarding that closed in the HR system but never in your cloud console. These need actual engineering or process work, and they deserve your attention first — they’re the ones an auditor would also find.
Undocumented exceptions are deliberate decisions nobody wrote down: the break-glass admin account, the legacy box exempt from MDM, the service account whose key can’t rotate on the standard schedule. Vanta can’t tell deliberate from broken until you document it. Written up properly — reason, owner, compensating control, review date — an exception is a normal part of a control environment, not a confession.
Work the list in this sequence and it shrinks fastest — most of it without infrastructure changes.
Your auditor doesn’t grade the dashboard — they test whether controls operated over the audit period. A test that failed for an afternoon and was fixed is a non-event. A control that was down for six weeks of your Type 2 window needs a remediation story: what failed, when you caught it, how you fixed it, and what prevents a repeat. Auditors handle documented deviations all the time; what damages a report is the gap they discover that you couldn’t explain.
So sequence by audit reality. If you’re inside an observation window, in-scope controls come first and everything else is hygiene. If the window hasn’t started, clear the backlog before you start the clock — a clean entry into the period is worth more than a fast one. And if the deeper issue is evidence that was never collected rather than tests that fail, that’s a different playbook: see behind on audit evidence.
Agency runs remediation sprints inside client Vanta tenants: engineers take scoped access, sort every red into the three buckets, clear the integration drift in the first pass, push real fixes through your normal change process, and write the exception documentation properly. It’s the standing weekly motion behind managed Vanta, compressed into a sprint — built on patterns from 1,000+ companies onboarded to Vanta through Agency. Kept running afterward, it’s 200+ hours saved per year.
One reassurance while you’re staring at the reds: the tool isn’t the problem. Vanta is telling you the truth — someone just has to act on it, continuously. Where the software ends and the operating work begins is the whole subject of Agency vs Vanta.
Not by themselves. Auditors evaluate whether controls operated during the period, not whether a dashboard was ever red. Short-lived failures that were caught and fixed are routine; sustained failures need remediation evidence and, if they span much of the window, an honest conversation with your auditor about timing.
Deactivating with a documented justification — reason, owner, compensating control, review date — is legitimate scoping. Snoozing a test to make the dashboard green with no record of why is how audit findings get manufactured. The difference is the paper trail, not the button.
Almost always integration drift: an expired token, a vendor API or permission change, new hires syncing in from your HR system, or new cloud resources entering scope. Check connector health before assuming your environment regressed — a single sync failure can light up dozens of tests at once.
Drift clears fastest — often on the first pass once connectors are fixed. Real control gaps depend on engineering complexity and your change process, and exception documentation is hours of writing, not weeks. An Agency sprint sequences audit-blocking items first so the date stops being at risk before the long tail is done.
Scoped and auditable: admin inside your Vanta tenant, read access plus a pull-request path into infrastructure, and nothing that bypasses your review. You keep ownership of every account, and every change we make lands through your normal approval flow.