---
sourceDocument: Zurich Impact
sourceDocumentLink: https://www.servicenow.com/docs/r/zurich/impact

 Release :

    - zurich

ft:locale :

    - en-US

ft:publication_title :

    - Zurich Impact

ft:clusterId :

    - ipact

bundleId :

    - ipact


---

# Real-time prevention monitoring for Scan Engine

# Real-time prevention monitoring for Scan Engine {#ariaid-title1}

* Release version: Zurich
* 
* Updated November 13, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Real-Time Prevention is a Scan Engine feature that actively monitors records as they are created or modified by developers and administrators, displaying real-time finding messages when saving records in any instance where
the Scan Engine is installed and activated.  
How it works:

* **Immediate Detection:** Identifies potential violations in scripts, includes, and other fields at the moment of edit.
* **On-Screen Alerts:** Displays findings in real-time with severity levels
* **Guided Resolution:** Provides details, such as line numbers, impact levels, and steps to resolve found issues.
* **Governance:** Supports exception workflows and links to supporting documentation for compliance.

{#using-real-time-prevention-monitoring-scan-engine__ul_g12_sz3_jhc}  
Note:  
Real-Time Prevention must be enabled in the Scan Engine properties page for this feature to function. For more information, refer to [Configure Scan Engine parameters](https://www.servicenow.com/docs/2zlFyhVtwSoxB22F1frkEw "Configure the primary scanning capabilities and configuration options for scheduled, on-demand, and real-time scans.").

Findings identified by real-time monitoring can have the following levels.
{#using-real-time-prevention-monitoring-scan-engine__table_dlv_bvk_hhc__entry__2}

| Level | Description |
|-|-|
| Review | * In real-time mode, displays an informational message without blocking saves or creating finding records. * In scan mode, Review level findings are recorded in the findings table for tracking purposes. {#using-real-time-prevention-monitoring-scan-engine__ul_gf5_xlh_khc} |
| Suggest | Prompts users to check for a better solution if one is available. |
| Recommend | * Prevents users from saving the record unless they resolve the issue or provide an exception reason. * For more information, refer to [Submit exceptions for the Scan Engine findings](https://www.servicenow.com/docs/Hlbh8~iq8b0CYZ4LYeZTng "For Recommend level findings, developers can submit exception requests if they feel the issue should not be considered a finding."). {#using-real-time-prevention-monitoring-scan-engine__ul_fzk_jmh_khc} |
| Act | * Prevents users from saving the record until they fix the code to meet the definition's requirements. * No exception reason option is available. * An override requires admin-level rights or the disabling of the definition. {#using-real-time-prevention-monitoring-scan-engine__ul_xpg_vmh_khc} |
[ ]

{#using-real-time-prevention-monitoring-scan-engine__table_dlv_bvk_hhc}  
Note:  
Depending on the level of the definition, users may be required to fix a finding before saving a record.

