Ask Roar Prompt Library
Ask Roar Prompt Library
Ask Roar lets you ask plain-language questions about your environment and get answers drawn straight from your live Liongard data — no queries or dashboards to build. This library is a starting set of questions to try, organized by what you want to learn. Paste any prompt as-is, or adjust the numbers (days, thresholds) to fit your needs.
Getting the Best Answers
- Keep it about the data. Ask "Which user accounts are guest accounts?" rather than naming your company or tenant — Ask Roar already knows which environment you're in.
- Ask one thing at a time. Start with a focused question, then ask a follow-up to go deeper.
- Use specific numbers. "Expiring in the next 60 days" or "changes in the last 7 days" gives sharper, more actionable answers.
- Ask for the "so what." Adding "and what does each one mean?" turns a list into insight you can act on.
- Confirm when asked. Roar sometimes checks its plan before pulling data ("Does this sound right?") — just click Yes, proceed to get your answer.
Asset Inventory & Discovery
Know what you have — the foundation of every security and compliance conversation.
| Prompt | What You'll Learn |
|---|---|
| Which operating systems are running on our devices, and are any end-of-life or no longer supported? | A full OS breakdown with support dates, so you can spot systems that need upgrading. |
| List our devices and the operating system each is running, with when each was last seen. | An inventory with last-seen dates to catch stale or unmanaged assets. |
| List all user accounts and flag which ones are administrators. | A complete identity list with privileged accounts called out. |
| Which user accounts are guest or external accounts? | External accounts invited into your tenant — an easy thing to lose track of. |
| Which systems haven't been inspected recently? | Coverage gaps where data may be out of date. |
Security & Compliance Auditing
Aligned to the CIS Controls — the questions auditors and cyber-insurance forms tend to ask.
| Prompt | CIS Control | What You'll Learn |
|---|---|---|
| Give me a summary of identity risk: how many accounts are admins, how many lack MFA, and how many are inactive. | 5, 6 | A single snapshot of your biggest access risks. |
| Which user accounts don't have multi-factor authentication enabled? | 6 | The specific accounts missing MFA — one of the most common findings. |
| Which devices don't have endpoint protection (EDR) installed? | 10 | Where your endpoint coverage has gaps. |
| Are any accounts inactive or dormant and worth reviewing? | 5 | Stale accounts that widen your attack surface. |
| Is disk encryption enabled on our servers and workstations? | 3 | Encryption coverage across your devices. |
| Is Remote Desktop (RDP) enabled or exposed on any devices? | 4 | RDP exposure, a frequent entry point for attackers. |
Identity & Access
Go a layer deeper on your people and their permissions.
| Prompt | What You'll Learn |
|---|---|
| List our administrator accounts and when each one last signed in. | Whether admin access is being used or has gone stale. |
| Which accounts have passwords set to never expire? | Long-lived credentials that may violate your password policy. |
| Which accounts are enabled but have never signed in? | Accounts that were set up and forgotten. |
| Are there any shared or generic administrator accounts? | Admin access that can't be traced to a specific person. |
Changes & Alerts
Stay ahead of what's changing and what needs attention.
| Prompt | What You'll Learn |
|---|---|
| List our open critical and high-priority alerts with their titles, and explain what each one is telling us. | An itemized list of the exact alerts — system, severity, and a plain-language explanation of each. |
| Which open alerts should we prioritize today? | Helps focus on the highest-impact issues first. |
| What configuration changes have been detected in the last 7 days? | Every tracked change — DNS records, admin adds, policy edits — in one place. |
| Which systems have had the most changes or alerts this month? | Where risk or instability is concentrated. |
| Are any domains or SSL/TLS certificates expiring in the next 60 days? | Expirations to renew before they cause an outage. |
Digging into a Specific System
When you want to understand how one type of system is set up — often after seeing an alert. Naming the type of system (firewall, Microsoft 365, backup) helps.
| Prompt | Best For |
|---|---|
| Have there been any recent changes to our firewall configuration? | Firewall and network devices. |
| Which DNS records or subdomains have changed recently, and could any be unexpected? | Domain and DNS monitoring. |
| Are all our backup jobs running successfully, and when did each last complete? | Verifying your backups are protecting you. |
| What security and conditional access policies are in place, and have any changed? | Microsoft 365 / Entra ID settings. |
| Show me the security posture of a specific server — EDR, encryption, firewall, and RDP status. | Reviewing a single machine in detail. |
Ask Roar can only answer questions about the systems Liongard is inspecting. If a prompt returns "no data," the related integration may not be set up yet — reach out to your IT provider to enable it.
Updated about 7 hours ago

