External reporting

View as Markdown

Platform

External reporting packages a dashboard, an inventory view, or a runZero report into a point-in-time snapshot that you can share with people who do not have a runZero account. Recipients open a link, verify their email address, and view the snapshot in a read-only browser page. Snapshots are immutable, scoped to the organizations you select, and can be regenerated on a recurring schedule.

Use it to give executives, auditors, customers, or other teams an at-a-glance view of your asset inventory, security posture, or a specific report without provisioning runZero accounts for them.

What you can share

You can share two types of external report:

  • A Dashboard report captures any dashboard you can view, including cross-organization shared dashboards. The snapshot holds the dashboard widgets for a configurable date window.
  • An Inventory report captures an asset, software, service, or vulnerability inventory query, including the columns you have selected and the current sort order. The snapshot freezes the matching rows and serves them to the recipient as a read-only table.

Sharing a report

You can start an external report from anywhere in the runZero Console that displays one of the supported views:

  • Open the dashboard and click the Share button in the header. The button appears on dashboards that can be shared, such as runZero-managed and cross-organization dashboards.
  • From an inventory page (Assets, Software, Services, or Vulnerabilities), run the query you want to share and use the Share button to create an external report. The current query, columns, and sort order are saved with the report.

The External Reports page lists every report you have created and lets you edit or delete them.

Share dialog options

When you create or edit an external report, the share dialog asks for:

  • Report name identifies the report in the runZero Console and appears in the email sent to recipients.
  • Email recipients lists one or more email addresses to notify each time a snapshot is generated. The notification email contains the link recipients use to open the report.
  • Report frequency sets how often the report regenerates. Choose One time for a single snapshot, or Daily, Weekly, or Monthly for a recurring schedule.
  • Organizations (My Organizations view) selects the organizations whose data the snapshot includes. You can only include organizations you have access to.
  • Automatically include new organizations (My Organizations view) adds organizations created after the report is set up to future runs of a recurring report, provided you have access to them.

Click Send report to save the configuration and queue the first snapshot. Snapshot generation runs in the background, and runZero emails the recipients as soon as the snapshot is ready.

How recipients view a report

When a snapshot is generated, each recipient receives an email with a link to the report. The first time they open the link, runZero asks them to accept the runZero terms of service.

runZero then emails a single-use verification link to that address. Clicking it confirms the recipient’s identity, sets a secure session cookie that lasts for 30 days, and redirects them to the report. While the cookie is valid, the recipient can return to the same report, or to any other report shared with the same email address by the same runZero account, without verifying again.

The verification link expires 30 minutes after it is sent. A recipient who misses that window can request a new one by reopening the report link and entering their email address again.

Recipients whose runZero account has access to one of the report’s organizations can open the report with their existing session and skip the email verification step.

Managing reports and snapshots

The External Reports page shows every external report your organization has created, grouped under three tabs:

  • All shows every external report.
  • One-time shows reports configured to run once.
  • Recurring shows reports configured to run on a daily, weekly, or monthly schedule.

Clicking a report opens its details page, which shows the report’s configuration and a table of every snapshot generated so far. From this page you can:

  • Edit the parent report to change its name, recipients, schedule, date window, or organizations. Edits affect future runs only; existing snapshots stay as they are.
  • Delete the parent report, which stops future runs and removes all of its snapshots.
  • Copy the share link for an individual snapshot.
  • Revoke a snapshot’s access link. Revoking invalidates the URL so it can no longer open the report, but leaves the snapshot record in place for auditing.
  • Delete an individual snapshot, which revokes its link and removes the captured data.

Each snapshot link is valid for 90 days from the time the snapshot is created. After that the link stops working; recipients of recurring reports continue to receive a fresh link in each run’s email.

Security and access

External reporting is designed so that report data leaves runZero only through links you explicitly create:

  • Each snapshot link contains a 256-bit random token signed with a per-account HMAC key. runZero rejects tampered or fabricated links without a database lookup.
  • Before a recipient can view a snapshot, they must prove ownership of an email address by clicking a verification link sent to that address. Their identity is then carried in a secure, account-scoped browser cookie.
  • Each time a recurring report runs, runZero re-checks the original creator’s access to the report’s organizations. Organizations they no longer have access to are dropped from the snapshot. If they have lost access to all of the report’s organizations, the run is skipped.
  • Every successful access of an external report is recorded as an external-report-viewed event for each organization in the snapshot. The event includes the recipient’s email address, IP, and user agent, and appears in the runZero activity log.
  • The public verification and access endpoints are rate limited to mitigate abuse.
  • You can revoke any snapshot link at any time from the report’s details page. Revoked links cannot be reactivated.
Updated