Reports
Reports & Exports turns what is on screen into a file you can send to an auditor, attach to a ticket, or load into a spreadsheet. Reports export as CSV or JSON, on demand.
The report catalogue
Section titled “The report catalogue”The left side of the page lists every report your role permits, grouped by category, with the recent downloads on the right. Twenty reports ship today; your catalogue may be shorter than this list because each report is gated by its own permission.
Data Discovery
Section titled “Data Discovery”| Report | Contents | Needs |
|---|---|---|
| PII Summary | Sensitive data findings across all datastores in an account | An account |
| Datastore Detail | One datastore, with its full findings breakdown | An account and a datastore |
Compliance
Section titled “Compliance”| Report | Contents | Needs |
|---|---|---|
| Compliance Report | Framework scores, violations, and control status | Optional framework |
| Gap Analysis | The gap between current posture and a framework’s requirements, across both datastores and identities | Optional framework |
| Gap Analysis Roadmap | Every control for one framework grouped into gaps, needs-verification, addressed and not-applicable, for datastores and identities. Answers “what is left to reach compliant”, not just “what is broken” | A framework (required) |
| Manual Attestation Controls | Every control Argus cannot assess from cloud telemetry, with the reason for each. Roughly half the control set - import it into your GRC tool | Optional framework |
All four need compliance:read rather than the general reports permission, so someone who can
pull operational exports may still not be able to pull compliance ones.
Risk & Security
Section titled “Risk & Security”| Report | Contents | Needs |
|---|---|---|
| Risk Assessment | Risk scores and severity breakdown for an account’s datastores, worst first | An account |
| Security Alerts | All alerts with severity, status, and recommendations | Nothing (alerts:read) |
| Policy Violations | Violations with status, severity, and resolution history | Nothing (policies:read) |
| Incidents | The incident log with priority, responders, and linked alerts | Nothing (incidents:read) |
| Public Exposure | Datastores reachable from the internet across every account. Includes the ones Argus could not verify, marked unverified, so “we could not check” never reads as “private” |
Nothing |
Infrastructure
Section titled “Infrastructure”| Report | Contents | Needs |
|---|---|---|
| Account Summary | Every datastore in an account with status, size, and risk overview | An account |
| Datastore Inventory | Every datastore across the whole tenant with account, size, risk and scan state | Nothing |
| Scan Coverage | Per account: agent health, scan schedule, and how many datastores have never been scanned. Answers “what is NOT being watched” | Nothing (agents:read) |
Governance
Section titled “Governance”| Report | Contents | Needs |
|---|---|---|
| Executive Summary | Risk posture, compliance status, and top alerts in one high-level view | Nothing |
| Audit Log | User actions, system events, and changes | Nothing (audit:read) |
| Identity Compliance | IAM identities with privilege flags, risk, and failing compliance signals | Nothing (identity:read) |
| Recommendations | Open and resolved recommendations with subject, status, and remediability | Nothing (recommendations:read) |
| Remediation Activity | Remediation runs with target, approver, live vs dry-run, rollback and risk reduction | Nothing (remediation:read) |
| Users & Access | Tenant members with roles, MFA status, and last login | Nothing (users:read) |
Executive Summary remains the fastest report to hand to someone who asked “how are we doing”.
Preview before you download
Section titled “Preview before you download”Every report can be previewed in-app before (or instead of) downloading it. Pick your options, then choose Preview rather than Download: the first 100 rows render in a table, and Download is available from inside the preview once you have seen what you are getting.
This matters most for the reports with no page of their own - Gap Analysis, Identity Compliance, Executive Summary and the Manual Attestation list exist only as reports, so preview is the only way to read them without opening a file in another tool.
Two things to know:
- A preview shows the first 100 rows and says so when there are more. Download is what gives you the complete set.
- A preview is not a download. It does not appear in Recent Downloads and does not count as an export in your audit trail, because nothing left the platform.
The generate dialog
Section titled “The generate dialog”Every report is configured in one dialog, whether you open it from the header button, a catalogue row, or a table’s Export shortcut. What it offers depends on the report:
- Scope - account (and datastore) selectors appear only where the report needs them.
- Filters - e.g. severity and status on alerts and violations, framework on compliance reports. A filter marked with an asterisk is required: the Gap Analysis Roadmap is always for one framework, so it offers no “All” option and cannot be generated until you pick one.
- Period - only on reports where time is a real axis (alerts, violations, incidents, recommendations, remediation activity, audit log). Pick a preset (7 / 30 / 90 days, last year) or Custom for an exact from-and-to range. Both dates are inclusive, so a range ending today includes today. Posture reports like Compliance or PII Summary are point-in-time snapshots and have no period.
- Search - on reports that support it (Security Alerts, Datastore Inventory, Public Exposure), matching the same text the corresponding table searches.
- Format - CSV or JSON.
- Fields - tick exactly the columns you want. Some reports offer extra column groups (Security Alerts has Compliance and Evidence; Remediation Activity has Diagnostics) which stay off unless you tick them, so the default export is not cluttered by detail most people do not need. Sectioned reports (Executive Summary, Compliance Report, Gap Analysis Roadmap, Datastore Detail) have fixed layouts and no field picker.
- Filename - a sensible default you can rename; the extension always matches the format.
Export from a table
Section titled “Export from a table”The alerts, datastores, violations, incidents, recommendations, audit log, and users tables carry an Export button that opens the same dialog, preselected, with the table’s current filters carried over. Two honest limits, both shown in the dialog before you generate:
- Filters that the report cannot express are listed as not applied to export rather than silently dropped. Multi-selections and search now carry across on the reports that support them, so this list is much shorter than it was.
- The export is the full filtered dataset up to the report’s row cap, not the page of rows you were looking at.
The Alerts and Datastores tables export through this same pipeline. Alerts previously had a separate export of its own; it was folded in once reports learned everything it could do (several severities or statuses at once, free-text search, exact date ranges, and the optional compliance and evidence columns). One consequence worth knowing: alert exports now appear in Recent Downloads and can be previewed, which the old separate path could not do.
Row caps, and files that admit it
Section titled “Row caps, and files that admit it”Every table-style report has a row cap (5,000-10,000 depending on the report). When a result is
capped, the file itself says so - CSV ends with a [ Truncated: showing X of Y rows ] line, JSON
carries truncated, total_rows, and returned_rows - and the download history records that a
partial export was taken. A file that silently stopped at 5,000 rows would read as “everything”;
these do not.
Two guarantees worth knowing
Section titled “Two guarantees worth knowing”Exports carry counts and metadata, never the sensitive values themselves. A PII Summary tells you a bucket holds 4,000 card numbers; it does not contain a single card number. That is what makes it safe to attach to a ticket, and it means an export can never become a new copy of the data you are trying to protect.
Compliance exports exclude hidden and stale datastores, and say how many were excluded. The count of what was left out is surfaced rather than swallowed, so posture cannot be quietly improved by hiding a bad asset before running the report. See Datastores for what hiding does.
Download history
Section titled “Download history”The right side of the page shows what has been generated: which report, in what format and with which options, when, and by whom. It is not trimmed by age - it grows, 25 to a page, because the whole point is proving to an auditor that a pack was produced on a given date, and evidence that expires after a week cannot do that. It is also how you notice someone exporting more than you expected.
A report with no matching rows still downloads, as a file with just its column headers, and is still recorded here. “We checked on this date and there were none” is a real answer, and the history row is what dates it.