Where the project is going next. Anything here can be argued with, and anything missing can be asked for.
In progress
ConnectSecure as a sixth asset collector
Feed asset_view (serial number, BIOS, encryption state, architecture, security grade) into the nightly asset pipeline, joined on serial number, to close remaining gaps in the unified asset view.
Register a 'vulnerability' detector in Invoke-RemediationScan. Using the CVE id as resourceId yields one ticket per CVE per tenant, inheriting dedup and re-open suppression from the existing pipeline.
Six open issues: Exchange Online checks, Microsoft Secure Score, DLP and sensitivity labels, external collaboration and B2B, geo-fence parameterisation.