Prisma AIRS · AI Runtime Security

Daily security review · Synthetic example

Attention required

Rolling last 24 hours, UTC (approximate for server-relative application queries)

Collected 2026-09-07T08:00:00.000Z → 2026-09-07T08:00:00.000Z
Read-only evidence · Confidential environment metadata

Sessions in collected app buckets1,300
Violating sessions51
Violation rate3.92%
Complete evidence sources7 / 7

What needs attention

Observed violations and configuration review items, not a numerical health score. Collection gaps remain visible in the evidence table.

attention

Violating sessions observed

Evidence: 51 violating sessions across 2 application buckets in the collected daily data.

Next step: Review the highest-volume applications in SCM, confirm intended enforcement, and investigate unexpected activity. Violations are not proof of a successful attack.

Source: Daily application activity

review

Timeout allows traffic: Staging availability

Evidence: An active profile explicitly sets inline-timeout-action to allow.

Next step: Review the availability-versus-enforcement tradeoff with the application owner; this is not evidence of a timeout or bypass.

Source: Security profiles

review

Inactive profile: Retired experiment

Evidence: The latest returned revision is explicitly inactive.

Next step: Confirm this is intentional before assigning the profile to an integration.

Source: Security profiles

Daily application activity

API-reported rolling one-day application buckets, ranked by violating sessions. Partial-source totals cover collected buckets only. Violating sessions are not necessarily blocked sessions.

3 collected rows
Application bucketSessionsViolating sessionsViolation rateRegistered ID match
Customer support860435%Yes
Engineering assistant32082.5%Yes
Document search12000%Yes

Current security profiles

Latest returned revision per profile name. These are current settings, not a record of changes during the daily window.

3 collected rows
ProfileRevisionActiveTimeout actionStorage maskingLast modified (UTC)
Production protection8YesblockOn in all returned configurations2026-09-06T08:00:00.000Z
Retired experiment1NoUnknownUnknownUnknown
Staging availability2YesallowOn in all returned configurationsUnknown

Registered application inventory

Current registered applications, separate from scan-metadata application buckets. Association counts do not establish key validity or deployment health. No key values or auth codes are included.

3 collected rows
ApplicationEnvironmentCloudModelKey associations
Engineering servicestagingazureExample modelUnknown
Search serviceproductiongcpUnknownUnknown
Support serviceproductionawsExample model0

Collected session observations

Source: complete. Timestamp-eligible entries: 1,300. Violated status: 51. Missing timestamps: 0; outside window: 0. These are collected session counts, not scan actions or detector events. No scan content is fetched.

2 collected rows
Session statusEntries
passed1,249
violated51

Daily session chart

Independent chart totals: 1,300 sessions; 51 violating sessions. Do not force these counters to equal a separately paginated inventory.

1 collected rows
Bucket time (UTC)SessionsViolating sessionsDetector violations
2026-09-07T07:00:00Z1,3005152

Top applications by detector violations

Server-ranked subset for one day, not a complete application inventory. Detector violations may exceed the number of violating sessions.

1 collected rows
Application bucketDetector violationsDetection types
Customer support52pi: 52

Daily detector severity trend

API-reported detector-policy events over the rolling day. Severity counts are preserved independently from distinct session counts; no previous-day comparison is inferred.

1 collected rows
Bucket time (UTC)CriticalHighMediumLowTotal
2026-09-07T07:00:00Z0052052

Evidence and collection coverage

Complete means pagination finished for that source, not that the environment is secure or that all traffic was ingested. Unavailable does not mean zero.

7 collected rows
Source / SDK methodWindowStatusRecordsPagesCollection notes
Daily application activity — dashboard.applicationsOverviewRolling 1 daycomplete31Collection completed.
Security profiles — profiles.list (latest=true)Current configurationcomplete31Collection completed.
Registered applications — customerApps.listCurrent configurationcomplete31Collection completed.
Daily session inventory — dashboard.sessionsOverviewRolling 1 daycomplete1,30052Collection completed.
Daily session chart — dashboard.sessionsChartRolling 1 daycomplete11Collection completed.
Top application violations — dashboard.topApplicationsViolationsRolling 1 day; server-ranked subsetcomplete11Collection completed.
Daily violation trend — dashboard.applicationsViolationsTrendRolling 1 daycomplete11Collection completed.

Scope, privacy, and limitations