Skip to main content
{ Reporting and Compliance / Vulnerability Management }

Orca Posture Report

Delivers a weekly report on Orca coverage across your cloud accounts, what changed in the alerts, and anything in the tenant that needs an admin, from failing account connections to stale scans.

What this agent does

This read-only agent checks the health of an Orca Security tenant every week. It finds cloud accounts, subscriptions, and projects that Orca is not connected to or has stopped scanning. It summarizes the Critical and High alerts that appeared, were closed, and were dismissed or snoozed since last week. It flags anything that needs an admin, such as a connection whose role lost permissions, a scan that has not completed in the window, or an integration that stopped delivering.

The challenge

Orca only protects the cloud accounts it can see, and gaps in coverage are easy to miss. A new account is created outside organization-level onboarding, a connection's role loses a permission, and scans stop without anyone noticing. Dismissed alerts are hard to audit when nobody reviews who dismissed what. A ticketing or messaging integration fails and the alerts stop reaching the team.

The solution

The agent checks coverage, scan health, activity, and integrations in one pass each week and compares them with the previous week. It lists what changed and what someone needs to act on, with the fix for each item. Provides a weekly briefing an admin can read in a few minutes.

Workflow

  1. 01

    Check coverage

    Find cloud accounts, subscriptions, and projects that Orca is not connected to, has a failing connection for, or has not scanned in the window.

  2. 02

    Check activity

    Summarize Critical and High alerts that appeared, were closed, and were dismissed or snoozed since last week.

  3. 03

    Check the tenant

    Check integrations, automations, and users with admin roles.

  4. 04

    Report

    Publish what changed and what needs action, with the fix for each item.

Agent template

# Orca Posture Report

## Measurable outcomes

Every week, the admin knows which cloud accounts Orca is not covering, what changed in the tenant, and what needs action before it breaks. Track covered and uncovered accounts and open action items on every run.

## Procedure

Once a week, list the cloud accounts, subscriptions, and projects Orca knows about. Flag the ones whose connection is failing or has lost permissions, and the ones with no completed scan in the last two days, unless I set another window. When I give it read-only access to my cloud organizations, compare their account lists with Orca and flag any account Orca has never seen. Summarize the new Critical and High alerts, the alerts closed, and the alerts dismissed or snoozed since the last report, with who dismissed or snoozed each one and the reason they gave. Flag snoozes with no end date. Check each integration and automation and flag any that is failing, or that sent nothing while matching alerts appeared. List users with admin roles and flag any added since last week. Compare everything with last week's report, and lead with what changed. Give every action item the specific fix. Report a check it cannot run as not checked, never as fine.

## Requirements

It needs read-only Orca API access to the tenant, and optional read-only access to the cloud organizations for the account comparison, and nothing more. It never changes Orca settings, connections, or alerts.