Site Guardian
A report-only compliance dashboard — see module drift, unauthorized additions, and version gaps across every site you run, before they break anything.
What it does
Site Guardian aggregates fleet scan data into one dashboard. Per site it shows which modules are installed, which drift from the distribution spec, which were added without authorization, and which are running stale versions. It does not make changes — it’s your early-warning system; fixes flow through the deploy tools.
Getting started
- Open Site Guardian (a hub-level module).
- Review the findings overview — sites are ranked by finding count; zero findings = compliant.
- Click a site to drill into its module list, drift list, and scan history.
- Fix drift by running a deploy (or removing an unauthorized module) — not from Site Guardian itself.
Drift over time
Guardian keeps a long scan history per site, so you can answer “when did this module appear?” or “how long has this version been behind?” — the movement, not just a snapshot.
Report-only, on purpose
There are no delete, push, or update buttons. Remediation runs through the deploy system, where every action is logged, reversible, and tested. Guardian is the eyes; the deploy tools are the hands.
Tips
A fresh finding sometimes just means the spec changed recently — check the distribution before assuming real drift.
Guardian’s data comes from its scan running on a schedule. If the dashboard looks stale, confirm the scan ran.