Administration
Configuration and backend controls for the OT IDS service — user access, data sources, thresholds, schedules and notifications (demo, non-persistent).
User access & RBAC
roles and access scopes| Role | Access scope | Users |
|---|---|---|
| Executive | Overview, trends, risk summary | 8 |
| OT Security Lead | Full dashboard access | 5 |
| Site Manager | Own site only | 82 |
| SOC Analyst | Alerts, incidents, vulnerabilities | 14 |
| Service Delivery Manager | Onboarding, hypercare, SLA and reporting views | 9 |
| Admin | Configuration and user management | 3 |
Data sources
backend connections feeding the dashboardClaroty IDS
Assets, alerts, vulnerabilities, sensor health
Connected
Nozomi IDS
Assets, alerts, vulnerabilities, sensor health
Connected
CMDB / Asset inventory
Site details, owners, criticality
Connected
Vulnerability database
CVSS, CVE, EPSS
Connected
Ticketing tool
Incidents, SLA, MTTR
Degraded
Reporting tracker
Schedule & delivery
Connected
Email / workflow
Notifications & acknowledgements
Connected
Report schedule
automated report generation and deliveryMonthly site security report
1st business day
Vulnerability report
Weekly, Monday
Executive summary
Monthly, 3rd
Risk posture
Monthly, 5th
Site master data
scope of the current filter selectionSites configured
In service scope
154
Regions
Geographic rollout areas
5
Business areas
Business areas covered
4
IDS platforms
Detection technologies in use
2
Site metadata is mastered in the CMDB and synced daily.
Thresholds & KPI formulas
service-wide rules applied to all sitesCritical alert threshold
Alerts at or above this severity page the SOC
Severity ≥ 8
Risk score bands
Composite site risk score, 0–950
Critical ≥ 620 · High ≥ 500 · Medium ≥ 380
Vulnerability SLA
Remediation targets by priority
P1 14 d · P2 30 d · P3 90 d
Priority formula
Inputs to vulnerability prioritization
CVSS + EPSS + asset criticality + exposure + business impact
Sensor offline alarm
Silence window before a sensor is flagged
> 30 min silent
Data refresh
Ingestion cadence from all sources
Every 15 minutes
Notification rules
email and workflow triggersNew CVSS 10 vulnerability
Immediate notification to site and SOC
Sensor offline > 30 min
Alarm to service delivery and site contact
SLA breach warning
Sent 3 days before a remediation deadline
Weekly digest
Summary of alerts and changes, Monday morning
Hypercare exit reminder
Prompt when the hypercare window closes
All times shown in local time of selected region · Data refresh every 15 minutes