iboss Inspector Summary
Summary
| Property | Value |
|---|---|
| Production Status | Preview |
| Category | Network |
| Discovers | N/A — single launchpoint. One iboss account maps to one Liongard launchpoint; there is no parent/child discovery. |
Description
Monitors a single iboss Zero Trust SSE account's security configuration: cluster and node topology, security policy layers and their allow/block list entries, default policy groups and reporting groups, statically defined proxy users and devices, locations (PAC zones) and private networks, SSL decryption posture, DLP content-analysis rules, firewall rules and ZTNA routed peers, and licensed module entitlements.
Asset Mapping: No asset-inventory mappings ship with this inspector — assetMappings.json ships as an empty array per Liongard's 2026-07-10 policy retiring asset-inventory mappings for new inspectors.
Data View Information
This is a single-launchpoint inspector — there is no parent/child split. All 12 views below are collected on that one launchpoint.
Overview Table
- Account & Licensing
- Account Settings ID
- Subscribed Modules
- Modules Not Licensed
- Accounts Visible To Credential
- API Key Expiry Date
- API Key Days Until Expiry
- Discovered Hosts
- Discovered Gateway Hostname
- Discovered Reporting Hostname
- Discovered Browser Isolation Hostname
- Security Posture Summary
- Cluster Count
- Gateway Node Count
- Reporting Cluster Count
- Policy Count
- Disabled Policy Count
- Policy Group Count
- Proxy User Count
- Static Device Count
- Devices In Default Policy Group
- Blocklist Entry Count
- Allowlist Entry Count
- DLP Rules Enabled Count
- SSL Bypassed Application Count
- Allow/Block List Truncated
Data Tab Headers
- Overview — Account & Licensing (11 fields), Discovered Hosts (8 fields), Security Posture Summary (13 fields)
- Clusters & Nodes — Clusters table, 7 columns
- Policies — Security Policies table, 10 columns
- Allow / Block List Entries — List Entries table, 7 columns
- Policy Groups — Default Policy Groups table (10 columns) and Reporting Groups table (3 columns)
- Users & Devices — Proxy Users table (7 columns) and Static Devices table (5 columns)
- Locations & Networks — Locations (PAC Zones) table (9 columns) and Private Networks table (2 columns)
- SSL Decryption — Decryption Coverage (3 fields) and Bypassed Applications table (1 column)
- DLP — Content Analysis Rules table, 6 columns
- Firewall & ZTNA — Firewall Rules & ZTNA Peers table, 7 columns
- Resource Catalog — Zero Trust Resources table, 6 columns
- Cloud Preferences — Platform Preferences, 5 fields
Metrics
| Metric | Description |
|---|---|
| iboss: Cluster Count | Number of clusters provisioned for this iboss account (secure web gateway, reporting and browser isolation). |
| iboss: Gateway Node Count | Total cluster member nodes across all clusters. A drop means a node was removed or failed out of its cluster. |
| iboss: Reporting Cluster Count | Number of reporting clusters. Zero means the account produces no report or URL-log data at all. |
| iboss: Policy Count | Total security policies: policy layers, resource policies, ZTNA routed policies and connector policies. |
| iboss: Disabled Policy Count | Security policies that exist but are switched off. A disabled policy is the classic unnoticed security regression. |
| iboss: Policy Group Count | Number of default policy groups (the platform's 'filtering groups') that users and devices are assigned to. |
| iboss: Proxy User Count | Statically defined proxy users. Tracks seat growth and stale-account accumulation. |
| iboss: Static Device Count | Statically defined devices known to the gateway. |
| iboss: Devices In Default Policy Group | Devices left in the default policy group (group number -1). These run the weakest policy and are usually a misconfiguration. |
| iboss: Blocklist Entry Count | URLs and domains across every blocklist policy layer. A sudden shrink is a filtering-coverage loss. |
| iboss: Allowlist Entry Count | URLs and domains across every allowlist policy layer. Growth here quietly widens what bypasses filtering. |
| iboss: DLP Rules Enabled Count | Content-analysis (DLP) rules that are switched on. Zero on a DLP-subscribed account means data-loss protection is off. |
| iboss: SSL Bypassed Application Count | Applications excluded from HTTPS decryption. Every entry is an inspection blind spot, and the list grows quietly. |
| iboss: Subscribed Module Count | Number of licensed iboss modules on the account (DLP, Private Access and so on). Tracks entitlement drift and upsell opportunity. |
| iboss: API Key Days Until Expiry | Days until the iboss API credential expires. When it lapses, every iboss integration the MSP runs stops silently. |
Actionable Alerts
| Rule | Trigger | Severity |
|---|---|---|
| No reporting cluster provisioned | iboss: Reporting Cluster Count equals 0 | High |
| Security policies are disabled | iboss: Disabled Policy Count is greater than 0 | High |
| API key expires within 30 days | iboss: API Key Days Until Expiry is less than 30 | High |
| Allowlist contents changed | iboss: Allowlist Entry Count changes since the previous inspection | Medium |
| Devices left in the default policy group | iboss: Devices In Default Policy Group is greater than 0 | Medium |
| Module entitlements changed | iboss: Subscribed Module Count changes since the previous inspection | Low |
Updated about 3 hours ago

