1Security
Screens

Reports

Turn Copilot readiness, compliance status and trends into a branded document - PDF, PowerPoint, HTML, CSV or JSON - from the dashboard or over the API.

Reports

The readiness and compliance screens are built for the people who sign in. The Reports screen answers the question that comes after: "How do I hand this to someone who has no 1Security login - under my own brand?"

You find it at Dashboards → Reports, below Copilot readiness. The Print report buttons on the Compliance and Copilot readiness screens open it too, filtered to that report.

What You Can Achieve

Hand over a document, not a login

Download the same data the screens show as a PDF, a PowerPoint deck or a single HTML file. The reader needs no 1Security account.

Put your own brand on it

Company name, logo, brand colour, prepared by and prepared for, footer and confidentiality label. Switch off the 1Security mention for a fully white-label report.

Read it against the right regulations

Choose the regulations the report is read against, or follow what each tenant declared on the Compliance screen.

Automate the delivery

Every template has an ID for the API. One request returns the finished file, so a script can produce the monthly report for each client.

Templates

There are three report types today. Each renders the same data as its screen.

Report typeSource
Copilot readiness assessmentCopilot readiness
Compliance statusCompliance
Trends reviewTrends

Eight ready-made templates are always available:

  • Copilot readiness briefing
  • Copilot readiness audit record
  • Copilot readiness scorecard
  • Compliance status briefing
  • Compliance audit record
  • Monthly trends review (last 30 days)
  • Quarterly trends record (last 90 days)
  • Weekly trends scorecard (last 7 days)

A ready-made template cannot be edited. Download it as it is, open it with Customize to adjust it before downloading, or choose Make a copy to keep your own version. A copy is either shared with the whole organization or private to you; the list shows ready-made, shared and private templates side by side, your copies first.

Each template uses one of three layouts:

LayoutLooks likeMade for
BriefingBold cover in the brand colour, large verdictsA decision maker
Audit recordFormal serif typography, dense tablesAn auditor, or the file
ScorecardNo cover, compact, fewest pagesRecurring reviews

Building a Template

The builder has the settings on the left and a live preview on the right. The preview updates as you type, so you see the document before you save or download anything.

The settings come in five groups.

Template

The template name and a description. Both are for you and your colleagues; they help you find the template in the list.

Design

  • Layout - Briefing, Audit record or Scorecard.
  • Report language - English, Polish, German, French, Spanish, Russian or Ukrainian.
  • Paper size - A4 or Letter.

Branding

  • Company name and Logo. The logo can be PNG, JPEG, WebP or SVG. Large images are scaled down.
  • Brand colour.
  • Prepared by and Prepared for. Prepared for defaults to the tenant name.
  • Contact line, Footer text and Confidentiality label.
  • Mention 1Security - switch it off for a fully white-label report.
  • Link findings to 1Security - switch it off when the readers have no 1Security account.

Content

Set the Report title, then tick the sections to include and use the arrows to put them in order. Your introduction is an optional text of your own that appears before the results.

Copilot readiness assessmentCompliance statusTrends review
Cover pageCover pageCover page
Your introductionYour introductionYour introduction
Verdict and readinessRegulations chosen for this report (always included)Movement in the period
What to fix firstReadiness by frameworkWhat changed most
All checksRequirementsAll trends
Sites to review (top 10)Articles by frameworkHow this was measured
Users with the widest reach (top 10)Changes since the last snapshot
Regulations chosen for this report (always included)How this was measured
How this was measured

A Trends review also has a Period: the last 7, 30 or 90 days. The review covers the trends on the shared Trends board; private trends are left out. For each trend it takes one value per day and compares the first value in the period with the latest one:

  • Movement in the period counts the trends that increased, decreased or stayed unchanged, in total and by category. Categories use the names set on your board.
  • What changed most lists the five largest increases and the five largest decreases, each with its line over the period.
  • All trends lists every trend with its severity, value at the start, value now and change.

A trend with fewer than two values in the period is listed as Not enough history, without a change.

Regulations

A Copilot readiness assessment and a Compliance status report say which regulations they are read against. Their Regulations chosen for this report section is always included: you can move it, but not leave it out. A Trends review has no such section, because a trend is a count you chose to watch and is not tied to an article.

  • Each tenant's own regulations - the report follows what each tenant declared on the Compliance screen. A tenant that declared none gets the common baseline.
  • Regulations chosen here - you tick the regulations, and every tenant the template renders is read against the same ones.

In a Copilot readiness report the section lists, for each regulation, the articles the checks speak to and their status. In a Compliance report the chosen regulations also decide which frameworks, requirements and articles the other sections show.

Statuses and notes

1Security measures what is connected to it. When the whole picture is different - AI agents that run on people's own machines, devices managed in another tool - a measured status can be right and still not tell the reader everything. In a Compliance report, Statuses and notes lists every requirement with Edit next to it:

  • As measured, note only keeps the measured status and adds your note.
  • Met, At risk (partly met), Not met or Not applicable sets the overall status. A note is required: it says what the measurement does not see.

The report then shows the status you set, marks it Own assessment, and prints the measured status and your note next to it. Articles that rest on an assessed requirement carry an asterisk and a footnote. Nothing measured is hidden or overwritten.

The record is saved for the tenant, not for the template. The same status and note show on the Compliance screen, in every other report, in snapshots and in the API.

For a Copilot readiness report, change a check's targets or snooze it with a note on the Copilot readiness screen. A snoozed check is listed as Snoozed with its note.

A saved template shows its Template ID for the API in the builder.

Formats

FormatWhat you get
PDFThe laid-out document. Every page has a footer with your footer text, the confidentiality label and page numbers.
PowerPointA 16:9 deck with the same sections, wording and branding as the PDF. Text, tables and bars are ordinary slide objects, so you can edit a slide or paste it into your own deck. Long tables continue on the next slide. A PNG or JPEG logo appears on the cover; with an SVG or WebP logo the deck shows your company name instead.
HTMLOne self-contained file with no external resources. It opens in any browser and can be attached to an email.
CSVOne row per check for Copilot readiness, one row per framework and article for compliance, or one row per trend for a trends review.
JSONThe full report document, for your own tooling.

Print prints the preview straight from the browser.

Reports Over the API

The same templates are available on the REST API with the evidence:read scope. One request returns the file itself:

curl -H "Authorization: Bearer $ONESEC_API_KEY" \
  -o readiness.pdf \
  "https://api.1security.ai/api/v1/reports/templates/builtin:copilot-readiness-briefing/render"

Add ?format=pptx, html, csv or json for the other formats. Use the ID of a saved template in place of the built-in one to get your own branding.

A tenant-bound key renders its own tenant. An organization-wide key renders the tenant you name in the X-Tenant-Id header, so a loop over your tenant list makes one call per tenant and produces one report per client.

The API reference lists the endpoints, the parameters and the per-tenant loop for partners. On the MCP server, list_report_templates and get_report return templates and report data as JSON or CSV; PDF, PowerPoint and HTML are available over REST only.

Good to Know

  • Shared and private copies. A copy shared with the organization is visible to every admin of the organization's tenants; a private copy only to you. You can change this on the template at any time.
  • Connected tenants are reported together. In the All tenants view of tenants connected together, one document covers all of them: a tenant overview, then a chapter per tenant. Otherwise a report covers the tenant you have open.
  • Demo tenant. Templates cannot be saved on the demo tenant. You can still customize one and download the result.
  • Files over the API are kept for 24 hours. Download a rendered file within that time, or render it again.
  • Language. The report itself is available in English, Polish, German, French, Spanish, Russian and Ukrainian. A ready-made template starts in the language of your dashboard, with regulations and articles cited the way that language cites them. A saved template keeps the language it was saved with. A trend you named yourself is printed as you named it.
  • Access. The screen is available to administrators only. For an administrator on custom permissions it is the Reports row of the permission matrix: View all opens templates and past runs, Write all also creates, edits and generates. It is granted separately from Compliance.

On this page