This is in relation to a previous ticket I have had open working with the Harness Reps. Specifically ticket #110470. Based off my discussion with Harness, Grace policies are only able to be created through a very manual process that is only possible by manually selecting findings/flaws after a scan has been completed. After that is completed, then you have to modify the existing OPA policy associated with that project. My suggestion here for a request is to update that process. Following Veracode specifically, as I have discussed with Abhishek Sahu, Veracode allows you to create a policy that can be associated to all projects and findings based on the discovered date. If a flaw is found on X day, then 30 days after the discovered date is when the pipeline will fail if left unfixed. Instead of it being a manual process, it should be added as a feature that will automatically be captured by Harness and its findings database. TL:DR Grace periods that are automatically catalogued instead of manually.