iboss Inspector Summary

Summary

PropertyValue
Production StatusPreview
CategoryNetwork
DiscoversN/A — single launchpoint. One iboss account maps to one Liongard launchpoint; there is no parent/child discovery.

Description

Monitors a single iboss Zero Trust SSE account's security configuration: cluster and node topology, security policy layers and their allow/block list entries, default policy groups and reporting groups, statically defined proxy users and devices, locations (PAC zones) and private networks, SSL decryption posture, DLP content-analysis rules, firewall rules and ZTNA routed peers, and licensed module entitlements.

Asset Mapping: No asset-inventory mappings ship with this inspector — assetMappings.json ships as an empty array per Liongard's 2026-07-10 policy retiring asset-inventory mappings for new inspectors.


Data View Information

📘

This is a single-launchpoint inspector — there is no parent/child split. All 12 views below are collected on that one launchpoint.

Overview Table

  • Account & Licensing
    • Account Settings ID
    • Subscribed Modules
    • Modules Not Licensed
    • Accounts Visible To Credential
    • API Key Expiry Date
    • API Key Days Until Expiry
  • Discovered Hosts
    • Discovered Gateway Hostname
    • Discovered Reporting Hostname
    • Discovered Browser Isolation Hostname
  • Security Posture Summary
    • Cluster Count
    • Gateway Node Count
    • Reporting Cluster Count
    • Policy Count
    • Disabled Policy Count
    • Policy Group Count
    • Proxy User Count
    • Static Device Count
    • Devices In Default Policy Group
    • Blocklist Entry Count
    • Allowlist Entry Count
    • DLP Rules Enabled Count
    • SSL Bypassed Application Count
    • Allow/Block List Truncated

Data Tab Headers

  • Overview — Account & Licensing (11 fields), Discovered Hosts (8 fields), Security Posture Summary (13 fields)
  • Clusters & Nodes — Clusters table, 7 columns
  • Policies — Security Policies table, 10 columns
  • Allow / Block List Entries — List Entries table, 7 columns
  • Policy Groups — Default Policy Groups table (10 columns) and Reporting Groups table (3 columns)
  • Users & Devices — Proxy Users table (7 columns) and Static Devices table (5 columns)
  • Locations & Networks — Locations (PAC Zones) table (9 columns) and Private Networks table (2 columns)
  • SSL Decryption — Decryption Coverage (3 fields) and Bypassed Applications table (1 column)
  • DLP — Content Analysis Rules table, 6 columns
  • Firewall & ZTNA — Firewall Rules & ZTNA Peers table, 7 columns
  • Resource Catalog — Zero Trust Resources table, 6 columns
  • Cloud Preferences — Platform Preferences, 5 fields

Metrics

MetricDescription
iboss: Cluster CountNumber of clusters provisioned for this iboss account (secure web gateway, reporting and browser isolation).
iboss: Gateway Node CountTotal cluster member nodes across all clusters. A drop means a node was removed or failed out of its cluster.
iboss: Reporting Cluster CountNumber of reporting clusters. Zero means the account produces no report or URL-log data at all.
iboss: Policy CountTotal security policies: policy layers, resource policies, ZTNA routed policies and connector policies.
iboss: Disabled Policy CountSecurity policies that exist but are switched off. A disabled policy is the classic unnoticed security regression.
iboss: Policy Group CountNumber of default policy groups (the platform's 'filtering groups') that users and devices are assigned to.
iboss: Proxy User CountStatically defined proxy users. Tracks seat growth and stale-account accumulation.
iboss: Static Device CountStatically defined devices known to the gateway.
iboss: Devices In Default Policy GroupDevices left in the default policy group (group number -1). These run the weakest policy and are usually a misconfiguration.
iboss: Blocklist Entry CountURLs and domains across every blocklist policy layer. A sudden shrink is a filtering-coverage loss.
iboss: Allowlist Entry CountURLs and domains across every allowlist policy layer. Growth here quietly widens what bypasses filtering.
iboss: DLP Rules Enabled CountContent-analysis (DLP) rules that are switched on. Zero on a DLP-subscribed account means data-loss protection is off.
iboss: SSL Bypassed Application CountApplications excluded from HTTPS decryption. Every entry is an inspection blind spot, and the list grows quietly.
iboss: Subscribed Module CountNumber of licensed iboss modules on the account (DLP, Private Access and so on). Tracks entitlement drift and upsell opportunity.
iboss: API Key Days Until ExpiryDays until the iboss API credential expires. When it lapses, every iboss integration the MSP runs stops silently.

Actionable Alerts

RuleTriggerSeverity
No reporting cluster provisionediboss: Reporting Cluster Count equals 0High
Security policies are disablediboss: Disabled Policy Count is greater than 0High
API key expires within 30 daysiboss: API Key Days Until Expiry is less than 30High
Allowlist contents changediboss: Allowlist Entry Count changes since the previous inspectionMedium
Devices left in the default policy groupiboss: Devices In Default Policy Group is greater than 0Medium
Module entitlements changediboss: Subscribed Module Count changes since the previous inspectionLow

Did this page help you?