# Enterprise Reporting

_Enterprise Reporting_ (known as _Data Insights_ until release 191) is your one-stop access to understand your organization's open-source consumption patterns including AI/ML components, risk and remediation patterns, and factors affecting the overall security posture. It summarizes how Sonatype Lifecycle impacts the security profile of the development pipelines within your organization.

**Note**  
We have implemented the dashboards using the Looker™ platform for versatility. The visualizations will continue to evolve in functionality or scope, based on future improvements and user feedback.

## Data Handling Processes for Enterprise Reporting

To address the concerns due to data processing with our third-party reporting tool, Looker™, we have implemented a 4-way protection methodology:

1. **Data Storage**  
   No data is stored in any third-party tool. We use the third-party tooling's streaming capability to receive the query results directly from the Sonatype environment in a dedicated instance. The data is transmitted without being stored.

2. **Data Anonymization**  
   The information for these visualizations and reports is restricted for an organization from the anonymized telemetry during application analysis performed via Sonatype Data Services.

3. **Data Authentication and Authorization**  
   To ensure that the data in these visualizations is accessible to authorized users only, the system programmatically creates obfuscated, unique one-way hash identifiers for the user and the organization's instance.

4. **Data Encryption**  
   We implement encryption for data in flight from the Lifecycle environment to the third-party reporting tool.

For added security, the vulnerability data for a specific application or component is not included in any of the dashboards.

### Advanced Reporting

To provide deeper reporting clarity, additional data is made available to be used for reporting following all encryption and data handling standards. The data element included in Advanced Reporting is:

- Application Name

When Advanced Reporting is disabled, application names are obfuscated in Enterprise Reporting.

To show application names in Enterprise Reporting, set ADVANCED_REPORTING_INSIGHTS_ENABLED to true using the Configuration REST API. See [Enable Advanced Reporting Insights](https://help.sonatype.com/en/configuration-rest-api.html#enable-advanced-reporting-insights).

### Flow for Data Request

1. A user invokes a dashboard from the _Data Insights_ feature in Sonatype Lifecycle.
2. The browser requests a one-time, unique URL for the insight via an internal IQ Server API.
3. The IQ Server invokes the Sonatype Data System API to check for a valid license and account using the standard one-way hash algorithms within IQ Server.
4. The Sonatype Data System invokes the Looker™ API to generate the one-time use URL.
5. Looker™ returns the fully signed and fully formed URL.
6. The Browser renders the URL in the frame in Sonatype Lifecycle.
7. Looker™ streams data encrypted from the back-end data systems (Databricks™) to render the report.

## Prerequisites

- Your browser has no restrictions on accessing “*. [looker.com](https://looker.com/)” URLs
- For the Safari browser, “_Prevent cross-site tracking_“ in the _Settings_ menu → Privacy is **disabled.**

## Accessing

Click on _Enterprise Reporting_ from the left navigation bar.

## Get to know your Enterprise Reporting Landing Page

The Enterprise Reporting landing page displays the following information:

- **Rapid Response Reports**  
   Rapid Response Reports provide fast, targeted insights into critical security issues that require immediate attention. These reports are designed to help organizations quickly assess exposure to high-impact vulnerabilities and take timely remediation actions across affected applications and components.
- **Enterprise Dashboards**  
   Enterprise dashboards offer a set of logically related visualizations or charts to provide a complete picture of key aspects that impact the organization security and compliance risks. The individual visualizations in an enterprise dashboard are curated and compiled to empower users to make data-driven informed decisions and maximize on the capabilities value delivered by using Sonatype Lifecycle to improve the program efficacy.
- **Data Insights**  
   Data Insights are standalone visualizations that enable focused analytics and data exploration. Based on the data generated as a result of using Sonatype Lifecycle, these visualizations answer specific task-oriented questions like reporting applications containing End-of-Life (EOL) components or AI/ML components, applications on-boarding rate, scan rates, component upgrades (Upgrade Posture) etc.
- **Partner Solutions**  
   Partner Solutions are partner-provided dashboards and integrations that extend Enterprise Reporting with specialized capabilities from trusted technology partners, such as End-of-Life (EOL) tracking or partner-sourced upgrade recommendations.

### Exporting dashboards and table data

Enterprise Reporting dashboards include two action menus: **Dashboard actions** and **Tile actions**.

- _Dashboard actions_ are available from the three-dot menu in the top-right corner of the dashboard. Use dashboard actions to refresh dashboard data, show or hide filters, download the dashboard, schedule delivery, or reset filters.
- _Tile actions_ are available from the three-dot menu on an individual visualization or table. Use tile actions to download data for a specific tile or table.

To export the full dataset for a table, open the tile actions menu, select Download data, expand Advanced data options, and set Number of rows and columns to include to All results.

On supported tiles, you can also use the Alerts icon to create alerts based on configured conditions, recipients, frequency, and delivery method.

### Rapid Response Reports: React2Shell Impact Report

Explore applications and components impacted by critical React Server Component vulnerabilities using this rapid response report.  
Learn more about [React2Shell Impact Report](https://help.sonatype.com/en/react2shell-impact-report.html#react2shell-impact-report)

### Rapid Response Reports: Mythos Readiness

Cross-reference your open source inventory with Mythos vulnerability data in a single exportable view.  
Learn more about [Mythos Readiness](https://help.sonatype.com/en/mythos-readiness.html#mythos-readiness)

### Enterprise Dashboard: Success Metrics

Explore your policy violation and remediation patterns using this foundational dashboard.  
Learn more about [Success Metrics](https://help.sonatype.com/en/success-metrics.html#success-metrics-337396)

### Enterprise Dashboard: Success Metrics: Remediation Ops

Investigate policy violations and remediation activity across your applications and components with this foundational dashboard.  
Learn more about [Success Metrics: Remediation Ops](https://help.sonatype.com/en/success-metrics--remediation-ops.html#success-metrics--remediation-ops)

### Enterprise Dashboard: Success Metrics: Program Health

Explore your organization’s security posture, remediation efficiency, and policy violation trends with this foundational dashboard.  
Learn more about [Success Metrics: Program Health](https://help.sonatype.com/en/success-metrics--program-health.html#success-metrics--program-health)

### Enterprise Dashboard: Security Risk Trends

Explore your security risk trends and mitigate risk with this foundational dashboard.  
Learn more about [Security Risk Trends](https://help.sonatype.com/en/security-risk-trends.html)

### Enterprise Dashboard: Security Risk Breakdown

Dive deeper into security risk and violation data with this foundational dashboard.  
Learn more about [Security Risk Breakdown](https://help.sonatype.com/en/security-risk-breakdown.html)

### Enterprise Dashboard: Waivers Explorer

Dive deeper into security risk and violation data with this foundational dashboard.  
Learn more about [Waivers Explorer](https://help.sonatype.com/en/waivers-explorer.html)

### Enterprise Dashboard: Legal Risk Trends

Explore your legal risk trends and mitigate risk with this foundational dashboard.  
Learn more about [Legal Risk Trends](https://help.sonatype.com/en/legal-risk-trends.html)

### Enterprise Dashboard: Golden Fixes

Dive deeper into golden fixes and violation data with this foundational dashboard.  
Learn more about [Golden Fixes](https://help.sonatype.com/en/golden-fixes-dashboard.html)

### Enterprise Dashboard: Best Practices

Explore your organization’s adoption of best practices and integration coverage across applications over time.  
Learn more about [Best Practices](https://help.sonatype.com/en/best-practices-dashboard.html)

### Data Insight: AI Models

Explore and inspect the metadata for the open-source AI models used in your applications.  
Learn more about [AI Models Usage](https://help.sonatype.com/en/ai-models-usage.html)

### Data Insight: AI Machine Learning

Observe the consumption of open-source AI/ML components in your applications.  
[Learn more about ML/AI Apps: Using Machine Learning.](https://help.sonatype.com/en/machine-learning-ai.html)

### Data Insight: Component EOL

See which components have the status of End of Life (EOL).  
[Learn more about Component EOL: Retiring Old Code](https://help.sonatype.com/en/component-end-of-life.html)

### Data Insight: Supply Chain Monitoring

Review the health of your OSS supply chain and observe key influencing factors.  
[Learn more about Supply Chain Monitoring](https://help.sonatype.com/en/supply-chain-monitoring.html)

### Data Insight: Stack Divergence

Compare your applications' component usage against industry norms to evaluate areas where you've fallen behind the adoption curve  
[Learn more about Stack Divergence](https://help.sonatype.com/en/stack-divergence.html)

### Partner Solutions: HeroDevs EOL Components

Explore your end-of-life component posture and view partner-provided upgrade recommendations with this partner dashboard.  
Learn more about [HeroDevs End of Life Components](https://help.sonatype.com/en/herodevs-end-of-life-components.html#herodevs-end-of-life-components)
