Senior management
76/100
Point-in-time health is Review recommended. 3 prioritised SQL finding(s) and 2 compliance control(s) require accountable review.
Confirm risk owners, priority and delivery dates.
SQL Server Assessment Report
Summary statusRed — immediate review
Assign accountable owners and review the red and highest-priority findings before approving related change.
Why this status Security risk · Resilience or recovery risk · Performance enhancement · Configuration or best-practice review · Compliance attention · Evidence gap
Shared evidence, different decisions: These summaries are derived from the detail below. They do not replace control-owner review, technical validation, or continuous monitoring.
76/100
Point-in-time health is Review recommended. 3 prioritised SQL finding(s) and 2 compliance control(s) require accountable review.
Confirm risk owners, priority and delivery dates.
2 attention
5 control(s) were represented: 1 not assessed and 0 approved exception(s). Unavailable or unassessed evidence is never treated as a pass.
Validate scope, evidence period, exceptions and reviewer sign-off.
4 findings
1 application finding(s), 2 native assessment finding(s), and 1 optional-toolkit finding(s) need triage across 6 database(s).
Allocate owners, validate dependencies and sequence safe changes.
3 prioritised
Use the SQL, application, maintenance and evidence sections for observed values and safe next reviews. Reproduce evidence before change and retain rollback and validation results.
Investigate the highest-priority evidence first; do not apply recommendations autonomously.
External context: Gallagher's UK Business Risk Index ranked cyber-crime third among the surveyed business risks. Guardian One only contributes bounded SQL/data-platform evidence; the customer owns likelihood, impact and enterprise-risk decisions.
2 review signal(s)
Counted from SQL security and relevant compliance evidence. This is not vulnerability scanning, attack detection, EDR, network assurance or incident response.
2 review signal(s)
Backup, database and capacity findings may help prioritise avoidable SQL interruption or recovery exposure. Guardian One does not forecast cash flow, prices or supply-chain performance.
Summary statusRed — immediate review
Assign accountable owners and review the red and highest-priority findings before approving related change.
Why this status Security risk · Resilience or recovery risk · Performance enhancement · Configuration or best-practice review · Compliance attention · Evidence gap
Best-practice summary: Use the snapshot to prioritise validation, not as proof of continuous health. Compare repeat assessments, business context, incidents, and owned monitoring before approving change.
76/100 — Review recommended
Point-in-time assessment score, not a live service indicator.Click a bar to filter findings; click it again to clear.
Click a database to filter findings; click it again to clear.
Summary statusRed — immediate review
Assign accountable owners and review the red and highest-priority findings before approving related change.
Why this status Security risk · Resilience or recovery risk · Performance enhancement · Configuration or best-practice review · Compliance attention · Evidence gap
Best-practice summary: Size CPU, memory, paging, and storage from representative demand with operating-system and virtual-host headroom. Confirm sustained patterns before changing platform resources.
Guardian One native coverage: Core SQL Server and Windows evidence, insights, risks and recommendations do not require third-party diagnostic tools. Approved third-party tool output supplements this baseline when installed and available.
Machine: GO-DEMO-SQL02
CPU: Latest SQL scheduler-health CPU shares: SQL Server 34%, Other processes 11%, Idle 55%. Windows host CPU was 45.0% at capture across 48 logical processor(s).
Storage: Storage capacity was reported for 2 paths; L: had the lowest headroom at 46.1 GB free of 256.0 GB (18% free).
Memory: SQL Server had allocated 90.0 GB of its 96.0 GB target (94%). Windows reported 28.0 GB available of 128.0 GB physical RAM and 36.0 GB available of its 144.0 GB commit limit.
Evidence: Windows host evidence was complete. No customer environment classification or machine-build template was configured.
Interpretation: These are point-in-time values; compare repeat assessments before changing capacity or configuration.
Host I/O sample: 9.4 ms read, 3.8 ms write; 460.5 reads/s and 188.2 writes/s.
45.0% Windows CPU at capture; 2 socket(s), 24 core(s), 48 logical processor(s).
Recent scheduler-health samples provide SQL shares; Windows utilisation is a persisted point-in-time host sample.28.0 GB available of 128.0 GB physical RAM
36.0 GB available of 144.0 GB commit limit
90.0 GB allocated of 96.0 GB target
Remote SQL Server memory-manager counters. Trend uses periodic Guardian One assessments.Environment: Not classified · Template: Not configured · Status: Not Assessed
Risk: Not assessed.
Recommendation: Review customer configuration.
| Server detail | Observed value |
|---|---|
| Windows operating system | Microsoft Windows Server 2022 Standard |
| Windows version | 10.0.20348 |
| Windows domain | DEMO.EXAMPLE |
| Windows host started | 2026-08-06T07:30:00+01:00 |
| Windows evidence captured | 2026-08-13T17:00:00+01:00 |
| Machine name | GO-DEMO-SQL02 |
| Domain | DEMO.EXAMPLE |
| Host operating system | Microsoft Windows Server 2022 Standard |
| Attention | Insight | Risk | Recommendation | Confidence and limits |
|---|---|---|---|---|
| MEDIUM | Transaction-log volume headroom requires review The log volume had 18% free capacity at the assessment point. | Requires review. | Compare retained growth with the operational forecast, then pre-size files or storage through approved change control. | Not stated Point-in-time evidence. |
Summary statusRed — immediate review
Assign accountable owners and review the red and highest-priority findings before approving related change.
Why this status Security risk · Resilience or recovery risk · Performance enhancement · Configuration or best-practice review · Compliance attention · Evidence gap
Best-practice summary: Run a supported SQL Server build with tested cumulative updates; use dedicated least-privilege service identities; validate maximum memory, MAXDOP, cost threshold and tempdb against the workload; and review SQL Server and Agent errors after every scheduled assessment.
Native baseline: This summary is produced from Guardian One collectors. Approved third-party diagnostics add supplementary evidence when available but are not required for the core assessment.
| Property | Observed value |
|---|---|
| Server and instance | GO-DEMO-SQL02\ERP |
| Machine name | GO-DEMO-SQL02 |
| Edition | Enterprise Edition |
| Product version | 15.0.4430.1 |
| Product level | CU |
| Database Engine service account | DEMO\svc_sql_erp |
| Database Engine started | 2026-08-06 07:45 |
| Default trace file | D:\SQLTrace\log.trc (Running) |
Collection status: Not Assessed. Window: not recorded days. Retained rows matching the review window: 0. Safety cap: not recorded rows. Source status was not persisted.
| Issue category | Count | Pattern | Earliest observed | Latest observed | Source | Risk | Recommendation |
|---|---|---|---|---|---|---|---|
| No classified errors or failures were found in the bounded evidence that was successfully read. This does not guarantee that no issue exists; review collection status, scope, retention and external logs. | |||||||
Collection status: Not Assessed. Rows reviewed: 0 of 0. Trace retention and scope are limited.
| Insight | Event | Count | Latest observed | Database scope | Risk | Recommendation |
|---|---|---|---|---|---|---|
| No classified trace events were returned. This is not proof that no event occurred; review collection status and trace retention. | ||||||
Best-practice summary: Pre-size data, log, and TempDB for measured demand; prefer workload-tested fixed-MB growth, avoid routine shrink, and govern free capacity through customer monitoring.
Point-in-time SQL Server file placement, capacity, and automatic-growth configuration. Growth settings reduce operational surprises but do not replace capacity monitoring or workload-based sizing.
Files assessed across system and user databases.
Files using predictable fixed-MB increments.
Review and replace with workload-tested fixed increments.
Confirm these files are intentionally fixed and adequately pre-sized.
These are scheduled, point-in-time Guardian One samples retained for up to 730 days. Exhaustion dates are estimates based on measured SQL file allocation growth and the latest volume free space; other files, purge activity, compression, movement and workload changes can alter the outcome.
| Drive or mount point | Evidence window | First SQL allocation | Latest SQL allocation | Allocation change | Latest free | Free-space change | Average growth | Estimated exhaustion | Confidence and limitation |
|---|---|---|---|---|---|---|---|---|---|
| No retained drive-capacity series is available yet. A new assessment records a sample; at least three measured samples over the configured minimum window are required for projection. | |||||||||
| Database | Evidence window | First allocated | Latest allocated | Latest used | Change | Average growth | 90-day estimate | Confidence and limitation |
|---|---|---|---|---|---|---|---|---|
| No retained database-capacity series is available yet. | ||||||||
Table-level history is disabled by default. Enable the governed CapacityHistoryTableCollectionEnabled setting when the customer approves bounded object-level size collection.
| Database.schema.table | Evidence window | First reserved | Latest reserved | Latest used | Change | Average growth | 90-day estimate | Confidence and limitation |
|---|---|---|---|---|---|---|---|---|
| No retained table-capacity series is available for this assessment window. | ||||||||
| Database | Logical file | Type | Current size | Maximum | Growth | Recommendation |
|---|---|---|---|---|---|---|
| ERP_Core | ERP_Core_log | LOG | 64.0 GB | 128.0 GB | 1.0 GB | Fixed growth and a file maximum are configured. Validate both against recent consumption, free volume capacity, maintenance windows, and recovery objectives. |
| ERP_Core | ERP_Core | ROWS | 240.0 GB | 600.0 GB | 1.0 GB | Fixed growth and a file maximum are configured. Validate both against recent consumption, free volume capacity, maintenance windows, and recovery objectives. |
| tempdb | tempdev | ROWS | 8.0 GB | 32.0 GB | 512 MB | Fixed growth and a file maximum are configured. Validate both against recent consumption, free volume capacity, maintenance windows, and recovery objectives. |
Full-backup size is a corroborating signal, not a direct measure of allocated file growth. Compression, changed-page density, backup scope, and data churn can affect the series. Longer-term forecasts should use retained database and file samples.
| Database | Evidence window | Full backups | First size | Latest size | Change | Average | Current allocated | Volume free | Interpretation and next step |
|---|---|---|---|---|---|---|---|---|---|
| At least two dated, non-copy-only full-backup size samples are required for a growth pattern. | |||||||||
| Role | Configured or observed path | Volume | Capacity | Files |
|---|---|---|---|---|
| Data | D:\SQLData | D:\ | 401,408 MB free of 1,048,576 MB | 9 |
| Transaction logs | L:\SQLLog | L:\ | 47,186 MB free of 262,144 MB | 6 |
| tempdb data | T:\SQLTemp | T:\ | 98,304 MB free of 131,072 MB | 8 |
| SQL binaries | C:\Program Files\Microsoft SQL Server\MSSQL15.ERP\MSSQL\Binn\sqlservr.exe | Not applicable — executable location only | Not applicable | |
| Default data | D:\SQLData | Not assessed — no matched volume evidence | Not assessed — directory count unavailable | |
| Default transaction logs | L:\SQLLog | Not assessed — no matched volume evidence | Not assessed — directory count unavailable | |
| Default backups | B:\SQLBackup | Not assessed — no matched volume evidence | 24 |
Best-practice summary: Validate each finding against workload, version, edition, dependencies, ownership, test evidence, approval, and rollback. Similar symptoms can have different causes.
Consolidated point-in-time findings from Guardian One assessment rules and supporting diagnostic evidence. Review recommendations with accountable service owners and qualified SQL specialists before making production changes.
| Attention | Group | Finding | Database | Details | Risk | Recommendation | Guidance summary |
|---|---|---|---|---|---|---|---|
| Immediate review Priority 25 |
Backup | ERP reporting database full backup outside target Guardian One native rule |
Instance level | The latest retained full-backup evidence is older than the demonstration recovery target. | The condition may affect the assessed SQL Server if left unresolved. | Validate the backup schedule and complete a governed restore test before closing the finding. | Guardian One assessment rule. Validate the evidence and proposed change with the responsible technical owner. |
| High attention Priority 55 |
Index design | Review an index for a frequently joined ERP relationship. Guardian One application database assessment |
ERP_Core | Referential operations may scan more data than necessary. | Validate the workload and proposed key order in a representative environment before change. | No additional guidance summary is available. | |
| High attention Priority 75 |
Capacity | Transaction-log volume headroom requires review Guardian One native rule |
Instance level | The log volume had 18% free capacity at the assessment point. | The condition may affect the assessed SQL Server if left unresolved. | Compare retained growth with the operational forecast, then pre-size files or storage through approved change control. | Guardian One assessment rule. Validate the evidence and proposed change with the responsible technical owner. |
Best-practice summary: Define maintenance from recovery objectives, workload, data change, and available windows. Prove backup recoverability and integrity outcomes; do not schedule commands merely because they are available.
Review-only maintenance starting points based on the collected evidence. Guardian One does not execute these commands, create schedules, or replace customer monitoring. Confirm recovery objectives, maintenance windows, edition support, storage, permissions, and change approval first.
| What | Why | Suggested timing | Example command | Risks and validation | Guidance summary |
|---|
Best-practice summary: Preserve application contracts. Review schema, constraints, indexes, options, and query patterns with developers, then test correctness, concurrency, performance, and rollback before deployment.
Schema, integrity, configuration, indexing, and transaction-log checks for user databases. Findings are ordered by priority and should be validated against application behaviour before changes are made.
This inventory provides assessment context even when no application-design exception was identified or persisted.
| Database | State | Recovery model | Compatibility | Size | Last full backup |
|---|---|---|---|---|---|
| ERP_Core | ONLINE | FULL | 150 | 286,720 MB | 2026-08-13 02:00 |
| ERP_Reporting | ONLINE | FULL | 150 | 92,160 MB | 2026-08-10 02:00 |
User databases represented in the findings.
Items requiring review across user databases.
Showing all 1 application findings.
| Attention | Group | Finding | Database | Details | Risk | Recommendation |
|---|---|---|---|---|---|---|
| High · P55 | Index design | Review an index for a frequently joined ERP relationship. | ERP_Core | Referential operations may scan more data than necessary. | Validate the workload and proposed key order in a representative environment before change. |
Best-practice summary: Protect master, model, msdb, and TempDB according to their distinct recovery and operational roles. Test restoration and rebuild procedures before an incident.
Availability, access, recovery configuration, capacity, and backup evidence for SQL Server system databases.
Expected system databases discovered.
System database records with an exception.
Backup evidence for master, model, and msdb.
| Database | State | Accessible | Recovery | Compatibility | Size | Last full backup | Assessment | Recommended action |
|---|---|---|---|---|---|---|---|---|
| master | ONLINE | Yes | SIMPLE | 150 | 512 MB | 2026-08-13 01:00 | No exception identified | Retain the evidence and continue scheduled review of availability, access, recovery configuration, and backups. |
| model | ONLINE | Yes | FULL | 150 | 128 MB | 2026-08-13 01:00 | No exception identified | Retain the evidence and continue scheduled review of availability, access, recovery configuration, and backups. |
| msdb | ONLINE | Yes | SIMPLE | 150 | 1,024 MB | 2026-08-13 01:00 | No exception identified | Retain the evidence and continue scheduled review of availability, access, recovery configuration, and backups. |
| tempdb | ONLINE | Yes | SIMPLE | 150 | 8,192 MB | Not applicable | No exception identified | Retain the evidence and continue scheduled review of availability, access, recovery configuration, and backups. |
Availability and execution status are assessed independently for each procedure. Configured Disabled means Guardian One detected the procedure but did not execute it. Missing, hidden, unauthorised, or configured-disabled procedures do not reduce native Guardian One coverage and are not interpreted as healthy or unhealthy SQL Server evidence.
| Procedure | Collection status | Execution status | Toolkit database | Limitation |
|---|---|---|---|---|
| Not assessed. First Responder Kit capability evidence was not collected or persisted. Native Guardian One assessment evidence remains available; absence is not a pass. | ||||
Best-practice summary: Treat compliance as evidence of control operation, ownership, exceptions, and remediation—not a one-time score. Expire exceptions and retain approvals and validation records.
Evidence-led control overview for prioritisation and governance. This section does not constitute certification, formal attestation, or confirmation that all applicable organisational, contractual, or regulatory controls were tested.
SQL Server administrative access controls. 1 control(s): 0 needing attention, 0 approved exception(s), 0 requiring review, 0 not assessed.
SQL Server network protocol controls. 1 control(s): 0 needing attention, 0 approved exception(s), 1 requiring review, 0 not assessed.
SQL Server attack-surface configuration controls. 1 control(s): 0 needing attention, 0 approved exception(s), 0 requiring review, 0 not assessed.
SQL Server build and update governance. 1 control(s): 0 needing attention, 0 approved exception(s), 0 requiring review, 1 not assessed.
SQL sensitivity-classification metadata coverage. 1 control(s): 1 needing attention, 0 approved exception(s), 0 requiring review, 0 not assessed.
| Topic | Control | Why this matters | Expected state | Observed state | Result | Recommended action |
|---|---|---|---|---|---|---|
| Data governance | Sensitive-data classification metadata reviewed | Classification metadata supports accountable data handling. | Documented review | ERP_Core 72% classified | Needs attention | Complete the classification review with the application and data owners. |
| Network security | SQL Server Browser service disabled unless required | The service advertises instance information. | Disabled unless approved | Running for named-instance discovery | Review required | Confirm the documented dependency and owner; disable the service if it is not required. |
| Access governance | Database Engine uses a managed domain identity | Managed identities support central lifecycle control. | Approved managed identity | DEMO\svc_sql_erp | Pass | Retain the approved identity and periodic access review. |
| Secure configuration | 'xp_cmdshell' disabled | Operating-system command execution increases compromise impact. | Disabled | Disabled | Pass | Retain the approved configuration. |
| Patch management | SQL Server patch level | Build currency requires comparison with a maintained, customer-approved SQL Server patch baseline. | The installed SQL Server build is supported by Microsoft and meets the organisation's approved patch baseline. | Installed build: 15.0.4430.1; update level: CU | Not assessed | Configure or confirm the organisation's approved SQL Server patch baseline before assessing this control; the recorded build alone is not evidence of failure or compliance. |
Best-practice summary: Activity evidence is a bounded sample. Correlate waits, blocking, grants, I/O, TempDB, and Query Store across representative periods before diagnosing a root cause.
Current requests and memory grants are a bounded point-in-time view. Current-request query text and user, host, and application identities are deliberately excluded.
Largest selected non-idle wait since the wait statistics were last reset.
Total across the ten displayed wait types; waits can overlap across concurrent tasks.
Requests blocked at the point of collection.
| Area | Observed evidence | Advisory |
|---|---|---|
| Current workload | 0 user request(s); 0 blocked at collection time. | No blocking was sampled. Reassess during a representative busy period before concluding that blocking is absent. |
| Query memory | 0 active grant(s); 0 waiting without a grant. | No grant wait was sampled. Use repeated assessments and Query Store evidence to validate workload behaviour. |
| Database file I/O | Worst busy-file average: 9.4 ms read; 3.8 ms write. | Correlate latency at or above 20 ms with waits, workload and storage telemetry; cumulative averages do not identify a single incident. |
| TempDB | 37.5% allocated; version store 6.2% of data-file capacity. | Review allocation across several assessments, active versioning work, spills and autogrowth before resizing. |
| Historical query evidence | 1 database status row(s); 1 review candidate(s). | Validate ranked candidates in their application context; do not force plans or change queries from aggregate evidence alone. |
| Session / request | Database | State / command | Wait / blocker | Elapsed / CPU | Logical reads / I/O |
|---|---|---|---|---|---|
| No user requests were active at the point of collection. | |||||
| Session / request | Database | Requested | Granted | Used | Peak used | Wait |
|---|---|---|---|---|---|---|
| No query memory grants were active at the point of collection. | ||||||
Average latency is cumulative since SQL Server started or the file counters were reset. Physical paths are retained as repository evidence but omitted from this report.
| ERP_Core | ERP_Core | ROWS | 185,000 | 9.40 ms | 47,000 | 3.80 ms | 240.0 GB |
This is a point-in-time allocation view and does not establish a growth trend.
| Measure | Observed | Interpretation |
|---|---|---|
| Data-file capacity | 8,192.0 MB | Total configured TempDB data-file size at collection time. |
| Allocated | 37.5% | 5,120.0 MB remained unallocated. |
| Version store | 512.0 MB | Row versions retained at collection time. |
| Internal / user objects | 1,024.0 / 256.0 MB | Workspace and user-object allocations. |
| Data files | 8 | Count only; file symmetry should be reviewed with the detailed file evidence. |
Wait statistics are cumulative SQL Server evidence since the instance started or the counters were reset. Correlate them with current workload and query evidence.
| Wait type | Area | Wait time | Share | Tasks | Average | Signal | Interpretation and next review |
|---|---|---|---|---|---|---|---|
| PAGEIOLATCH_SH | Data file I/O | 82.0 sec | 100.0% | 180 | 455.6 ms | 5.1% | Check storage latency, memory pressure, large scans, and indexes before attributing the wait to storage alone. |
| Database | State | Capture mode | Storage | Evidence window | Limitations |
|---|---|---|---|---|---|
| ERP_Core | READ_WRITE | AUTO | 384.0 MB of 2,048 MB | 2026-08-06 00:00 to 2026-08-13 17:00 | Bounded retained evidence; Guardian One does not alter Query Store configuration. |
Candidates are ranked by total duration within the configured bounded window. The captured query excerpt keeps the report useful after the Query Store window changes.
| Database | Query ID | Plan ID | Captured query | Executions | Average duration | Average CPU | Average reads | Safe next review |
|---|---|---|---|---|---|---|---|---|
| ERP_Core | 1842 | 7 | SELECT OrderId, CustomerId FROM dbo.Orders WHERE CustomerId = @CustomerId | 920 | 1,180.5 ms | 612.4 ms | 18,400 | Review the identified query and plan in its application context. Validate plan history, parameters, concurrency, and business criticality before tuning or forcing a plan. |