💡 Still using the classic Drata experience? Refer to Exclusions for the original UI.
A finding represents a specific resource, configuration, or result that affects whether a test passes or fails. You can exclude findings when they do not apply to your organization or represent an approved exception. Excluding items ensures tests focus on issues that impact compliance while preserving visibility and audit context.
Example scenarios
If a security group allows public SSH for a documented business reason, you can exclude that finding while recording justification.
If a vulnerability test reports priorities that do not impact compliance, you can exclude those findings to focus remediation on relevant risks.
Personnel findings
If a test lists personnel as findings, you can’t exclude or reinclude those individuals from the Monitoring page. Create these exclusions from the Personnel page instead, where you can manage personnel exclusions or mark them out of scope.
Exclude findings from a test
Open Monitoring and select a test.
Open the Findings tab.
Select one or more findings.
Select Exclude.
Enter a business rationale.
Select Submit.
You can select an individual finding to view additional details before excluding it.
Re-include excluded items
Open Monitoring and select a test.
Open the Exclusions tab.
Select one or more excluded items.
Select the Include
Confirm by selecting Reinclude.
Drata reapplies the item during the next test run.
Find tests with exclusions
To find tests that include exclusions:
Open Monitoring.
Apply the Has exclusions filter.
This filter shows all tests with one or more excluded findings.
