Why GCP SCC findings still appear after remediation
Last updated: October 1, 2026
If you remediate the underlying issue in Google Cloud Platform (GCP), the related Security Command Center (SCC) finding may still appear in Oneleet until SCC updates that finding’s state.
How it works
SCC can continue to report a finding as active even after the underlying resource has been remediated. As long as the finding remains active and is not muted in SCC, it can continue to appear in Oneleet and keep the related monitor in a failing state.
When comparing Oneleet with SCC, keep in mind that shorter time filters in the SCC Findings view can hide older findings that are still active. Multiple findings can also share the same category, such as CONTAINER_IMAGE_VULNERABILITY, while still being separate findings rather than duplicates.
Why it matters
The monitor state and the remediation SLA are related, but they are not the same thing. A monitor can remain in a failing state while active findings are still within their allowed remediation window. A failing monitor does not by itself mean the SLA has been breached.