OOTB Dashboards

Veza dashboards help security teams:

  • Identify risks across your authorization landscape

  • Monitor activity and detect anomalies

  • Review misconfigurations in SaaS and cloud platforms

  • Analyze access patterns for users, groups, and resources

  • Track privileged access across integrated systems

Veza provides 58 out-of-the-box (OOTB) dashboards that deliver immediate insights into your authorization graph. These dashboards are automatically available to all Veza tenants and are organized into categories based on their focus area:

  • Activity Monitoring

  • Authorization Risk

  • Cloud IAM

  • Data Warehouse and Data Lake Insights

  • SaaS Misconfiguration Reports

  • General

Each dashboard contains curated saved queries that focus on specific security and governance use cases.

This document lists each out-of-the-box dashboard as a quick reference. You can access all system dashboards in Veza from the Saved Queries view.


Quick Reference

Jump directly to any dashboard:


Using OOTB Dashboards

Accessing Dashboards

  1. Navigate to Access Intelligence > Dashboards in the Veza UI

  2. OOTB dashboards are pre-loaded and available immediately in the dashboard library

  3. Use the category filters to browse dashboards by type

  4. Click any dashboard to view its curated insights and saved queries

For more information about dashboard features, time controls, filtering, and sharing capabilities, see the Dashboards Overview.

Using Dashboard IDs

Each OOTB dashboard has a stable, unique identifier (Dashboard ID) that you can use to:

  • Construct direct URLs to specific dashboards for sharing or bookmarking

  • Integrate with automation using the Assessment Reports API

  • Reference dashboards in scripts and workflows

Accessing Dashboards by ID

You can access any dashboard directly using this URL pattern:

https://your-tenant.veza.com/app/dashboard/library/{dashboard_id}

Example: To access the AWS IAM Insights dashboard:

https://your-tenant.veza.com/app/dashboard/library/64e4231c-ead9-4bf0-bed7-afa94511f476

Replace your-tenant with your organization's Veza tenant name.

Programmatic Access via API

Veza provides a comprehensive REST API for working with dashboards (called "Assessment Reports" in the API). You can use dashboard IDs to:

  • Retrieve dashboard configuration and metadata

  • Fetch time-series data for dashboard queries

  • Manage custom dashboards programmatically

  • Share dashboards between teams

For complete API documentation, see Dashboard APIs.

Dashboard Visibility and Integration Requirements

All OOTB dashboards are visible to all customers, regardless of which integrations are configured in your Veza tenant. This design allows you to:

  • Discover available insights as you plan to add new integrations

  • Understand the full analytical capabilities of the Veza platform

  • Preview dashboard contents before connecting additional systems

What happens when you lack required integrations:

  • Dashboards remain visible in the dashboard library

  • Opening a dashboard will show empty results or "No data" messages if the required entities don't exist in your authorization graph

  • You can use the Integration filter in the Dashboards UI to show only dashboards relevant to your configured integrations

Example: If your tenant has only AWS and Okta integrations configured, you'll see all 58 OOTB dashboards. However, Snowflake-specific dashboards will return no results when opened. Use the Integration filter to display only AWS and Okta dashboards.

Creating Custom Dashboards from OOTB Templates

While OOTB dashboards cannot be modified directly, you can create customized versions:

  1. Clone an OOTB dashboard: Open any OOTB dashboard and use the Clone action (⋮ menu) to create a custom copy

  2. Customize the cloned dashboard: Add or remove queries, adjust filters, and tailor the dashboard to your specific needs

  3. Share custom dashboards: Once cloned, you can share your customized dashboard with other teams in your organization

Why create custom dashboards:

  • Filter to specific business units or departments

  • Combine queries from multiple OOTB dashboards

  • Add your own custom saved queries alongside OOTB queries

  • Share tailored insights with specific teams based on their integration scope

Only custom (cloned) dashboards can be shared between teams. OOTB dashboards are already available to all users with access to the required integrations. See the Dashboard Sharing Guide for detailed sharing workflows.

For detailed instructions on customizing dashboards, managing saved queries, and configuring alerts, see the Dashboards Overview.


Dashboard Reference

The following sections provide a complete reference of all OOTB dashboards, organized by category.

Activity Monitoring

Snowflake Activity Report

Category: Activity Monitoring

This report provides insights into Snowflake activity across logins, dormant users and roles, over-provisioned users and roles, and overprovisioned resources. Requires Activity for Snowflake to be enabled in Veza Systems Settings order to see data. (22 saved queries). Dashboard ID: 86a0a926-e7a5-4d64-a056-46ec5af68b96.

Authorization Risk

AWS IAM Insights

Category: Authorization Risk

AWS IAM Insights (32 saved queries). Dashboard ID: 64e4231c-ead9-4bf0-bed7-afa94511f476.

AWS Risks

Category: Authorization Risk

AWS Risks by priority (29 saved queries). Dashboard ID: adc15d2b-fcae-429b-b074-1e61df7bda6c.

Active Directory Risks

Category: Authorization Risk

Active Directory Risks by priority (22 saved queries). Dashboard ID: 69e0f4d9-2d20-41d7-9c22-fe518ea2e28e.

Azure AD Risks

Category: Authorization Risk

Azure AD Risks by priority (27 saved queries). Dashboard ID: 0b1c1abe-66aa-463c-88c3-505bba76e693.

GitHub Security

Category: Authorization Risk

Github Security insights around Access, NHI, and Hygiene (28 saved queries). Dashboard ID: 006d7cf5-2cd5-4eb1-aac3-f6298b368e8e.

Google Cloud IAM Insights

Category: Authorization Risk

Google Cloud IAM Insights (17 saved queries). Dashboard ID: 47b52261-21b9-401a-8e44-4f44cb981ef8.

IDP Identity Insights

Category: Authorization Risk

Identity Insights across IDP Identities, IDP Identity Groups, Local Identities (29 saved queries). Dashboard ID: 8d285337-2687-4e49-a2d6-a38990ef1f18.

Identity Security Posture Management Insights (ISPM)

Category: Authorization Risk

Insights around password security, MFA, blast radius, secrets management risks, identity posture for strong ISPM (48 saved queries). Dashboard ID: 272874c4-1efe-40ed-b18c-c490d73e55ab.

Identity and Privilege Access Insights

Category: Authorization Risk

Important findings relating to identity and privileged access, including potential risks and misconfigurations (94 saved queries). Dashboard ID: 3ee89f3a-811d-4508-8da4-ceda449b19c0.

NHI Overview Insights

Category: Authorization Risk

Overview of NHI inventory and risks insights (31 saved queries). Dashboard ID: 8542b7ae-43ed-43d0-9cc2-dc18d4005df3.

Okta Risks

Category: Authorization Risk

Okta Risks by priority (27 saved queries). Dashboard ID: eb942c6f-74f7-44d3-b5f5-4188ae53326c.

PCI 4.0 Insights Report

Category: Authorization Risk

Veza's support for PCI 4.0 requirement subsections (16 saved queries). Dashboard ID: 3ca3557d-0fcd-4a8b-82c9-0998823481b6.

Salesforce Risks

Category: Authorization Risk

Salesforce risks by priority (23 saved queries). Dashboard ID: 5ef75bc5-6363-4618-82c6-cefe1ec64176.

ServiceNow Security

Category: Authorization Risk

ServiceNow Insights around Inventory and Risks (12 saved queries). Dashboard ID: 8f623917-95a6-4a50-a509-56b1f4b630bb.

Snowflake Risks

Category: Authorization Risk

Snowflake risks by priority (30 saved queries). Dashboard ID: 56306215-7ea7-4588-bb69-b4624030a09b.

Cloud IAM

Cloud IAM Insights

Category: Cloud IAM

Important findings relating to Cloud IAM Insights, including potential risks and misconfigurations (86 saved queries). Dashboard ID: e70aa258-4718-4124-bd5f-caca8a77e8cd.

Data Warehouse and Data Lake Insights

BigQuery Insights

Category: Data Warehouse and Data Lake Insights

BigQuery Insights (9 saved queries). Dashboard ID: 82379123-d820-4cda-bcbb-265186be32cb.

Databricks Insights

Category: Data Warehouse and Data Lake Insights

Databricks Insights (20 saved queries). Dashboard ID: 6f59d261-971e-4dae-bfae-5e14cd24d94e.

Redshift Insights

Category: Data Warehouse and Data Lake Insights

Redshift Insights (12 saved queries). Dashboard ID: f26e85b0-fad0-4260-b32a-d2d73dd20bbb.

Snowflake Insights

Category: Data Warehouse and Data Lake Insights

Snowflake Insights (12 saved queries). Dashboard ID: 64dae968-7bc4-4ab5-82f6-82b8aeab532e.

SaaS Misconfiguration Reports

GitHub Misconfigurations

Category: SaaS Misconfiguration Reports

GitHub Account Misconfigurations (9 saved queries). Dashboard ID: 6f8d4930-5cb8-417e-9f54-e6942ad90d6f.

Salesforce Misconfigurations

Category: SaaS Misconfiguration Reports

Salesforce Account Misconfigurations (6 saved queries). Dashboard ID: 5b69bed6-e997-4da1-af22-8887d53be827.

General

AWS Activity Monitoring

Category: General

This report contains all the queries that related to Activity Monitoring including dormancy and over-provisioned ones. The output for the queries in this report are limited to the resources supported by activity monitoring i.e. S3 buckets, Secrets Manager Secrets and KMS CMK (14 saved queries). Dashboard ID: 0195a65a-4496-7cb1-a3f5-08e41fc84195.

AWS Role Mining Insights

Category: General

Insights about AWS roles' count, types, level of access and level of activity (22 saved queries). Dashboard ID: 431edab3-e29a-462f-bd8d-10e7fbc5c079.

Account Takeover Dashboard

Category: General

Account Takeover Dashboard (24 saved queries). Dashboard ID: 5414d08f-02e0-42b0-b8f0-068e0cce9230.

Accounts that can Bypass MFA

Category: General

Identities that can circumvent MFA (14 saved queries). Dashboard ID: eab8a9ad-e048-4d4d-9c25-33d8f401c368.

Active Directory and Azure AD Insights

Category: General

Active Directory and Azure AD Insights (21 saved queries). Dashboard ID: 24015679-9423-4340-9e7e-5019fd170ff6.

Azure AD Activity Report

Category: General

This report provides insights into Azure AD activity across users, guests, admins, over-provisioned resources, and sharepoint folders, libraries and sites usage. Requires Activity monitoring for Azure AD to be enabled in Veza Systems Settings in order to see data. (20 saved queries). Dashboard ID: 0194e0fa-e015-75e2-bd13-4260a3ee2ab2.

Data Insights

Category: General

Important findings relating to data resources (44 saved queries). Dashboard ID: cf53a8a6-42ad-45ed-b1de-9d1295222bf5.

Dormant Entities

Category: General

Entities with no recent activity or changes (29 saved queries). Dashboard ID: d8ac0b6c-2a6e-4fc8-b39c-8ec565ec613a.

Google Drive

Category: General

Summary of Google Drives and Folders (9 saved queries). Dashboard ID: e05be5e9-eddc-4bd6-a894-5ed2d817c90d.

Identity Protection Risks

Category: General

Identity Protection Risks (42 saved queries). Dashboard ID: 27fa8520-08cc-4334-b8cb-6afc355ffc60.

Identity Threat Detection & Response (ITDR)

Category: General

Identity Threat Detection & Response (ITDR) (35 saved queries). Dashboard ID: e6298509-f615-4f80-887b-60b7f3ffeb7d.

NHI Inventory

Category: General

An inventory of entities automatically assigned the "non-human" identity type (41 saved queries). Dashboard ID: f4835436-6e5e-4618-81cc-22076e3745b0.

NHI Keys and Secrets

Category: General

All Keys (Managed Encryption Keys), Secrets (Items stored in Vaults and Secrets Managers), and AccessCreds (API Keys, Personal Access Tokens/Keys and Certificates used to authenticate service accounts) (15 saved queries). Dashboard ID: a8fbfd89-4cb0-4198-b786-4c0d1c199f48.

NHI Risks

Category: General

Risk insights for NHI entities, Keys and Secrets and Access Credentials (35 saved queries). Dashboard ID: 0aebd76a-c51b-4305-9f76-0d62c591bc30.

Okta Activity Monitoring

Category: General

This report contains all the queries that related to Okta Activity Monitoring including dormancy and over-provisioned ones. The output for the queries in this report are limited to the resources supported by activity monitoring in Okta (13 saved queries). Dashboard ID: 0195a681-4c47-7624-8f0d-03cac177a974.

Okta Activity Report

Category: General

This report provides insights into Okta User, Admin, App Activity. Requires Activity monitoring for Okta to be enabled in Veza Systems Settings in order to see data. (10 saved queries). Dashboard ID: 3b02f3eb-9fd1-40e2-ab6c-af85f08eb55f.

Okta Insights

Category: General

Okta Insights (30 saved queries). Dashboard ID: 1119cabc-d025-4c87-baf4-b032dbc021c0.

Primitive Role Assignments in Google Cloud Platform (GCP)

Category: General

This report provides a comprehensive analysis of the assignment of primitive roles (Owner, Editor, Viewer) to Google Cloud Platform (GCP) principals (users, groups, service accounts) within the entire GCP organization. Primitive roles are highly permissive and can pose significant security risks if not managed properly. The report is a collection of queries that identify and track the assignment of these roles across all projects and resources in the GCP organization. By analyzing the distribution and usage of primitive roles, the report aims to highlight areas where role assignments can be optimized to adhere to the principle of least privilege, thereby enhancing the overall security posture of the organization. (24 saved queries). Dashboard ID: 2a8350c8-8bae-4197-8991-2f5ad716263c.

Privileged Access Dashboard

Category: General

Privileged Access Insights across Cloud, SaaS, IDP, Databases (18 saved queries). Dashboard ID: 2654341b-c473-4a7b-9a7b-739dde137313.

Privileged Access by Accounts

Category: General

Accounts that have update or delete permissions (114 saved queries). Dashboard ID: da270a1d-86cf-46f3-8e38-818e5d932146.

Privileged Access by Deactivated Accounts

Category: General

Accounts that are deactivated and have update or delete permissions (18 saved queries). Dashboard ID: 7ef9d4fc-f48c-4282-a991-4fd81b617950.

Privileged Access by External Accounts

Category: General

External accounts that have update or delete permissions (2 saved queries). Dashboard ID: cc431171-98f2-486a-bd7b-296ef12596c9.

Privileged Access by Machine Identities and Service Accounts

Category: General

Machine Identities and Service Accounts that have Update or Delete permissions (17 saved queries). Dashboard ID: 5386defb-9828-4476-8b3d-40c47a42b5f7.

Privileged Access by Roles

Category: General

Roles that have update or delete permissions (12 saved queries). Dashboard ID: 81210a46-0663-4434-8049-3db2f154b0fe.

Resource Risk Management - Unstructured Data

Category: General

This report contains all the queries for Resource Risk Management (45 saved queries). Dashboard ID: 33a85eda-5107-43a2-9865-3d5a77ecbda5.

SOC 1 Compliance

Category: General

Veza SOC 1 Compliance Dashboard can be used as a reference to build a similar dashboard with your SOC 1 in-scope systems and controls. In this model dashboard, Azure AD is the SSO application. SOC 1 in-scope systems include Workday, Salesforce, Oracle Fusion Cloud, and Azure Blob Container. In-scope tools are Azure AD and Github. (26 saved queries). Dashboard ID: b6486015-fedd-4a10-a292-d542d8d0d225.

SOX Compliance

Category: General

Veza SOX Compliance Dashboard can be used as a reference to build a similar dashboard with your SOX in-scope systems and controls. In this model dashboard, Okta is the SSO application. SOX in-scope system includes Workday, Salesforce, NetSuite, Coupa and AWS S3 Bucket. In-scope tools are Okta and Github. (31 saved queries). Dashboard ID: 2038e5df-71d3-48a4-870a-00aa55a65274.

SaaS Security Posture Management (SSPM)

Category: General

SaaS Security Posture Management (SSPM) identity risks for your SaaS apps. (16 saved queries). Dashboard ID: b62be8a3-61dc-4545-bde8-0f3535ca7d0e.

Salesforce Security Dashboard

Category: General

Salesforce Security Dashboard (16 saved queries). Dashboard ID: 388d2720-2683-4905-86ed-faf65ef8a461.

Service Account Governance

Category: General

Insights into Service Accounts across Active Directory, AWS, Azure, GCP, Okta, Salesforce, and ServiceNow (17 saved queries). Dashboard ID: 6471c09a-fe8f-46ef-8519-deae38a9efe8.

Snowflake Activity Monitoring

Category: General

This report contains all the queries that related to Activity Monitoring including dormancy and over-provisioned ones. The output for the queries in this report are limited to the resources supported by activity monitoring (14 saved queries). Dashboard ID: 0195aa5f-0a52-7595-8579-40868a264d5e.

Snowflake Data Governance Dashboard

Category: General

Unlocking key insights, vulnerabilities and metrics for effective governance of your Snowflake platform (27 saved queries). Dashboard ID: faa31406-0c5c-4067-b45d-73db46c5641e.

Snowflake Role Mining Insights

Category: General

Insights about Snowflake roles' count, types, level of access and level of activity (10 saved queries). Dashboard ID: de82e65e-82d2-4740-a8f7-ffd1b65269fd.

Structured Data Risk

Category: General

Structured Data Risk (70 saved queries). Dashboard ID: 019910d5-97d4-74f1-9f41-bb961967d58c.

Top Insights

Category: General

High-value findings that are vital to securing your environments (17 saved queries). Dashboard ID: 2e6d29de-9169-4850-a7bb-f62b79bde637.


Last updated

Was this helpful?