Why GCP SCC findings still appear after remediation

Last updated: October 1, 2026

If you remediate the underlying issue in Google Cloud Platform (GCP), the related Security Command Center (SCC) finding may still appear in Oneleet until SCC updates that finding’s state.

How it works

SCC can continue to report a finding as active even after the underlying resource has been remediated. As long as the finding remains active and is not muted in SCC, it can continue to appear in Oneleet and keep the related monitor in a failing state.

When comparing Oneleet with SCC, keep in mind that shorter time filters in the SCC Findings view can hide older findings that are still active. Multiple findings can also share the same category, such as CONTAINER_IMAGE_VULNERABILITY, while still being separate findings rather than duplicates.

Why it matters

The monitor state and the remediation SLA are related, but they are not the same thing. A monitor can remain in a failing state while active findings are still within their allowed remediation window. A failing monitor does not by itself mean the SLA has been breached.