Dashboard

See security, endpoint, and operational posture at a glance before drilling into action.

XDRShield Dashboard gives teams a tenant-aware starting point for reviewing alerts, endpoint health, coverage signals, operational trends, and investigation priorities before moving into agents, alerts, events, cases, policies, or response workflows.

Security posture summaryEndpoint and health signalsDrill-down workflow
Why it matters

A useful dashboard turns posture signals into the next right action.

Security operations move faster when analysts and operators can see priority alerts, coverage concerns, agent health, and operational trends without opening every feature page first. The dashboard summarizes the environment and points teams toward the workflow that needs attention.

01

Focus attention quicklyBring high-level security, endpoint, and operational signals into one starting view.
02

Connect summary to workflowDrill from dashboard signals into alerts, agents, events, cases, policies, and response pages.
03

Support tenant-aware reviewReview customer or tenant posture without mixing unrelated operational scope.
04

Reduce stale assumptionsUse dashboard context as a prompt to validate underlying evidence before action.
Operating model

Use dashboard summaries to decide where to investigate next.

The dashboard is the operating front door for XDRShield. It summarizes key security and endpoint posture signals for the selected scope, helping teams identify which queues or workflows need attention, then drill into the detailed page that owns the evidence or action.

  • Review alert, endpoint, health, case, and operational signals for the selected tenant or customer scope.
  • Use dashboard indicators to decide whether to open Alerts, Events, Agent Health, Cases, Policies, or Response Actions.
  • Treat dashboard tiles as summaries; validate important decisions in the detailed workflow pages.
  • Use the dashboard during daily review, customer service checks, and incident handoff.
XDRShield architecture connecting endpoint visibility, investigation, response, and operations
Feature capabilities

What the XDRShield Dashboard helps teams do.

Each capability supports fast situational awareness and directed follow-up.

Posture overview

Review high-level endpoint, security, health, and operational signals for the selected scope.

Explore Posture overview →

Operating workflow

From dashboard signal to detailed workflow.

A dashboard workflow prevents summary views from becoming a substitute for evidence validation.

Choose the correct scope

Select the customer, tenant, or workspace before interpreting dashboard signals.

Review high-priority signals

Check alert pressure, health concerns, investigation workload, and coverage indicators.

Open the owning workflow

Drill into Alerts, Events, Agent Health, Cases, Policies, or Response Actions based on the signal.

Validate evidence

Use detailed pages to confirm affected endpoint, time range, status, owner, and supporting evidence.

Assign or act

Create cases, assign owners, tune policy, fix agent health, or request governed response as needed.

Return for review

Use the dashboard again after action to confirm the operational view reflects progress.

Common use cases

Where Dashboard helps most.

Use the dashboard when teams need fast posture orientation before choosing the detailed workflow.

Daily operations review

Start the day with a tenant-aware view of alert, endpoint, health, and investigation pressure.

MSP customer check-ins

Review customer posture quickly before opening customer-specific alert, case, or agent queues.

Incident handoff

Orient the next analyst to current alert pressure, open work, and follow-up areas.

Coverage and health follow-up

Spot endpoints or health signals that require Agent Health or Agent Management review.

Management reporting preparation

Use dashboard summaries to decide which detailed evidence exports or pages need review.

Policy rollout monitoring

Watch for coverage or alert changes after policy updates, then validate in detailed policy and event pages.

Dashboard signal reference

Use summaries as a starting point, not the final evidence.

This table clarifies how to move from dashboard signals into the detailed XDRShield workflow.

Area What it means How teams use it
Alert signal A summary of detection pressure or alert queue state for the selected scope. Open Security Alerts to filter by severity, status, host, title, and evidence.
Agent health signal A summary of reporting or endpoint health concerns. Open Agent Health Monitoring or Agent Management to review last sync, availability, and version context.
Case signal A summary of investigation workload or aging work. Open Cases to review owner, severity, status, SLA, evidence, and timeline.
Coverage or policy signal A cue that endpoint assignment, policy sync, or monitoring coverage needs review. Open Security Policy Management, Agent Management, or Events to validate details.
Operational use

Dashboard for SOC, IT, and MSP teams.

The dashboard provides shared orientation while detailed workflows provide evidence and action.

For SOC and IT teams

Use the dashboard to identify the next queue or workflow that needs attention.

  • Start with the selected tenant or workspace.
  • Drill into detailed pages for evidence validation.
  • Use summaries to guide prioritization, not final decisions.

Explore security alerts →

For MSP and customer operations

Use dashboard scope to review customer posture, then open customer-specific agents, alerts, cases, policies, or activity evidence.

  • Validate customer scope before interpreting metrics.
  • Use dashboard signals for service review preparation.
  • Drill into detailed evidence before customer-facing conclusions.

Explore customer management →

Questions buyers ask

Dashboard FAQs.

What is the XDRShield Dashboard?

The XDRShield Dashboard is a tenant-aware starting view that summarizes security, endpoint, health, case, and operational signals so teams can decide which workflow needs attention next.

Should dashboard summaries be used as final evidence?

No. Dashboard signals are summaries. Important operational, security, or customer-facing decisions should be validated in detailed pages such as Alerts, Events, Agent Health, Cases, Policies, or Response Actions.

How does the dashboard support MSP operations?

MSP teams can review customer or tenant posture in the selected scope, then drill into customer-specific workflows for alerts, agents, cases, policies, activity logs, and response actions.

What should teams check first on the dashboard?

Teams should confirm the selected scope, then review priority alerts, agent health or coverage concerns, case workload, and any operational signals requiring follow-up.

How does the dashboard connect to investigations?

Dashboard signals can guide analysts into Security Alerts, Security Events, Threat Hunting, Cases, and Response Actions where detailed evidence and accountable action are managed.

Turn posture signals into action

Start with the dashboard, then validate in the owning workflow.

Use XDRShield Dashboard to orient daily operations, identify priority queues, and drill into the detailed evidence needed for confident security action.