Prisma Cloud Posture Report
Delivers a weekly report on Prisma Cloud coverage across your cloud accounts, what changed in the alerts and policies, and anything in the tenant that needs an admin, from ingestion errors to disconnected Defenders.
What this agent does
This read-only agent checks the health of a Prisma Cloud tenant every week. It finds cloud accounts, subscriptions, and projects that are not onboarded to Prisma Cloud, have ingestion errors, or have stopped ingesting. It summarizes the Critical and High alerts that appeared, were resolved, and were dismissed or snoozed since last week. It flags anything that needs an admin, such as an account whose role lost a permission, Defenders that disconnected, or an integration that stopped delivering.
The challenge
Prisma Cloud only protects the cloud accounts it is onboarded to, and gaps are easy to miss. A new account is created outside the organization-level onboarding, a role loses a permission, and ingestion for one service fails while the rest looks fine. A policy is disabled to quiet an alert and never turned back on. Dismissed alerts are hard to audit when nobody reviews who dismissed what. Runtime Defenders disconnect from a cluster and the workload findings stop.
The solution
The agent checks onboarding, ingestion, policies, Defenders, integrations, credit usage, and alert movement in one pass each week and compares them with the previous week. It lists what changed and what someone needs to act on, with the fix for each item. Provides a weekly briefing an admin can read in a few minutes.
Workflow
- 01
Check coverage
Find cloud accounts that are not onboarded, have ingestion errors, or whose last successful ingestion is older than a day.
- 02
Check activity
Summarize Critical and High alerts that appeared, were resolved, and were dismissed or snoozed since last week.
- 03
Check the tenant
Check policy and alert rule changes, Defender connectivity and versions, integrations, and credit usage.
- 04
Report
Publish what changed and what needs action, with the fix for each item.
Agent template
# Prisma Cloud Posture Report
## Measurable outcomes
Every week, the admin knows which cloud accounts Prisma Cloud is not covering, which policies and alert rules changed, how the Critical and High alerts moved, and what needs action before it breaks. Track covered and uncovered accounts, policy changes, and open action items on every run.
## Procedure
Once a week, list the cloud accounts, subscriptions, and projects Prisma Cloud is onboarded to, with each account's status and ingestion errors by service. Flag accounts with a failing status, with ingestion errors, or whose last successful ingestion is older than a day, unless I set another window. When I give it read-only access to my cloud organizations, compare their account lists with Prisma Cloud and flag any account Prisma Cloud has never seen. Summarize the new Critical and High alerts, the alerts resolved, and the alerts dismissed or snoozed since the last report, with who dismissed or snoozed each one and the note they left. Flag snoozes with no end date. Flag each policy disabled or enabled since last week and each alert rule whose scope changed, with who changed it from the audit log. Check Defender connectivity. Flag clusters and hosts whose Defenders disconnected in the window, and Defenders older than the Console version. Check each integration and flag any that is failing or has not delivered in the window. Compare credit usage with the licensed credits, and flag anything above 80 percent. List users with the System Admin role and flag any added since last week. Compare everything with last week's report, and lead with what changed. Give every action item the specific fix. Report a check it cannot run as not checked, never as fine.
## Requirements
It needs read-only Prisma Cloud API access to cloud accounts, policies, alert rules, alerts, integrations, users, the audit log, and credit usage. It also needs read-only Prisma Cloud Compute API access for Defenders, and optional read-only access to the cloud organizations for the account comparison, and nothing more. It never changes Prisma Cloud settings, policies, accounts, or alerts. Related templates
-
Aikido Issue Triage
Checks open Aikido findings against the affected repository and writes an evidence-backed decision back to each one.
Vulnerability Management / Application Security 4 tools -
Aikido Posture Report
Delivers a weekly report on Aikido coverage, what changed, and anything in the workspace that needs attention, from failing scans to plan limits.
Reporting and Compliance / Vulnerability Management 4 tools -
AWS Resource Logging and Delivery
Identifies the AWS log sources in an account that are not enabled or not delivering logs.
Reporting and Compliance / Infrastructure Operations 1 tools -
AWS Security Hub CSPM Finding Triage
Writes an evidence-based judgment for each open Critical and High Security Hub CSPM finding, verifies it against the live resource, and suppresses the ones the checks prove are false positives.
Featured Vulnerability Management 2 tools