- Plans must be validated via dry-run simulations before execution.
- Execution against external cloud providers is gated by the deployment flag
REMEDIATION_EXECUTION_ENABLED(disabled by default in self-hosted deployments). - Approved actions require Two-Person Integrity (dual admin approval).
1. Remediation Lifecycle
2. Generating a Plan
A remediation plan specifies the exact sequence of provider operations needed to mitigate a finding:3. The Execution Safety Gate
Before any change is dispatched to a cloud provider, NHI Security checks the deployment configuration:
Check if execution is enabled in your environment:
4. Approving and Executing Plans
Once verified, an independent Organization Admin approves execution:partially_failed, and an alert is recorded.

