Executive Risk Posture
FortiGate telemetry is converted into prioritized findings with explainable evidence.
AI Usage Risk
DNS Control
DNS control posture will appear after a snapshot.
The AI layer summarizes structured findings and recommended action, while scoring remains evidence-based.
Priority Findings
Risk Signal Matrix
Signal Intensity
All Findings
Finding Detail
Policy & Destination Exposure
| Policy | Port | Countries | Events | Risk |
|---|
Asset Risk Distribution
Finding Evidence
Top Domains
Top Clients
DNS Control Posture
Set the DNS servers owned or approved by your organization.
Approved Organization DNS
Enter internal DNS IP addresses separated by commas. Example: 192.168.2.1, 192.168.2.2
Why It Matters
A controlled DNS path improves visibility and helps detect clients that bypass the organization resolver by using public DNS directly.
Detected AI Services
Services observed across retained collector snapshots. Prompts, responses, files, and HTTPS payloads are not collected.
| Service | Provider | Clients | DNS Queries | Sessions | Bytes Out / In | Risk Signal |
|---|
Usage Signal
Scope
Which AI services appear in the organization’s network and how often they are observed.
It does not inspect prompts, responses, uploaded files, or the content of encrypted traffic.
Identified AI Clients
Identity priority: authenticated user, hostname, then IP address. IP is retained as supporting evidence.
| Identity | User | Hostname | IP Address | AI Services |
|---|
AI Usage Risk Assessment
Recommended Actions
Total Events
Events retained in each collector snapshot
Risk Findings
Correlated findings in each collector snapshot
AI Network Sessions
Unique sessions associated with detected AI services
AI Outbound Traffic
Bytes sent from clients to detected AI services
Snapshot History
Each row is one unique snapshot window. Values are not added across snapshots.
| Snapshot Time | Total Events | Findings | Exposure | DNS Queries | AI Services | AI Sessions | AI Out / In |
|---|
AI Narrative
Recommended Command Deck
Edge Collector Monitor
| Collector | Status | Log Rate | Last Log | Buffer | Dropped | Events | Findings |
|---|
Manual Snapshot
Request a fresh snapshot, then run the Edge Collector push command from your collector machine.
CISO Report
Generate a concise executive report from the latest snapshot, AI insight, and findings.
My Profile
Your session remains active after saving, but the new password will be required next time.
Account Summary
Add Admin User
Admin accounts are stored in the cloud database and require a valid admin session.
Admin Users
| Name | Role | Status | Action |
|---|
AI Policy
This guidance is added to the AI prompt when a new AI Insight is generated. It does not regenerate old locked insights.
How AI Uses It
Use this to control risk appetite, approved exposure rules, wording, and preferred mitigation style.
Snapshot Mode
Collectors receive policy changes automatically during their next check-in. No restart is needed.
Current Behavior
Manual Snapshot on the Collectors page remains available in both modes.
Add Edge Collector
The token column only shows a preview. This full secret is shown only after rotation. Put it on the Edge Collector machine, not in GitHub.
Registered Edge Collectors
| Name | Collector ID | Site | Status | Last Seen | Token | Action |
|---|
Add Log Source
Registered Sources
| Device | Vendor | Product | Parser | Collector | Zone | Action |
|---|