CentralCSP
FeaturesScript inventory

Script inventory

Every script observed on your payment pages, with a review status. The four tabs, what each status means, and how a script leaves the list.

Last update:

The script inventory holds every script observed on a page matching an enabled payment-page pattern, each with a review status. It is built from CSP hash reports and lives under PCI DSS > Script inventory.

The script inventory requires a plan that includes compliance.

If the inventory is empty, the cause is almost always scope rather than reporting. For more information, refer to Payment pages.

The four tabs

The inventory is split across four tabs:

TabShows
OriginsOne row per origin serving scripts in scope. Select an origin to filter Scripts by it
ScriptsThe full inventory, filterable by any status
Action requiredYour work queue, holding only Unreviewed and Needs review
RejectedOnly scripts marked rejected

Work from Action required. It is the only tab whose emptiness means something.

Retired scripts are excluded from every tab.

The Action required tab holds a mix of statuses:

The script inventory on its Action required tab, with a mix of statuses

Statuses

Every script in scope carries one status:

StatusMeaning
UnreviewedDetected, nobody has decided
Needs reviewWas justified, and the hash has changed since
JustifiedAuthorized at its current hash
RejectedJudged not to belong on a payment page

Needs review is the status that does the work in requirement 11.6.1. A justification is pinned to the hash it was made against, so when content at that URL changes, the script comes back to you instead of staying quietly approved.

The evidence PDF prints these as Pending review, Hash changed, Authorized, and Rejected.

What is recorded per script

Each script carries its origin, first and last seen, current hash, tags, the current review decision, and the full history.

Two things there are worth knowing. Pages lists the document URLs it was seen on, which answers scope questions directly. Hash history lists every hash with first and last seen, which is how you tell a routine release cadence from an unexpected change.

Making decisions from here is covered in Justifying scripts.

Refresh inventory

Managers get a Refresh inventory button, rate-limited to once per 30 seconds. Reconciliation also runs hourly and immediately after any scope or rule change, so you rarely need it. For more information, refer to Reconciliation.

Export CSV

The toolbar exports the current view, honouring your filters, with no row limit. It includes the justification text, both hashes, who decided and when, and the tags.

This is the artefact to use when you need to work through a large inventory in a spreadsheet, or share it with someone without dashboard access. Viewer role is enough.

For a full audit package including the ledger, use the evidence export instead.

Next steps

On this page