Observation automates beautifully. Integrations pull configurations, user lists, and logs on a schedule, so evidence collection stops being a screenshot hunt. Automated tests compare each artifact against a control and open a task the moment something drifts — which is continuous monitoring in practice. Policy distribution, training reminders, onboarding and offboarding checklists: anything repetitive with a machine-readable source of truth belongs in this bucket, and the mature platforms handle it well enough that doing it manually is now a choice, not a constraint.
Everything after detection resists automation. Software can flag an over-permissive role; deciding whether it matters, fixing the Terraform behind it, negotiating an exception with the auditor, or redesigning the access process is judgment and remediation, and it lands on a person. So do scoping decisions, risk treatment, vendor reviews with ambiguous answers, and security questionnaires that read like essay exams. A red test is a to-do item, not a fix — automation compresses the observing and barely touches the deciding.
The distinction matters most at purchase time. Choosing where to automate is a platform decision — shortlists and head-to-heads live in the comparison hub — but every platform generates a stream of findings someone must own. Teams that want the automation and the operating layer in one motion pair the software with a service like Managed Vanta, where Agency’s engineers maintain the integrations, clear what the automation raises, and keep the dashboard green between audits.