Skip to main content

Agentic Reporting

Overview

This capability is now in Beta, if you would like to join the program, please contact your account manager.

Guardz Agentic Reporting brings AI-powered security reporting directly into the platform. This new feature introduces a more efficient and flexible way for MSPs to create, customize, and deliver security reports to their customers.

It uses agentic AI workflows to generate automated, intelligent reports on your organization's security posture, surfacing insights without requiring manual data assembly or report configuration.

Who Can Access It?

  • MSP admins

  • Elite plan customers

Key Capabilities:

Capability

Description

AI-generated reports

Reports are produced automatically using agentic AI workflows. No manual setup required.

Chat driven capability

Interact with reports through a conversational chat UI:

Start with a predefined report, build one from scratch, or refine the data after the report is created.

Per-organization scope

Data is always scoped to a single customer/organization.

Federated query

Query data directly from third-party sources (e.g., Microsoft logs) without needing it pre-loaded in Guardz.

Saved reports

Reports can be saved and downloaded. Report data is dynamic and reflects the latest available security data.

Suggested prompts

Pre-built prompt suggestions are available to get started quickly and reliably.

How It Works?

  1. Query Builder Agent:

    Interprets your natural language input, identifies the relevant data tables and schemas, and determines whether the data lives in the Guardz data lake or needs to be fetched externally via federated query.

  2. Dynamic Widget:

    Once the data is retrieved, a second agent autonomously decides the best way to visualize it: graph, table, bar chart, etc.

  3. Multi-Query Mode:

    For complex or broad requests (e.g., "give me a full summary"), the system splits the task across multiple sub-agents working in parallel to gather all the data needed.

Availability Aspects:

  • Accessed data:

    • Security data (e.g., issues and incidents)

    • EDR (SentinelOne) Logs

    • M365 logs

    • And more

  • Only managed SentinelOne data.

  • Currently, this capability is available only for Microsoft domain tenants (GWS is not yet support, it is on our roadmap).


Using Agentic Reporting

How to Access Agentic Reporting?

  1. Log in to the Guardz platform.

  2. Select a specific customer (if you manage multiple customers, you must first select a specific customer organization from the organization switcher before the reporting experience load).

  3. In the left-hand sidebar, locate and click the Reporting icon (a document with a bar chart and an AI sparkle indicator).

Once inside the Reporting Section:

  1. Choose from a selection of predefined reports

  2. Or, use the chat to:

    1. Ask for more options for predefined reports

    2. Create and specify the data / information you want to retrieve and display

    3. Once the report has been generated, the chat can be used to fine-tune the data, explore findings, and perform additional analysis.

  3. Save or download reports for future reference.

    This lets you return to them later without having to run the query again, although the underlying data may have been updated in the meantime.

  4. Click the + button to start a new conversation. conversations are not saved, while saved reports are stored and remain accessible.

Please note:

  • The module loads automatically scoped to the selected customer.

  • You can navigate within the reporting module to explore different report types, time ranges, and security dimensions.

  • Switching back to "All Customers" will show a prompt to select a customer instead of report data.

Did this answer your question?