---
title: Remediate a tool
description: Allow, warn, or block one tool, many tools at once, or one tool on one laptop.
---

_[console.superalign.ai/remediation](https://console.superalign.ai/remediation)_

## Before you begin

- You have the **Owner** or **Admin** role. Viewers can see the page but not decide.
- You know what each decision does on the laptop. See [Allow, Warn, Block](/surface/governance/decisions).

## The Remediation page

Four tabs, each with a live count.

| Tab | Contents | Shortcut |
| --- | --- | --- |
| **Open** | Tools seen recently with no decision yet | `R` then `O` |
| **Allowed** | Tools you allowed | `R` then `A` |
| **Warned** | Tools you set to warn | `R` then `W` |
| **Blocked** | Tools you blocked | `R` then `B` |

Columns are **Risk**, **Name**, **Asset Type**, and **Endpoints** (how many laptops have it). Filter by type, risk level, and number of laptops.

## One tool

1. **Open the tool**

    Click its name. A panel opens on the right.

2. **Choose**

    At the bottom of the panel, click **Allow**, **Warn**, or **Block**, or press `A`, `W`, or `B`.

3. **Confirm**

    Read the window. It names the tool and the number of laptops affected. Click the matching button.

The tool moves to its tab, shows **Governed** in Inventory, and an audit entry is written.

## Many tools at once

**Specific tools.** Tick the box next to each one, or click a row and drag down to select a range. The panel becomes **Selected Assets** with the same three buttons plus **Clear Selection** (`C`). The button matching the current tab is disabled, since it would change nothing.

**Everything matching a filter.** Tick the box in the table header. Your decision applies to every tool that matches the current search and filters, up to 500 per batch, highest risk first. If more match, the console tells you how many remain for the next batch.

Each batch is all-or-nothing. If you change tabs or filters with tools selected, the console asks before clearing the selection.

## One tool on one laptop

1. **Open the laptop**

    Go to **Endpoints** and click the laptop.

2. **Open the tool on it**

    On the **Assets** tab, click the tool.

3. **Choose**

    Use **Allow**, **Warn**, or **Block** in the panel. This applies to this laptop only.

Until you do this, the panel shows **Inherits Default**: the laptop follows the company-wide decision.

## Checking what was decided

Every decision, single or batch, is in the [Audit log](/surface/admin/audit-log) under **Asset Governance**, with who decided, when, and the before and after state of each tool.

## Next steps

- [Audit log](/surface/admin/audit-log) to see what was decided and when
- [Endpoints](/surface/console/endpoints) to check a laptop after a Block
- [How risk is calculated](/surface/risk/scoring) to decide with the score in mind
