Skip to content

Dashboard

The dashboard is a posture summary, not a worklist. It answers “is anything on fire, and is the pipeline that would tell me healthy?” in one screen, then hands you off to the page where the actual work happens. Almost every element is clickable and goes somewhere specific.

A 24h / 7d / 30d / 90d selector in the page header scopes the period-sensitive numbers: alerts opened and resolved in the period, scans completed in the period, average scan duration, and the recent activity feed. It does not change point-in-time values such as your risk score, datastore counts, or compliance percentages - those are always “right now”. The two trend charts keep their own separate 30d / 90d toggles.

Until the tenant has a cloud account, a reporting agent, and a completed discovery, the dashboard shows a three-step checklist instead of its metrics:

  1. Connect cloud account
  2. Deploy agent
  3. Run first discovery

The metric widgets are deliberately suppressed while the checklist is up, because every counter would read zero and read as a posture claim rather than an empty state. Recent Activity and Quick Actions stay visible, since both are useful before setup completes. Step 2 watches for the agent’s first heartbeat and advances on its own the moment it lands, so you can leave the page open while the agent comes up. See Deploy the agent.

Tile What it means Clicks through to
Accounts Connected accounts over total connected accounts. A gap here means something is failing access, not that you are missing coverage. Cloud Accounts
Datastores Every datastore in the inventory, excluding hidden and not-found ones. Datastores
Coverage The share of your inventory that has been scanned at least once. This is the honesty check on every other number: low coverage means the risk and compliance figures describe only part of your estate. Not clickable
Risk Score Tenant posture score out of 100, coloured by band, with the direction of travel over the period. Risk
Open Alerts Alerts not yet resolved, coloured by the worst severity present, with the percentage change over the period. Alerts

Coverage is the tile to read first. A 92 risk score across 12% coverage is not a good posture, it is an untested one.

A breakdown of scanned datastores into High, Medium, and Low risk, sized against the number of datastores actually scanned. Use it to judge shape: a long Low tail with three Highs is a normal estate, while a flat spread usually means classification is still catching up. Opens the Risk Assessment page. How a datastore earns its band is covered in Risk engine.

One radial gauge per framework you have enabled, sorted worst score first so the frameworks needing attention lead. Each gauge shows the framework’s compliance percentage and, underneath, its met controls over total controls. Frameworks that have never been assessed sort last rather than pretending to be perfect. Clicking a gauge opens that framework’s controls.

The footer adds three tenant-level figures:

  • Overall - the aggregate compliance score, annotated with the coverage percentage behind it. When coverage is low the score is greyed out rather than presented as authoritative, for the same reason the Coverage tile matters above.
  • Frameworks - how many are being assessed.
  • Est. Exposure - a rough monetary estimate of regulatory exposure, derived from published penalty ranges for the frameworks you are failing and the volume of affected records.

Scoring, control mapping, and evidence export are covered in Compliance mapping & scoring.

Your triage worklist: the highest-scoring datastores right now. Each row opens that datastore’s detail drawer directly, so you can go from “what is worst” to “what is inside it” in one click. The full ranking lives on the Risk page.

Open alerts broken down by severity, with the most recent listed underneath and clickable straight into the alert drawer. Two period counters sit at the bottom: New in Period and Resolved. Read them as a pair. New consistently outrunning Resolved is a capacity problem, not a posture problem, and it is the earliest signal that alert volume needs tuning through policy or suppression. See Alerts & Incidents.

Two charts, each with its own 30d / 90d toggle: tenant risk score over time, and alert volume over time. These are the “are we getting better” view that a single-day score cannot give you. A risk score that is flat while alert volume climbs usually means new findings are landing on datastores you already knew were bad.

Present only if you have permission to view Identity. Four counters: Total Identities, Over-Privileged, Users without MFA, and Open Recommendations against identities. Over-privileged and no-MFA are the two that reliably turn into incidents, so they are the ones worth watching week to week. Opens Identity & Access; the scoring behind it is in Identity & access risk.

Agent fleet status: how many agents are Online, Offline, and the total, with the individual agents listed. This is the widget that tells you whether the rest of the dashboard is current. An offline fleet means no new discovery and no new scans, so every other number quietly ages. Opens the Agents page.

The scanning pipeline’s own health, carrying one of three states:

State Meaning
Healthy Scans have run recently.
Degraded There has been activity, but the last scan is well over a day old.
Blocked No scan activity at all: nothing completed, nothing running, nothing on record.

Alongside it: scans Completed in the period, how many are In Progress, the Last Scan timestamp, and Avg Duration, plus a Scan Coverage bar of scanned datastores over total. Degraded or Blocked here is usually an agent or credentials problem rather than a scanning problem, so check System Health and the account’s status first.

A condensed feed of what has happened in the tenant, drawn from the same record as the audit trail. It answers “did someone change something” before you go hunting for why a number moved. Opens the Audit log.

Four shortcuts, each hidden if your role does not permit it: Add Account, Run Assessment, View Alerts, and Generate Report.

Two compact widgets at the bottom, each shown only if you have the matching read permission:

  • Remediation - executions Pending approval, Running, and Failed in the last seven days, with recent executions listed and clickable. Pending is the one that needs a human: those runs are stopped waiting on an approver. See Remediation.
  • Policy - Open violations, how many are Compliance-linked, and how many policies are Overdue review. Each figure links into the matching filtered view. See Policies.

The refresh button in the page header reloads everything. The dashboard also refreshes itself when an assessment or a scan completes elsewhere in the app, so a run you kicked off from Cloud Accounts lands here without a manual reload.