Standard reporting in Core; advanced reporting add-on

Show what changed, what remains open and what evidence supports closure.

Guardian Security Reporting uses persisted findings, risks, actions, investigations, assessments and evidence to explain current posture and security improvement.

Australian data residency

Guardian for Australian customers is built, operated and hosted in Australia. All Guardian customer and platform data, including backups and recovery copies, is maintained and stored within Australia.

Standard reporting in CoreEvidence linkageCustomer-readable outputsAdvanced board and scheduled reporting
Buyer decision summary

Know what Guardian Security Reporting does, what the customer sees and what Damocles is responsible for before activation.

Guardian retains report version, definition, period, included products, source references, approval, artefact, recipients and supersession history where supported.

The package schedule identifies standard reports and cadence. Advanced Reporting identifies bespoke definitions, board packs, schedules, branding, exports, analyst narrative and delivery requirements.

Guardian does not fabricate missing trend history, complete source coverage, report artefacts or scheduled delivery.

01

What the product does

Available report sections depend on the selected package, products, data and approved report definition.

02

What the customer sees

Operational, customer and board reporting can share definitions without exposing the same level of detail.

03

What Damocles manages

Bespoke analysis and board reporting remain additional where outside the standard package.

The operational problem

A report is not useful when it repeats activity but cannot explain whether material risk reduced or which decisions remain open.

Security reporting often combines screenshots and counts from unrelated tools without consistent definitions, source traceability or evidence supporting a claimed resolution.

Guardian reports use the same operational records that manage the work. This allows the reader to move from an executive summary to the finding, risk, action, investigation or assessment that supports it.

01

Report the current state

Show material risks, findings, overdue actions, product status and current remediation posture.

02

Explain movement

Identify what opened, progressed, resolved, returned for further work or closed during the period.

03

Link the evidence

Trace results to the approved records, assessments, investigations and remediation evidence supporting them.

Product capability

Reporting built from the operational record rather than a separate spreadsheet.

Available report sections depend on the selected package, products, data and approved report definition.

SR

Standard security reports

Current Core and package reporting based on supported Guardian records and customer scope.

EV

Evidence linkage

Trace a result to the finding, risk, action, assessment, investigation or source record.

LM

Lifecycle movement

Show opened, progressed, resolved, review, reopened and closed activity using retained history.

EX

Approved exports

Export allow-listed customer information without credentials, raw payloads or internal storage paths.

BP

Board and executive packs

Use Advanced Reporting for bespoke definitions, narrative, decision focus and board-ready structure.

SC

Scheduled delivery

Deliver approved reports where recipients, cadence, retention, review and delivery method are configured.

What the customer sees

Different audiences receive different depth while using one record of truth.

Operational, customer and board reporting can share definitions without exposing the same level of detail.

OP

Operational report

Detailed product state, source health, findings, actions, investigations and blockers for the working team.

CS

Customer service report

Current posture, material activity, unresolved work, service state and required customer decisions.

EX

Executive summary

Priority risk, overdue actions, progress, significant change and decisions requiring leadership attention.

BR

Board pack

Bespoke governance structure, narrative, trend and decision framing where Advanced Reporting is selected.

PR

Provider report

Authorised customer reports, service allocation and recurring review material for MSP relationships.

AR

Artefact register

Approved report version, status, publication date, supersession and recipient history.

What Damocles manages

Damocles can manage report definition, validation, narrative, approval and delivery according to scope.

Bespoke analysis and board reporting remain additional where outside the standard package.

RD

Report definition

Confirm audience, questions, scope, period, products, metrics, narrative and required decisions.

DV

Data validation

Check source state, definitions, traceability, evidence, time range and known gaps before publication.

NA

Narrative analysis

Explain material movement, blockers, residual risk and customer decisions without unsupported claims.

AP

Approval and publication

Apply the approved review, workflow, publication, supersession and retention process.

SD

Scheduled delivery

Manage approved cadence, recipients, delivery method and failed-delivery follow-up.

RR

Reporting review

Review whether the report continues to answer the audience questions and adjust approved definitions.

Operating lifecycle

From approved records to a reviewable report and retained artefact.

The report definition controls scope, period, metrics, evidence, narrative and authorised recipients.

01

Define

Confirm audience, questions, scope, period, products, metrics and required decisions.

02

Collect

Use the persisted Guardian records available for the customer and selected period.

03

Validate

Check definitions, source traceability, evidence, availability and known gaps.

04

Explain

Present material change, unresolved risk, service conditions and required decisions.

05

Approve

Apply review, approval, publication and supersession controls.

06

Deliver and retain

Publish or export to authorised recipients and retain the artefact history.

Common use cases

Common Guardian reporting use cases.

The product supports internal, customer, provider and executive audiences with explicit definitions.

MR

Monthly security review

Summarise current posture, material events, open risks, overdue actions and service health.

BR

Board reporting

Present priority risk, trend, decisions and evidence in a bespoke board-ready structure.

MS

MSP customer reporting

Provide consistent customer-safe reports across authorised provider relationships.

AS

Assessment reporting

Publish approved penetration, website, infrastructure or other assessment artefacts and follow-up.

SO

Security Operations reporting

Report sources, alerts, investigations, escalations, actions and unresolved monitoring gaps.

AR

Assurance and audit support

Provide traceable evidence and action history without claiming unsupported certification or compliance.

Operating model

How Guardian Security Reporting is onboarded, integrated, evidenced and scoped commercially.

These details remain explicit before activation, but are grouped into one operating view so buyers can review the responsibilities without working through four separate page sections.

ON

Onboarding and implementation

Reporting onboarding begins with audience questions and metric definitions. The customer identifies the audience, decisions, reporting period, products, measures, thresholds, narrative, recipients, branding, delivery, retention and approval requirements. Existing reports are reviewed to identify duplication and unsupported metrics. A draft report validates data availability, definitions, time range, source traceability, evidence and known gaps. Metrics without reliable data are removed or presented as unavailable rather than fabricated. Go-live records the approved definition, cadence, recipients, workflow, delivery, retention, supersession and change-control process.

IN

Connector and integration model

Reporting can include supported product and connector data without exposing their vendor implementation as the report structure. Each product contributes normalised Guardian records with source references and availability. The report uses product and outcome language while retaining traceability to the selected connector internally. New report data requires a defined source, customer ownership, metric logic, time model, availability state and evidence. A connector name alone is not a metric definition. Exports and external delivery use allow-listed fields and recipients. Raw upstream payloads, credentials and internal operational identifiers remain restricted.

EV

Data, evidence and reporting

Every reported result should be traceable to the record and definition that produced it. Guardian retains report version, definition, period, included products, source references, approval, artefact, recipients and supersession history where supported. Trend appears only where retained history and consistent definitions support it. Missing history is not reconstructed from current-state data. Reports distinguish measured data, analyst interpretation, customer decision and unavailable information so the reader can understand confidence and limitations.

CM

Commercial unit and responsibilities

Standard reporting is included in Guardian Core; bespoke reporting is an additional product. The package schedule identifies standard reports and cadence. Advanced Reporting identifies bespoke definitions, board packs, schedules, branding, exports, analyst narrative and delivery requirements. Custom data engineering, new connectors, complex historical reconstruction and specialist advisory analysis may require separate scope. The customer owns authorised recipients, internal decisions and use of the report. Damocles owns the report activities listed in the product schedule.

Frequently asked questions

Questions buyers ask about Guardian Security Reporting.

The exact answer is confirmed in the proposal and package schedule, but these points should be understood before activation.

Q1

Can reports be customised?

Yes through Advanced Reporting where the definition, data, narrative, approval and delivery are approved.

Q2

Can reports be scheduled?

Yes where the recipients, cadence, delivery, retention and failure handling are configured.

Q3

Can an MSP brand customer reports?

Potentially through an approved branding and provider-reporting model.

Q4

Are raw tool exports included?

Customer reports use allow-listed Guardian records. Raw upstream payloads are not exposed by default.

Q5

Can Guardian create historical trends immediately?

Only where retained records and consistent definitions support the period. Missing history is shown as unavailable.

Q6

Does a report prove compliance?

No. It can provide evidence and status but does not make unsupported legal, audit or certification determinations.

Scope and boundaries

Reporting availability follows the actual data, definitions and approved workflow.

Guardian does not fabricate missing trend history, complete source coverage, report artefacts or scheduled delivery.

Export fields, recipients, retention, branding, review and delivery methods are approved before use.

Reports support decisions and evidence but do not replace legal advice, formal audit or certification authority.

Take the next practical step

Review whether current reports explain risk movement and the actions still required.

We will map the audience, products, metrics, evidence, narrative, approval and delivery schedule to standard or advanced Guardian reporting.