Appearance
Reports
Path: /reports
Reports are attribution exposure events.
See the screenshot and field list in Objects and terms.
They include ownership. They are not the same list as Exposures.
- First-party is your org.
- Joint is shared.
- Third-party is vendor-attributed.
A letter grade on Vendor Monitoring is a scorecard.
Do not treat a report row as the close action. See the investigation playbook.
Scorecard charts
The page shows posture charts for the current filter set:
- Posture meter
- Indicator breakdown
- Platform donut
- Severity trend
Filters
Use the filters to narrow the list.
| Filter | What it does |
|---|---|
| Search | Text match on the report |
| Minimum severity | Low, Medium, High, or Critical |
| Ownership | First-party, joint, third-party, or all ownership types |
| Source | Source of the report |
| Age | 7 days, 30 days, 90 days, 180 days, or 1 year |
| Leaker domain | Domain that published the leak |
| False positives | Show true positives (default) or false positives |
| Remediated | Hidden by default. Turn on to include fixed items |
Attribution confidence does not hide an approved report.
Lower confidence reduces how much a vendor incident weighs on the TPRM scorecard.
It does not remove the row.
Status actions
You can mark a report as:
- False positive — treated as safe and hidden by default
- Remediated — treated as fixed and hidden by default
Open a report to read the full attribution view.
Open a report
Select a row to open the report detail.