Skip to main content

Exclude findings from tests (New Experience)

Use this article to exclude specific items from a compliance test when the test does not apply to those items.

Updated this week

💡 Still using the classic Drata experience? Refer to Exclusions for the original UI.

A finding represents a specific resource, configuration, or result that affects whether a test passes or fails. You can exclude findings when they do not apply to your organization or represent an approved exception. Excluding items ensures tests focus on issues that impact compliance while preserving visibility and audit context.

Example scenarios

  • If a security group allows public SSH for a documented business reason, you can exclude that finding while recording justification.

  • If a vulnerability test reports priorities that do not impact compliance, you can exclude those findings to focus remediation on relevant risks.

Personnel findings

If a test lists personnel as findings, you can’t exclude or reinclude those individuals from the Monitoring page. Create these exclusions from the Personnel page instead, where you can manage personnel exclusions or mark them out of scope.

Exclude findings from a test

  1. Open Monitoring and select a test.

  2. Open the Findings tab.

  3. Select one or more findings.

  4. Select Exclude.

  5. Enter a business rationale.

  6. Select Submit.

You can select an individual finding to view additional details before excluding it.

Re-include excluded items

  1. Open Monitoring and select a test.

  2. Open the Exclusions tab.

  3. Select one or more excluded items.

  4. Select the Include

  5. Confirm by selecting Reinclude.

Drata reapplies the item during the next test run.

Find tests with exclusions

To find tests that include exclusions:

  1. Open Monitoring.

  2. Apply the Has exclusions filter.

This filter shows all tests with one or more excluded findings.

Did this answer your question?