Skip to content

Reports

Reports & Exports turns what is on screen into a file you can send to an auditor, attach to a ticket, or load into a spreadsheet. Reports export as CSV or JSON, on demand.

The left side of the page lists every report your role permits, grouped by category, with the recent downloads on the right. Twenty reports ship today; your catalogue may be shorter than this list because each report is gated by its own permission.

Report Contents Needs
PII Summary Sensitive data findings across all datastores in an account An account
Datastore Detail One datastore, with its full findings breakdown An account and a datastore
Report Contents Needs
Compliance Report Framework scores, violations, and control status Optional framework
Gap Analysis The gap between current posture and a framework’s requirements, across both datastores and identities Optional framework
Gap Analysis Roadmap Every control for one framework grouped into gaps, needs-verification, addressed and not-applicable, for datastores and identities. Answers “what is left to reach compliant”, not just “what is broken” A framework (required)
Manual Attestation Controls Every control Argus cannot assess from cloud telemetry, with the reason for each. Roughly half the control set - import it into your GRC tool Optional framework

All four need compliance:read rather than the general reports permission, so someone who can pull operational exports may still not be able to pull compliance ones.

Report Contents Needs
Risk Assessment Risk scores and severity breakdown for an account’s datastores, worst first An account
Security Alerts All alerts with severity, status, and recommendations Nothing (alerts:read)
Policy Violations Violations with status, severity, and resolution history Nothing (policies:read)
Incidents The incident log with priority, responders, and linked alerts Nothing (incidents:read)
Public Exposure Datastores reachable from the internet across every account. Includes the ones Argus could not verify, marked unverified, so “we could not check” never reads as “private” Nothing
Report Contents Needs
Account Summary Every datastore in an account with status, size, and risk overview An account
Datastore Inventory Every datastore across the whole tenant with account, size, risk and scan state Nothing
Scan Coverage Per account: agent health, scan schedule, and how many datastores have never been scanned. Answers “what is NOT being watched” Nothing (agents:read)
Report Contents Needs
Executive Summary Risk posture, compliance status, and top alerts in one high-level view Nothing
Audit Log User actions, system events, and changes Nothing (audit:read)
Identity Compliance IAM identities with privilege flags, risk, and failing compliance signals Nothing (identity:read)
Recommendations Open and resolved recommendations with subject, status, and remediability Nothing (recommendations:read)
Remediation Activity Remediation runs with target, approver, live vs dry-run, rollback and risk reduction Nothing (remediation:read)
Users & Access Tenant members with roles, MFA status, and last login Nothing (users:read)

Executive Summary remains the fastest report to hand to someone who asked “how are we doing”.

Every report can be previewed in-app before (or instead of) downloading it. Pick your options, then choose Preview rather than Download: the first 100 rows render in a table, and Download is available from inside the preview once you have seen what you are getting.

This matters most for the reports with no page of their own - Gap Analysis, Identity Compliance, Executive Summary and the Manual Attestation list exist only as reports, so preview is the only way to read them without opening a file in another tool.

Two things to know:

  • A preview shows the first 100 rows and says so when there are more. Download is what gives you the complete set.
  • A preview is not a download. It does not appear in Recent Downloads and does not count as an export in your audit trail, because nothing left the platform.

Every report is configured in one dialog, whether you open it from the header button, a catalogue row, or a table’s Export shortcut. What it offers depends on the report:

  • Scope - account (and datastore) selectors appear only where the report needs them.
  • Filters - e.g. severity and status on alerts and violations, framework on compliance reports. A filter marked with an asterisk is required: the Gap Analysis Roadmap is always for one framework, so it offers no “All” option and cannot be generated until you pick one.
  • Period - only on reports where time is a real axis (alerts, violations, incidents, recommendations, remediation activity, audit log). Pick a preset (7 / 30 / 90 days, last year) or Custom for an exact from-and-to range. Both dates are inclusive, so a range ending today includes today. Posture reports like Compliance or PII Summary are point-in-time snapshots and have no period.
  • Search - on reports that support it (Security Alerts, Datastore Inventory, Public Exposure), matching the same text the corresponding table searches.
  • Format - CSV or JSON.
  • Fields - tick exactly the columns you want. Some reports offer extra column groups (Security Alerts has Compliance and Evidence; Remediation Activity has Diagnostics) which stay off unless you tick them, so the default export is not cluttered by detail most people do not need. Sectioned reports (Executive Summary, Compliance Report, Gap Analysis Roadmap, Datastore Detail) have fixed layouts and no field picker.
  • Filename - a sensible default you can rename; the extension always matches the format.

The alerts, datastores, violations, incidents, recommendations, audit log, and users tables carry an Export button that opens the same dialog, preselected, with the table’s current filters carried over. Two honest limits, both shown in the dialog before you generate:

  • Filters that the report cannot express are listed as not applied to export rather than silently dropped. Multi-selections and search now carry across on the reports that support them, so this list is much shorter than it was.
  • The export is the full filtered dataset up to the report’s row cap, not the page of rows you were looking at.

The Alerts and Datastores tables export through this same pipeline. Alerts previously had a separate export of its own; it was folded in once reports learned everything it could do (several severities or statuses at once, free-text search, exact date ranges, and the optional compliance and evidence columns). One consequence worth knowing: alert exports now appear in Recent Downloads and can be previewed, which the old separate path could not do.

Every table-style report has a row cap (5,000-10,000 depending on the report). When a result is capped, the file itself says so - CSV ends with a [ Truncated: showing X of Y rows ] line, JSON carries truncated, total_rows, and returned_rows - and the download history records that a partial export was taken. A file that silently stopped at 5,000 rows would read as “everything”; these do not.

Exports carry counts and metadata, never the sensitive values themselves. A PII Summary tells you a bucket holds 4,000 card numbers; it does not contain a single card number. That is what makes it safe to attach to a ticket, and it means an export can never become a new copy of the data you are trying to protect.

Compliance exports exclude hidden and stale datastores, and say how many were excluded. The count of what was left out is surfaced rather than swallowed, so posture cannot be quietly improved by hiding a bad asset before running the report. See Datastores for what hiding does.

The right side of the page shows what has been generated: which report, in what format and with which options, when, and by whom. It is not trimmed by age - it grows, 25 to a page, because the whole point is proving to an auditor that a pack was produced on a given date, and evidence that expires after a week cannot do that. It is also how you notice someone exporting more than you expected.

A report with no matching rows still downloads, as a file with just its column headers, and is still recorded here. “We checked on this date and there were none” is a real answer, and the history row is what dates it.