* [Blog](https://www2.paloaltonetworks.com/blog) * [Cloud Security](https://www2.paloaltonetworks.com/blog/cloud-security/) * [Cloud Security](https://www2.paloaltonetworks.com/blog/category/cloud-security/) * Close the Gaps in Code-to... # Close the Gaps in Code-to-Cloud Tracing with Cortex Cloud [](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww2.paloaltonetworks.com%2Fblog%2Fcloud-security%2Fcode-to-cloud-tracing-dashboard%2F) [](https://twitter.com/share?text=Close+the+Gaps+in+Code-to-Cloud+Tracing+with+Cortex+Cloud&url=https%3A%2F%2Fwww2.paloaltonetworks.com%2Fblog%2Fcloud-security%2Fcode-to-cloud-tracing-dashboard%2F) [](https://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Fwww2.paloaltonetworks.com%2Fblog%2Fcloud-security%2Fcode-to-cloud-tracing-dashboard%2F&title=Close+the+Gaps+in+Code-to-Cloud+Tracing+with+Cortex+Cloud&summary=&source=) [](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https://www2.paloaltonetworks.com/blog/cloud-security/code-to-cloud-tracing-dashboard/&ts=markdown) \[\](mailto:?subject=Close the Gaps in Code-to-Cloud Tracing with Cortex Cloud) Link copied By [Cameron Hyde](https://www.paloaltonetworks.com/blog/author/cameron-hyde/?ts=markdown "Posts by Cameron Hyde") Aug 27, 2026 5 minutes [Cloud Security](https://www.paloaltonetworks.com/blog/category/cloud-security/?ts=markdown) [Code to Cloud](https://www.paloaltonetworks.com/blog/cloud-security/category/code-to-cloud/?ts=markdown) [Cortex Cloud](https://www.paloaltonetworks.com/blog/tag/cortex-cloud/?ts=markdown) Cortex Cloud is advancing code-to-cloud security by introducing Code-to-Cloud Coverage to measure the bidirectional traceability between source code and running assets, identify gaps, and eliminate blind spots. ## Find Out How Far Your Code-to-Cloud Context Really Goes Code-to-cloud has become foundational to modern cloud security. Security teams increasingly expect to trace risks across the application lifecycle, from issues found in code to the assets they reach in production and from runtime risks back to the artifacts, build pipeline and code repository behind them. Traceability helps teams prioritize risks in both directions by connecting development findings to production impact and cloud issues back to their source, while also deduplicating the same underlying issue across the application lifecycle so it can be fixed once at the source. Tracing capabilities have improved considerably as the market has matured, but security teams still lack visibility into the connections that are missing. A CNAPP may show no runtime asset connected to a repository or image, creating a false negative: the asset may exist in production, but the platform simply cannot establish the relationship to the code that created it. Without knowing whether a missing connection reflects a true absence or a gap in coverage, teams cannot confidently identify where blind spots remain. Missing traceability can directly affect security decisions in both directions. A code vulnerability is harder to prioritize without knowing whether it reaches an exposed production workload, while a cloud or runtime issue is harder to prioritize and remediate without understanding where it originated, what application it affects and who owns the fix. ## Measure Coverage Across the Application Lifecycle Effective code-to-cloud security requires teams to continuously measure visibility coverage across the full application lifecycle and eliminate blind spots. Closing those gaps gives AppSec, CloudSec and SOC teams more complete context to prioritize risk, investigate issues and drive remediation back to the right source. Complete traceability also improves visibility into the business application itself by connecting the development and runtime assets that make it up. AppSec teams can better determine which development risks reach production, CloudSec teams can understand their impact across the application and trace issues back to their source and owner, while SOC teams gain additional context about the assets they are investigating. Rather than discovering missing context during an investigation, teams can proactively identify coverage gaps and close them before they impact prioritization, investigation or remediation. ## Find and Close Code-to-Cloud Coverage Gaps with Cortex Cloud Cortex Cloud's new Code-to-Cloud Coverage measures the percentage of assets with complete traceability between development and production, shows where connections break and provides guidance to close coverage gaps. Cortex Cloud's Asset Lineage Graph connects code repositories, build pipelines, registry artifacts and runtime assets to provide visibility across the application lifecycle. It establishes those relationships by correlating metadata from source control, CI/CD systems, build artifacts and runtime environments, including AI-powered analysis of CI/CD build logs when standard detection patterns cannot identify a connection. Infrastructure as code requires a different type of connection because Terraform and CloudFormation definitions create cloud resources rather than becoming the runtime asset themselves. Cortex Cloud uses YOR tags to preserve that relationship, linking provisioned cloud resources back to the IaC that created them so teams can trace infrastructure changes from code into production without requiring Terraform state files that may contain sensitive data. ![Application Security dashboard for "Code to Cloud Coverage" displaying 0% cloud-to-code traceability across 1.1K runtime artifacts, with flow stages showing drops at Deployment and Build, alongside three recommended onboarding steps.](https://www.paloaltonetworks.com/blog/wp-content/uploads/2026/08/word-image-366657-2.png) Image 1: Code to Cloud Coverage Dashboard The Code-to-Cloud Coverage dashboard brings those relationships together to show where coverage is complete and where links are missing. When Cortex Cloud cannot establish a connection, it surfaces the gap and provides guidance to resolve it, helping teams distinguish between an asset that truly has no relationship and one that simply isn't connected. Complete lineage makes code-to-cloud context more actionable in both directions. Teams can follow risks from development into production to understand their impact, or start with a runtime issue and trace it back to the source and team responsible for fixing it. Better coverage gives teams stronger context to prioritize risk and accelerate remediation. ### Trace the Full Path for Every Asset Within the Unified Asset Inventory, the Code to Cloud tab visualizes lineage for individual assets, complementing the environment-wide view in Code-to-Cloud Coverage. Teams can drill into a specific asset and follow its connections across repositories, build pipelines, container or VM images and the runtime resources where those images are deployed. ![Dashboard view under the "Code to Cloud" tab showing a container image lineage graph connecting base core images to AWS registry images, accompanied by a "Missing Traceability" notification.](https://www.paloaltonetworks.com/blog/wp-content/uploads/2026/08/word-image-366657-3.png) Image 2: Code to Cloud traceability with missing code repository Asset-level lineage gives teams the context to understand where an asset came from, where it is running and what development resources are connected to it. Cortex Cloud can also show when repository code is deployed to runtime or powers an internet-accessible endpoint, bringing production and exposure context directly into the investigation. ## Know What's Traceable and What Isn't Code-to-cloud tracing gives teams critical context across development and production. Code-to-Cloud Coverage takes that further by showing where connections are complete, where gaps remain and what teams need to do to close them. ## Learn More [Request a demo](https://www.paloaltonetworks.com/cortex/cloud/demo) to see how Cortex Cloud helps you eliminate blind spots across code and cloud. *** ** * ** *** ## Related Blogs ### [Announcement](https://www.paloaltonetworks.com/blog/cloud-security/category/announcement/?ts=markdown), [AppSec](https://www.paloaltonetworks.com/blog/cloud-security/category/appsec/?ts=markdown), [Cloud Security](https://www.paloaltonetworks.com/blog/category/cloud-security/?ts=markdown), [Code to Cloud](https://www.paloaltonetworks.com/blog/cloud-security/category/code-to-cloud/?ts=markdown), [Software Supply Chain Security](https://www.paloaltonetworks.com/blog/cloud-security/category/software-supply-chain-security/?ts=markdown) [#### Cortex Cloud Named an Overall Leader in KuppingerCole's 2026 Software Supply Chain Security Report](https://www2.paloaltonetworks.com/blog/cloud-security/kuppingercole-supply-chain-report-leadership/) ### [Cloud Security](https://www.paloaltonetworks.com/blog/category/cloud-security/?ts=markdown), [CNAPP](https://www.paloaltonetworks.com/blog/cloud-security/category/cnapp/?ts=markdown), [Code to Cloud](https://www.paloaltonetworks.com/blog/cloud-security/category/code-to-cloud/?ts=markdown) [#### Overcoming Cloud Security Consolidation Challenges](https://www2.paloaltonetworks.com/blog/cloud-security/cloud-security-consolidation-challenges/) ### [Cloud Security](https://www.paloaltonetworks.com/blog/category/cloud-security/?ts=markdown), [Product Features](https://www.paloaltonetworks.com/blog/security-operations/category/product-features/?ts=markdown), [Products and Services](https://www.paloaltonetworks.com/blog/category/products-and-services/?ts=markdown) [#### Why Diverse Cloud Environments Require Flexible Security](https://www2.paloaltonetworks.com/blog/2025/07/why-diverse-cloud-environments-require-flexible-security/) ### [Announcement](https://www.paloaltonetworks.com/blog/category/announcement/?ts=markdown), [Application Security](https://www.paloaltonetworks.com/blog/cloud-security/category/application-security/?ts=markdown), [Cloud Security](https://www.paloaltonetworks.com/blog/category/cloud-security/?ts=markdown), [CNAPP](https://www.paloaltonetworks.com/blog/cloud-security/category/cnapp/?ts=markdown), [News and Events](https://www.paloaltonetworks.com/blog/security-operations/category/news-and-events/?ts=markdown), [Product Features](https://www.paloaltonetworks.com/blog/security-operations/category/product-features/?ts=markdown), [Products and Services](https://www.paloaltonetworks.com/blog/category/products-and-services/?ts=markdown) [#### Introducing Cortex Cloud --- The Future of Real-Time Cloud Security](https://www2.paloaltonetworks.com/blog/2025/02/announcing-innovations-cortex-cloud/) ### [Cloud Security](https://www.paloaltonetworks.com/blog/category/cloud-security/?ts=markdown), [Code to Cloud](https://www.paloaltonetworks.com/blog/cloud-security/category/code-to-cloud/?ts=markdown) [#### Best Practices for Managing Vulnerabilities in the Cloud--Part 2](https://www2.paloaltonetworks.com/blog/cloud-security/managing-vulnerabilities-part-two/) ### [Cloud Security](https://www.paloaltonetworks.com/blog/category/cloud-security/?ts=markdown), [Code to Cloud](https://www.paloaltonetworks.com/blog/cloud-security/category/code-to-cloud/?ts=markdown) [#### Best Practices for Managing Vulnerabilities in the Cloud](https://www2.paloaltonetworks.com/blog/cloud-security/managing-vulnerabilities-part-one/) ### Subscribe to Cloud Security Blogs! Sign up to receive must-read articles, Playbooks of the Week, new feature announcements, and more. ![spinner](https://www2.paloaltonetworks.com/blog/wp-content/themes/panwblog2023/dist/images/ajax-loader.gif) Sign up Please enter a valid email. By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown) and acknowledge our [Privacy Statement](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown). Please look for a confirmation email from us. If you don't receive it in the next 10 minutes, please check your spam folder. This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply. {#footer} {#footer} Products and Services * [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security?ts=markdown) * [Secure AI by Design](https://www.paloaltonetworks.com/ai-security?ts=markdown) * [Prisma AIRS](https://www.paloaltonetworks.com/prisma/prisma-ai-runtime-security?ts=markdown) * [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security?ts=markdown) * [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions?ts=markdown) * [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention?ts=markdown) * [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering?ts=markdown) * [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire?ts=markdown) * [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security?ts=markdown) * [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown) * [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security?ts=markdown) * [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security?ts=markdown) * [Industrial OT Security](https://www.paloaltonetworks.com/network-security/medical-device-security?ts=markdown) * [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown) * [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall?ts=markdown) * [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations?ts=markdown) * [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls?ts=markdown) * [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager?ts=markdown) * [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription?ts=markdown) * [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os?ts=markdown) * [Panorama](https://www.paloaltonetworks.com/network-security/panorama?ts=markdown) * [Secure Access Service Edge](https://www.paloaltonetworks.com/sase?ts=markdown) * [Prisma SASE](https://www.paloaltonetworks.com/sase?ts=markdown) * [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration?ts=markdown) * [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem?ts=markdown) * [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown) * [Prisma Access](https://www.paloaltonetworks.com/sase/access?ts=markdown) * [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser?ts=markdown) * [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan?ts=markdown) * [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation?ts=markdown) * [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown) * [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex?ts=markdown) * [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown) * [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown) * [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security?ts=markdown) * [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security?ts=markdown) * [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security?ts=markdown) * [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud?ts=markdown) * [AI-Driven SOC](https://www.paloaltonetworks.com/cortex?ts=markdown) * [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam?ts=markdown) * [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr?ts=markdown) * [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar?ts=markdown) * [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse?ts=markdown) * [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response?ts=markdown) * [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam?ts=markdown) * [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira?ts=markdown) * [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management?ts=markdown) * [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management?ts=markdown) * [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager?ts=markdown) * [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance?ts=markdown) * [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management?ts=markdown) * [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic?ts=markdown) * [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management?ts=markdown) * [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance?ts=markdown) * [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery?ts=markdown) * [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access?ts=markdown) * [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42?ts=markdown) * [Proactive Assessments](https://www.paloaltonetworks.com/unit42/assess?ts=markdown) * [Incident Response](https://www.paloaltonetworks.com/unit42/respond?ts=markdown) * [Transform Your Security Strategy](https://www.paloaltonetworks.com/unit42/transform?ts=markdown) * [Discover Threat Intelligence](https://www.paloaltonetworks.com/unit42/threat-intelligence-partners?ts=markdown) Company * [About Us](https://www.paloaltonetworks.com/about-us?ts=markdown) * [Careers](https://jobs.paloaltonetworks.com/en/) * [Contact Us](https://www.paloaltonetworks.com/company/contact-sales?ts=markdown) * [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility?ts=markdown) * [Customers](https://www.paloaltonetworks.com/customers?ts=markdown) * [Investor Relations](https://investors.paloaltonetworks.com/) * [Location](https://www.paloaltonetworks.com/about-us/locations?ts=markdown) * [Newsroom](https://www.paloaltonetworks.com/company/newsroom?ts=markdown) Popular Links * [Blog](https://www.paloaltonetworks.com/blog/?ts=markdown) * [Communities](https://www.paloaltonetworks.com/communities?ts=markdown) * [Content Library](https://www.paloaltonetworks.com/resources?ts=markdown) * [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia?ts=markdown) * [Event Center](https://events.paloaltonetworks.com/) * [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center) * [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z?ts=markdown) * [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/compliance?ts=markdown) * [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure?ts=markdown) * [Sitemap](https://www.paloaltonetworks.com/sitemap?ts=markdown) * [Tech Docs](https://docs.paloaltonetworks.com/) * [Unit 42](https://unit42.paloaltonetworks.com/) * [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd) ![PAN logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg) * [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown) * [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center?ts=markdown) * [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown) * [Documents](https://www.paloaltonetworks.com/legal?ts=markdown) Copyright © 2026 Palo Alto Networks. All Rights Reserved * [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks) * [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector?ts=markdown) * [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/) * [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks) * [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks) * EN Select your language