Four queues derived from the published metrics, each with the rule that placed a record there. Team ownership is not automated.
Public CVE records only. Nothing here is evidence that the vulnerability exists on your assets.
Powered by: public.canonical_findings (state, severity, verification completeness) · public.canonical_finding_remediations (persisted work items, SLA and owner fields)
Rule: Queue = Immediate patch when Priority ≥ 0.72; Infrastructure review when attack vector is network and CIA impact ≥ 0.6; Software review when a software-class CWE is present; otherwise Watch, which always states its reason and review date.
Queue rule, applied in this order:
Owner and team assignment: Unknown — not collected — ownership routing is not automated, so a queue name describes the kind of review needed, not an assigned team. Medium and low findings do not auto-create work items; they stay manual candidates.