Security and decisions

Security reports and URL assessments without admin dependency

Security teams need reliable context, but they should not require another Zscaler admin account for every report. CentaurNexus provides supported reads by role and makes their data basis visible.

August 4, 2026 · CentaurNexus · Reading time approx. 6 minutes

Security analysis combining reports and multiple sources for a URL assessment
CentaurNexus: Security reports and URL assessments without admin dependency

Reports with a visible data basis

A report is only as meaningful as its sources. For supported reads, CentaurNexus shows source, status, data age and coverage. Security, management and internal reviewers therefore share a traceable data basis.

Interpret approvals in the dashboard

Security teams can review pending and decided approvals in their assigned tenant context. Tenant policy assigns the appropriate decision path and keeps status, reason and responsible role together.

Assess URLs across multiple signals

Nexus MetaScore combines the signals available for a URL assessment. Each connected source is shown with its status, data age and contribution to the result. This creates a transparent decision basis instead of an isolated score.

Nexus MetaScore in context: Available signals, source status, data age and coverage form a traceable basis for decisions.

Security teams can compare the assessment with approvals, recent access patterns and the available tenant context before selecting the next action. The same source view remains available when the case moves to another role.

From finding to controlled action

If an assessment leads to an approval or change, selection, tenant policy, audit, activation and read-back remain separate steps. Security retains the decision basis and a complete view of the workflow.

A report must explain its reach

“No findings” can mean two very different things. Either no relevant event was observed during the selected period, or a required source was not fully available. Without data age and coverage, those cases cannot be distinguished reliably. Period, tenant, source and source state therefore belong directly in the report.

OneAPI can be the authoritative source for current configuration. Time-based analysis can additionally require appropriate NSS or LSS feeds. A report joins these layers only where the data actually belongs to the tenant and question.

Role-based access instead of another admin dependency

Security analysts should not need broad vendor-admin access every time they run an authorised report. CentaurNexus provides the intended view through its own role model. Tenant isolation and row-level controls limit the data an operator can access.

Zscaler administration remains with the responsible administrators while security receives the information required for assessment and documentation. A role does not gain broader rights merely because a report combines several sources.

Nexus MetaScore as a traceable aggregation

Nexus MetaScore combines available URL signals into a shared assessment. The value remains useful only when its components are visible. Those can include Zscaler category and block context, available risk signals, observed usage and, depending on the concrete integration, external threat intelligence.

A missing source is not treated as a benign signal. Assessment coverage shows which components were present. Analysts can distinguish a broad, current finding from a preliminary view based on limited evidence.

Example: assess a requested website

A user requests access to a blocked website. Security sees the exact URL, business reason, available category and policy context, and observations from the available history. Nexus MetaScore structures the available signals without making the decision on behalf of the analyst.

The analyst can approve, reject or leave the request open for further review. If the decision creates a target-system change, it remains one controlled action. Activation and read-back stay part of the same workflow.

Approvals and reports belong together but remain separate tasks

A report can indicate a need for action. It does not automatically implement that action. CentaurNexus exposes the transition from finding to decision and from decision to confirmed effect as separate states.

This is valuable during later review. Security can see which evidence existed at decision time. Administrators can see the exact change that was activated. Management receives an aggregated view without losing the technical detail path.

Export reports with a traceable data basis

An exportable report connects period, tenant, sources, data age, coverage, filters and creation time. Security, management and internal reviewers therefore work from the same documented data basis.

The export supports internal reviews, customer communication and technical documentation. Reusable report profiles create a consistent workflow across teams and tenants.

From individual findings to recurring review

In addition to ad-hoc URL assessment, security needs a recurring view of categories, block decisions, approvals and noteworthy trends. A defined reporting period exposes change without silently mixing data from different coverage states.

The review should identify open actions, responsible roles and the next review date. A report then becomes part of a traceable operating rhythm between security, administration and management rather than a static file.

Separate decision quality from later outcome

A URL that later appears benign does not prove that every earlier decision was correct. Equally, a cautious rejection is not wrong merely because no later activity was observed. The relevant question is whether the decision was traceable from the sources and tenant policy available at the time.

CentaurNexus therefore keeps the decision basis separate from later history. A retrospective can show which new information arrived without rewriting the historical evidence state.

One data basis, different role views

The analyst needs individual signals and the decision basis. A security owner reviews open risks, trends and actions. Management sees aggregated development, coverage and responsibility. These views use the same tenant-bound workflow without giving every role the same detail rights.

MSP reporting also remains strictly customer-bound. Comparable measures can be aggregated only while tenant separation and coverage remain intact. A cross-customer view does not expand access to individual raw data.

Questions a good report should answer

Which source supports the finding? Which tenant and period does it cover? How current and complete is the data? What decision or action follows, and who owns it? When the report answers these questions directly, the recipient can assess it without another broad vendor-admin login.

Accept a reliable security workflow

  1. Define report purpose, target role and tenant context.
  2. Identify required OneAPI, NSS, LSS and optional external sources.
  3. Test data age, coverage and failure states with real cases.
  4. Review URL assessment with complete and deliberately incomplete source sets.
  5. Accept approval, activation and read-back as separate states.
  6. Review exports and recipients against the agreed evidence purpose.

The result is a security workspace that connects assessments, approvals, sources and follow-up actions in one traceable decision context.

Frequently asked questions

Does Security need broad Zscaler admin rights?

Not for role-based CentaurNexus reports. The visible scope follows role, tenant and coverage.

Does every URL assessment use external threat intelligence?

No. External sources depend on the concrete integration. The result must show the sources actually used.

Which details are included in an exported report?

Period, tenant, sources, data age, coverage, filters and creation time remain documented together.

Sources and further information

See the workflow in context

Choose the relevant role in the demo launcher. The demo uses prepared sample data.

Open demo launcher