Stable Identity for Assets and Findings
Build asset identity from multiple signals: cloud resource IDs, agent GUIDs, MAC addresses, tags, and authoritative CMDB references. For application issues, include repository, commit, and dependency coordinates. For infrastructure, layer IPs with ownership and environment. On findings, pair CVE identifiers with package names, versions, file paths, and stack traces when available. This composite approach tolerates change without collapsing distinct issues, preventing both accidental duplication and harmful over-merges that hide genuine risk from busy decision makers.