Connection noise. Expired OAuth tokens, renamed cloud projects, changed API scopes — one broken integration can light up dozens of tests at once. Reconnect, let the checks re-run, and watch a chunk of the wall turn green without touching a single control. Vanta shows the connection state on each test’s detail view, so spotting these takes minutes, not archaeology.
Genuine gaps. An account that really has no MFA, a laptop outside disk encryption, an access review that’s overdue. This is the only bucket with security meaning and the only urgent one — route each item to the system’s owner with a date, and let monitoring confirm the fix on its own.
Undocumented exceptions. The break-glass admin account, the contractor device outside MDM, the legacy repo nobody ships from. These were decisions, not failures; the remedy is scoping or a written exception with a compensating control. Auditors accept documented exceptions — what they don’t accept is surprises.
That’s the whole method. The long version — common test families, what each red actually means, and the fix for each — is at failing Vanta tests. If the wall rebuilds itself every few weeks, the missing ingredient is an owner, which is the problem Managed Vanta solves.
Not directly — auditors never grade your dashboard. But a red that reflects a control genuinely not operating during the observation period can surface as an exception. Age matters more than count: a two-day red is hygiene, a two-month red is evidence.
Recurring reds mean drift without ownership — integrations that silently disconnect, infrastructure changing faster than its configuration, and nobody watching the queue between audit pushes. The fix is a standing owner and a weekly cadence, not a bigger one-time cleanup.