Best Practices for Using Agent Val
Here are some tips on how to get maximum value from Agent Val.
Run Val Continuously, Not Just On-Demand
Why
Configuration drift is continuous. The window between detection and exploitation keeps shrinking. Running Val continuously ensures that exploitable exposures are never left untested as your environment changes.
How
Set Agent Val to run continuously based on your environmental and risk context. This keeps your exploitability picture current without waiting for a manual trigger, so your team always knows what's actually exploitable right now.
Start with Your Highest-Value Assets
Why
Val is a risk-aware selection engine — it narrows focus to exposures that are both weaponized globally and relevant to your highest-value assets. Starting with the assets that matter most ensures your first validation cycles deliver the highest impact.
How
Focus initial validation on your most critical asset groups:
- Crown jewels and critical business assets — highest-frequency continuous validation
- Internet-facing assets — prioritized by active threat-actor relevance
- Production servers and cloud workloads (AWS, Azure, GCP)
- Workstations and end-user devices
- Development and test environments - on-demand, lower urgency
Pair Agent Val with Agent Sara
Why
Agent Val identifies and prioritizes Patch Tuesday CVEs impacting your environment and drafts patch jobs. But Sara works from threat context and business criticality — she cannot confirm whether those CVEs are actually exploitable in your production environment with your controls in place. Without Val, remediation teams still act on theoretical risk.
Pairing Sara and Val completes the loop: Sara narrows to the right CVEs, Val confirms which of those are real threats.
How
After Agent Sara generates her Patch Tuesday exposure summary and prioritization plan, run Agent Val on the same asset scope. Val validates which of Sara's prioritized CVEs are genuinely exploitable — shrinking the confirmed remediation target list further and ensuring patch effort is concentrated on confirmed threats, not Sara's full theoretical backlog.
Configure Val's post-remediation revalidation trigger to fire automatically after Sara's patch jobs complete, closing the full remediation loop without manual steps.
Configure Post-Remediation Revalidation Triggers
Why
A patch job completing does not mean the exploit path is closed. Patches can fail silently, apply partially, or leave residual exploitability due to dependent configuration. Without post-remediation revalidation, SLA closure is based on ticket status — not evidence. This creates paper-only remediation that fails audit scrutiny and leaves real exposure gaps undetected.
How
Enable the Post-Remediation trigger in Agent Val's task configuration. Set it to fire automatically after Qualys TruRisk Eliminate patch jobs complete. Val will re-run TruConfirm against the same exploit paths on patched assets — no manual steps required.
SLA closes at "exploit path confirmed closed" — Val generates cryptographic proof reports that are immediately available for audit, CAB review, and executive reporting without additional preparation.
Use Cryptographic Proof Reports for CAB and Audit
Why
Change Advisory Boards and auditors require evidence that remediation actions have genuinely reduced risk — not just that tickets have been resolved. Self-attestations and scan-output summaries do not meet the standard for high-stakes change approval or compliance review. Val's cryptographic proof of closure is tamper-evident and tied to actual exploit-path confirmation, making it the strongest available evidence artifact.
How
Present Val's cryptographic proof of closure reports as your primary evidence in CAB submissions, audit responses, and executive risk briefings — replace scan outputs and ticket-closed counts with exploit-path-confirmed-closed reports.
For pre-CAB reviews, use Val's TruConfirm exploitability result and AI Reliability Score together: exploitability result proves the change is necessary, AI Reliability Score proves the proposed patch is safe for your specific asset configurations.
Review AI Reliability Scores Before Enterprise-Wide Patch Rollout
Why
A patch safe for most assets may behave unpredictably on EOL/EOS software or non-standard configurations. The AI Reliability Score, trained on 140M+ deployments, surfaces these edge cases before you deploy enterprise-wide.
How
Before any enterprise-wide rollout, review the AI Reliability Score for each recommended patch. For assets with lower scores — especially those running EOL/EOS software — use a phased approach: test environment first, then pilot, then full production. Combine with Agent Sara's patch ring structure for staged rollouts.
Share Email Summaries with the Right Audiences
Why
Regular updates keep leadership informed and confident in your patch management program.
How
Enable email notifications on your Agent Val tasks. Share summaries with CISOs, IT leadership, and Change Advisory Board (CAB) chairs.
Prioritize Confirmed-Exploitable Findings
Why
Less than 1% of critical vulnerabilities are actively exploited. Val's Confirmed Exploitable count is the only metric reflecting genuine attacker leverage in your environment right now.
How
Focus first on Agent Val's Confirmed Exploitable metric and the amplified TruRisk queue — less than 0.1% of total findings. Create dedicated change windows for these. Unvalidated theoretical findings can follow standard remediation cadence.