Skip to main content
{ Reporting and Compliance / Vulnerability Management }

Wiz Posture Report

Delivers a weekly report on Wiz coverage across your cloud accounts, what changed, and anything in the tenant that needs attention, from failing connectors to license use.

What this agent does

This read-only agent checks the health of a Wiz tenant every week. It finds cloud accounts, subscriptions, and projects that Wiz is not connected to or has stopped scanning. It summarizes the issues that appeared, were resolved, or were rejected since last week. It flags anything that needs an admin, such as a failing connector, workloads missing the Wiz sensor, or usage close to the contract's limits.

The challenge

Wiz only protects the cloud accounts it can see, and gaps in coverage are easy to miss. A new account is created outside the organization connector, a connector's role loses permissions, and scans stop without anyone noticing. Rejected issues are hard to audit when nobody reviews who rejected what. Billable workload counts grow past the contract, and admins find out at renewal.

The solution

The agent checks coverage, activity, and tenant limits in one pass each week and compares them with the previous week. It lists what changed and what someone needs to act on, with the fix for each item. Provides a weekly briefing an admin can read in a few minutes.

Workflow

  1. 01

    Check coverage

    Find cloud accounts, subscriptions, and projects that Wiz is not connected to or has not scanned recently.

  2. 02

    Check activity

    Summarize issues that appeared, were resolved, or were rejected since last week.

  3. 03

    Check the tenant

    Check connectors, sensor deployment, integrations, and usage against the contract's limits.

  4. 04

    Report

    Publish what changed and what needs action, with the fix for each item.

Agent template

# Wiz Posture Report

## Measurable outcomes

Every week, the admin knows which cloud accounts Wiz is not covering, what changed in the tenant, and what needs action before it breaks. Track covered and uncovered accounts and open action items on every run.

## Procedure

Once a week, list the cloud accounts, subscriptions, and projects Wiz knows about. Flag the ones with no connector, a failing connector, or no scan in the last day, unless I set another window. When I give it read-only access to my cloud organizations, compare their account lists with Wiz and flag any account Wiz has never seen. Flag workloads that should run the Wiz sensor and do not, and sensors on outdated versions. Summarize the new Critical and High issues, the issues resolved, and the issues rejected since the last report, with who rejected them and why. Check each integration and service account, and flag any that are failing or about to expire. Compare billable usage with the contract's limits, and flag anything above 80 percent. Compare everything with last week's report, and lead with what changed. Give every action item the specific fix. Report a check it cannot run as not checked, never as fine.

## Requirements

It needs read-only Wiz API access to the tenant, and optional read-only access to the cloud organizations for the account comparison, and nothing more. It never changes Wiz settings, connectors, or issues.