Admission control can stop risky objects before they run

Blocking a bad configuration at creation is the difference between prevention and investigation.

A policy that refuses privileged pods means none exist. A dashboard listing privileged pods means somebody has to notice and act. Both are described as controls; only one of them changes what is running in your cluster.

More on Kubernetes