Guardian One

SQL Server Assessment Report

Role-Based Assessment Summary

Summary statusRed — immediate review

Action required now

Assign accountable owners and review the red and highest-priority findings before approving related change.

Why this status Security risk · Resilience or recovery risk · Performance enhancement · Configuration or best-practice review · Compliance attention · Evidence gap

Shared evidence, different decisions: These summaries are derived from the detail below. They do not replace control-owner review, technical validation, or continuous monitoring.

Senior management

76/100

Point-in-time health is Review recommended. 3 prioritised SQL finding(s) and 2 compliance control(s) require accountable review.

Action

Confirm risk owners, priority and delivery dates.

Compliance and risk

2 attention

5 control(s) were represented: 1 not assessed and 0 approved exception(s). Unavailable or unassessed evidence is never treated as a pass.

Action

Validate scope, evidence period, exceptions and reviewer sign-off.

DBA and development leads

4 findings

1 application finding(s), 2 native assessment finding(s), and 1 optional-toolkit finding(s) need triage across 6 database(s).

Action

Allocate owners, validate dependencies and sequence safe changes.

Hands-on DBA and SQL development

3 prioritised

Use the SQL, application, maintenance and evidence sections for observed values and safe next reviews. Reproduce evidence before change and retain rollback and validation results.

Action

Investigate the highest-priority evidence first; do not apply recommendations autonomously.

Business-Risk Context

External context: Gallagher's UK Business Risk Index ranked cyber-crime third among the surveyed business risks. Guardian One only contributes bounded SQL/data-platform evidence; the customer owns likelihood, impact and enterprise-risk decisions.

Cyber-crime context

2 review signal(s)

Counted from SQL security and relevant compliance evidence. This is not vulnerability scanning, attack detection, EDR, network assurance or incident response.

Operational and cost context

2 review signal(s)

Backup, database and capacity findings may help prioritise avoidable SQL interruption or recovery exposure. Guardian One does not forecast cash flow, prices or supply-chain performance.

Assessment Snapshot

Summary statusRed — immediate review

Action required now

Assign accountable owners and review the red and highest-priority findings before approving related change.

Why this status Security risk · Resilience or recovery risk · Performance enhancement · Configuration or best-practice review · Compliance attention · Evidence gap

Best-practice summary: Use the snapshot to prioritise validation, not as proof of continuous health. Compare repeat assessments, business context, incidents, and owned monitoring before approving change.

Assessment health

76/100 — Review recommended

Point-in-time assessment score, not a live service indicator.

Findings by risk

Click a bar to filter findings; click it again to clear.

Largest databases

Click a database to filter findings; click it again to clear.

System databases

Machine Summary

Summary statusRed — immediate review

Action required now

Assign accountable owners and review the red and highest-priority findings before approving related change.

Why this status Security risk · Resilience or recovery risk · Performance enhancement · Configuration or best-practice review · Compliance attention · Evidence gap

Best-practice summary: Size CPU, memory, paging, and storage from representative demand with operating-system and virtual-host headroom. Confirm sustained patterns before changing platform resources.

Machine
GO-DEMO-SQL02
Windows evidence: CompletePersisted snapshot captured 2026-08-13T17:00:00+01:00.

Guardian One native coverage: Core SQL Server and Windows evidence, insights, risks and recommendations do not require third-party diagnostic tools. Approved third-party tool output supplements this baseline when installed and available.

Machine summary

Machine: GO-DEMO-SQL02

CPU: Latest SQL scheduler-health CPU shares: SQL Server 34%, Other processes 11%, Idle 55%. Windows host CPU was 45.0% at capture across 48 logical processor(s).

Storage: Storage capacity was reported for 2 paths; L: had the lowest headroom at 46.1 GB free of 256.0 GB (18% free).

Memory: SQL Server had allocated 90.0 GB of its 96.0 GB target (94%). Windows reported 28.0 GB available of 128.0 GB physical RAM and 36.0 GB available of its 144.0 GB commit limit.

Evidence: Windows host evidence was complete. No customer environment classification or machine-build template was configured.

Interpretation: These are point-in-time values; compare repeat assessments before changing capacity or configuration.

Drive summary

D:Mount point: D: · 392.0 GB free of 1,024.0 GB · NTFS
62% used
L:Mount point: L: · 46.1 GB free of 256.0 GB · NTFS
82% used

Host I/O sample: 9.4 ms read, 3.8 ms write; 460.5 reads/s and 188.2 writes/s.

CPU usage

45%0%00+0100+01
  • SQL Server: 34%
  • Other processes: 11%
  • Idle: 55%

45.0% Windows CPU at capture; 2 socket(s), 24 core(s), 48 logical processor(s).

Recent scheduler-health samples provide SQL shares; Windows utilisation is a persisted point-in-time host sample.

Machine memory and page file

Windows memory and commit

28.0 GB available of 128.0 GB physical RAM

36.0 GB available of 144.0 GB commit limit

Page files

  • C:\pagefile.sys (system managed)2.0 of 16.0 GB used (12%)

SQL Server memory

104 GB52 GB0

90.0 GB allocated of 96.0 GB target

Remote SQL Server memory-manager counters. Trend uses periodic Guardian One assessments.

Largest caches and clerks

  • Ad hoc plan cache3,072 MB
  • Procedure plan cache1,536 MB

Machine build template

Environment: Not classified · Template: Not configured · Status: Not Assessed

Risk: Not assessed.
Recommendation: Review customer configuration.

Machine detail

Server detailObserved value
Windows operating systemMicrosoft Windows Server 2022 Standard
Windows version10.0.20348
Windows domainDEMO.EXAMPLE
Windows host started2026-08-06T07:30:00+01:00
Windows evidence captured2026-08-13T17:00:00+01:00
Machine nameGO-DEMO-SQL02
DomainDEMO.EXAMPLE
Host operating systemMicrosoft Windows Server 2022 Standard

Machine insights and recommendations

AttentionInsightRiskRecommendationConfidence and limits
MEDIUMTransaction-log volume headroom requires review
The log volume had 18% free capacity at the assessment point.
Requires review.Compare retained growth with the operational forecast, then pre-size files or storage through approved change control.Not stated
Point-in-time evidence.

SQL Server Summary

Summary statusRed — immediate review

Action required now

Assign accountable owners and review the red and highest-priority findings before approving related change.

Why this status Security risk · Resilience or recovery risk · Performance enhancement · Configuration or best-practice review · Compliance attention · Evidence gap

Best-practice summary: Run a supported SQL Server build with tested cumulative updates; use dedicated least-privilege service identities; validate maximum memory, MAXDOP, cost threshold and tempdb against the workload; and review SQL Server and Agent errors after every scheduled assessment.

SQL Server
GO-DEMO-SQL02\ERP
Version
15.0.4430.1
Edition
Enterprise Edition
Product level
CU
Assessment completed
2026-08-13 17:00

Native baseline: This summary is produced from Guardian One collectors. Approved third-party diagnostics add supplementary evidence when available but are not required for the core assessment.

PropertyObserved value
Server and instanceGO-DEMO-SQL02\ERP
Machine nameGO-DEMO-SQL02
EditionEnterprise Edition
Product version15.0.4430.1
Product levelCU
Database Engine service accountDEMO\svc_sql_erp
Database Engine started2026-08-06 07:45
Default trace fileD:\SQLTrace\log.trc (Running)

SQL Server and SQL Agent Log Issues

Collection status: Not Assessed. Window: not recorded days. Retained rows matching the review window: 0. Safety cap: not recorded rows. Source status was not persisted.

Issue categoryCountPatternEarliest observedLatest observedSourceRiskRecommendation
No classified errors or failures were found in the bounded evidence that was successfully read. This does not guarantee that no issue exists; review collection status, scope, retention and external logs.

Default Trace Insights

Collection status: Not Assessed. Rows reviewed: 0 of 0. Trace retention and scope are limited.

InsightEventCountLatest observedDatabase scopeRiskRecommendation
No classified trace events were returned. This is not proof that no event occurred; review collection status and trace retention.

SQL Server Storage

Best-practice summary: Pre-size data, log, and TempDB for measured demand; prefer workload-tested fixed-MB growth, avoid routine shrink, and govern free capacity through customer monitoring.

Point-in-time SQL Server file placement, capacity, and automatic-growth configuration. Growth settings reduce operational surprises but do not replace capacity monitoring or workload-based sizing.

Database files

3

Files assessed across system and user databases.

Fixed growth

3

Files using predictable fixed-MB increments.

Percentage growth

0

Review and replace with workload-tested fixed increments.

Growth disabled

0

Confirm these files are intentionally fixed and adequately pre-sized.

Retained Drive Capacity History

These are scheduled, point-in-time Guardian One samples retained for up to 730 days. Exhaustion dates are estimates based on measured SQL file allocation growth and the latest volume free space; other files, purge activity, compression, movement and workload changes can alter the outcome.

Drive or mount pointEvidence windowFirst SQL allocationLatest SQL allocationAllocation changeLatest freeFree-space changeAverage growthEstimated exhaustionConfidence and limitation
No retained drive-capacity series is available yet. A new assessment records a sample; at least three measured samples over the configured minimum window are required for projection.

Retained Database Capacity History

DatabaseEvidence windowFirst allocatedLatest allocatedLatest usedChangeAverage growth90-day estimateConfidence and limitation
No retained database-capacity series is available yet.

Retained Table Capacity History

Table-level history is disabled by default. Enable the governed CapacityHistoryTableCollectionEnabled setting when the customer approves bounded object-level size collection.

Database.schema.tableEvidence windowFirst reservedLatest reservedLatest usedChangeAverage growth90-day estimateConfidence and limitation
No retained table-capacity series is available for this assessment window.

Database File Growth Settings and Recommendations

DatabaseLogical fileTypeCurrent sizeMaximumGrowthRecommendation
ERP_CoreERP_Core_logLOG64.0 GB128.0 GB1.0 GBFixed growth and a file maximum are configured. Validate both against recent consumption, free volume capacity, maintenance windows, and recovery objectives.
ERP_CoreERP_CoreROWS240.0 GB600.0 GB1.0 GBFixed growth and a file maximum are configured. Validate both against recent consumption, free volume capacity, maintenance windows, and recovery objectives.
tempdbtempdevROWS8.0 GB32.0 GB512 MBFixed growth and a file maximum are configured. Validate both against recent consumption, free volume capacity, maintenance windows, and recovery objectives.

Database and Backup Growth Patterns

Full-backup size is a corroborating signal, not a direct measure of allocated file growth. Compression, changed-page density, backup scope, and data churn can affect the series. Longer-term forecasts should use retained database and file samples.

DatabaseEvidence windowFull backupsFirst sizeLatest sizeChangeAverageCurrent allocatedVolume freeInterpretation and next step
At least two dated, non-copy-only full-backup size samples are required for a growth pattern.

SQL Server Storage Locations

RoleConfigured or observed pathVolumeCapacityFiles
DataD:\SQLDataD:\401,408 MB free of 1,048,576 MB9
Transaction logsL:\SQLLogL:\47,186 MB free of 262,144 MB6
tempdb dataT:\SQLTempT:\98,304 MB free of 131,072 MB8
SQL binariesC:\Program Files\Microsoft SQL Server\MSSQL15.ERP\MSSQL\Binn\sqlservr.exeNot applicable — executable location onlyNot applicable
Default dataD:\SQLDataNot assessed — no matched volume evidenceNot assessed — directory count unavailable
Default transaction logsL:\SQLLogNot assessed — no matched volume evidenceNot assessed — directory count unavailable
Default backupsB:\SQLBackupNot assessed — no matched volume evidence24

SQL Server

Best-practice summary: Validate each finding against workload, version, edition, dependencies, ownership, test evidence, approval, and rollback. Similar symptoms can have different causes.

Consolidated point-in-time findings from Guardian One assessment rules and supporting diagnostic evidence. Review recommendations with accountable service owners and qualified SQL specialists before making production changes.

Attention Group Finding Database Details Risk Recommendation Guidance summary
Immediate review
Priority 25
Backup ERP reporting database full backup outside target
Guardian One native rule
Instance level The latest retained full-backup evidence is older than the demonstration recovery target. The condition may affect the assessed SQL Server if left unresolved. Validate the backup schedule and complete a governed restore test before closing the finding. Guardian One assessment rule. Validate the evidence and proposed change with the responsible technical owner.
High attention
Priority 55
Index design Review an index for a frequently joined ERP relationship.
Guardian One application database assessment
ERP_Core Referential operations may scan more data than necessary. Validate the workload and proposed key order in a representative environment before change. No additional guidance summary is available.
High attention
Priority 75
Capacity Transaction-log volume headroom requires review
Guardian One native rule
Instance level The log volume had 18% free capacity at the assessment point. The condition may affect the assessed SQL Server if left unresolved. Compare retained growth with the operational forecast, then pre-size files or storage through approved change control. Guardian One assessment rule. Validate the evidence and proposed change with the responsible technical owner.

Maintenance Suggestions

Best-practice summary: Define maintenance from recovery objectives, workload, data change, and available windows. Prove backup recoverability and integrity outcomes; do not schedule commands merely because they are available.

Review-only maintenance starting points based on the collected evidence. Guardian One does not execute these commands, create schedules, or replace customer monitoring. Confirm recovery objectives, maintenance windows, edition support, storage, permissions, and change approval first.

What Why Suggested timing Example command Risks and validation Guidance summary

Application Database Checks

Best-practice summary: Preserve application contracts. Review schema, constraints, indexes, options, and query patterns with developers, then test correctness, concurrency, performance, and rollback before deployment.

Schema, integrity, configuration, indexing, and transaction-log checks for user databases. Findings are ordered by priority and should be validated against application behaviour before changes are made.

Persisted user-database inventory

This inventory provides assessment context even when no application-design exception was identified or persisted.

DatabaseStateRecovery modelCompatibilitySizeLast full backup
ERP_CoreONLINEFULL150286,720 MB2026-08-13 02:00
ERP_ReportingONLINEFULL15092,160 MB2026-08-10 02:00

Databases affected

1

User databases represented in the findings.

Filter by group

Findings identified

1

Items requiring review across user databases.

Filter by priority

Showing all 1 application findings.

AttentionGroupFindingDatabaseDetailsRiskRecommendation
High · P55 Index design Review an index for a frequently joined ERP relationship. ERP_Core Referential operations may scan more data than necessary. Validate the workload and proposed key order in a representative environment before change.

System Database Checks

Best-practice summary: Protect master, model, msdb, and TempDB according to their distinct recovery and operational roles. Test restoration and rebuild procedures before an incident.

Availability, access, recovery configuration, capacity, and backup evidence for SQL Server system databases.

System databases

4 of 4

Expected system databases discovered.

Needs attention

0

System database records with an exception.

Full backups recorded

3 of 3

Backup evidence for master, model, and msdb.

DatabaseStateAccessibleRecoveryCompatibilitySizeLast full backupAssessmentRecommended action
masterONLINEYesSIMPLE150512 MB2026-08-13 01:00No exception identifiedRetain the evidence and continue scheduled review of availability, access, recovery configuration, and backups.
modelONLINEYesFULL150128 MB2026-08-13 01:00No exception identifiedRetain the evidence and continue scheduled review of availability, access, recovery configuration, and backups.
msdbONLINEYesSIMPLE1501,024 MB2026-08-13 01:00No exception identifiedRetain the evidence and continue scheduled review of availability, access, recovery configuration, and backups.
tempdbONLINEYesSIMPLE1508,192 MBNot applicableNo exception identifiedRetain the evidence and continue scheduled review of availability, access, recovery configuration, and backups.

Evidence Summary

Optional First Responder Kit capabilities

Availability and execution status are assessed independently for each procedure. Configured Disabled means Guardian One detected the procedure but did not execute it. Missing, hidden, unauthorised, or configured-disabled procedures do not reduce native Guardian One coverage and are not interpreted as healthy or unhealthy SQL Server evidence.

ProcedureCollection statusExecution statusToolkit databaseLimitation
Not assessed. First Responder Kit capability evidence was not collected or persisted. Native Guardian One assessment evidence remains available; absence is not a pass.

Compliance Overview

Best-practice summary: Treat compliance as evidence of control operation, ownership, exceptions, and remediation—not a one-time score. Expire exceptions and retain approvals and validation records.

Evidence-led control overview for prioritisation and governance. This section does not constitute certification, formal attestation, or confirmation that all applicable organisational, contractual, or regulatory controls were tested.

Access governance

SQL Server administrative access controls. 1 control(s): 0 needing attention, 0 approved exception(s), 0 requiring review, 0 not assessed.

Network security

SQL Server network protocol controls. 1 control(s): 0 needing attention, 0 approved exception(s), 1 requiring review, 0 not assessed.

Secure configuration

SQL Server attack-surface configuration controls. 1 control(s): 0 needing attention, 0 approved exception(s), 0 requiring review, 0 not assessed.

Patch management

SQL Server build and update governance. 1 control(s): 0 needing attention, 0 approved exception(s), 0 requiring review, 1 not assessed.

Data governance

SQL sensitivity-classification metadata coverage. 1 control(s): 1 needing attention, 0 approved exception(s), 0 requiring review, 0 not assessed.

Compliance Control Results

TopicControlWhy this mattersExpected stateObserved stateResultRecommended action
Data governance Sensitive-data classification metadata reviewed Classification metadata supports accountable data handling. Documented review ERP_Core 72% classified Needs attention Complete the classification review with the application and data owners.
Network security SQL Server Browser service disabled unless required The service advertises instance information. Disabled unless approved Running for named-instance discovery Review required Confirm the documented dependency and owner; disable the service if it is not required.
Access governance Database Engine uses a managed domain identity Managed identities support central lifecycle control. Approved managed identity DEMO\svc_sql_erp Pass Retain the approved identity and periodic access review.
Secure configuration 'xp_cmdshell' disabled Operating-system command execution increases compromise impact. Disabled Disabled Pass Retain the approved configuration.
Patch management SQL Server patch level Build currency requires comparison with a maintained, customer-approved SQL Server patch baseline. The installed SQL Server build is supported by Microsoft and meets the organisation's approved patch baseline. Installed build: 15.0.4430.1; update level: CU Not assessed Configure or confirm the organisation's approved SQL Server patch baseline before assessing this control; the recorded build alone is not evidence of failure or compliance.

Activity Overview

Best-practice summary: Activity evidence is a bounded sample. Correlate waits, blocking, grants, I/O, TempDB, and Query Store across representative periods before diagnosing a root cause.

Current requests and memory grants are a bounded point-in-time view. Current-request query text and user, host, and application identities are deliberately excluded.

Leading cumulative wait

PAGEIOLATCH_SH

Largest selected non-idle wait since the wait statistics were last reset.

Selected wait time

0.0 h

Total across the ten displayed wait types; waits can overlap across concurrent tasks.

Currently blocked requests

0

Requests blocked at the point of collection.

Quantum advisories

AreaObserved evidenceAdvisory
Current workload0 user request(s); 0 blocked at collection time.No blocking was sampled. Reassess during a representative busy period before concluding that blocking is absent.
Query memory0 active grant(s); 0 waiting without a grant.No grant wait was sampled. Use repeated assessments and Query Store evidence to validate workload behaviour.
Database file I/OWorst busy-file average: 9.4 ms read; 3.8 ms write.Correlate latency at or above 20 ms with waits, workload and storage telemetry; cumulative averages do not identify a single incident.
TempDB37.5% allocated; version store 6.2% of data-file capacity.Review allocation across several assessments, active versioning work, spills and autogrowth before resizing.
Historical query evidence1 database status row(s); 1 review candidate(s).Validate ranked candidates in their application context; do not force plans or change queries from aggregate evidence alone.

Current requests

Session / requestDatabaseState / commandWait / blockerElapsed / CPULogical reads / I/O
No user requests were active at the point of collection.

Query memory grants

Session / requestDatabaseRequestedGrantedUsedPeak usedWait
No query memory grants were active at the point of collection.

Database file I/O

Average latency is cumulative since SQL Server started or the file counters were reset. Physical paths are retained as repository evidence but omitted from this report.

ERP_CoreERP_CoreROWS185,0009.40 ms47,0003.80 ms240.0 GB

TempDB allocation

This is a point-in-time allocation view and does not establish a growth trend.

MeasureObservedInterpretation
Data-file capacity8,192.0 MBTotal configured TempDB data-file size at collection time.
Allocated37.5%5,120.0 MB remained unallocated.
Version store512.0 MBRow versions retained at collection time.
Internal / user objects1,024.0 / 256.0 MBWorkspace and user-object allocations.
Data files8Count only; file symmetry should be reviewed with the detailed file evidence.

Leading non-idle waits

Wait statistics are cumulative SQL Server evidence since the instance started or the counters were reset. Correlate them with current workload and query evidence.

Wait typeAreaWait timeShareTasksAverageSignalInterpretation and next review
PAGEIOLATCH_SHData file I/O82.0 sec100.0%180455.6 ms5.1%Check storage latency, memory pressure, large scans, and indexes before attributing the wait to storage alone.

Query Store coverage

DatabaseStateCapture modeStorageEvidence windowLimitations
ERP_CoreREAD_WRITEAUTO384.0 MB of 2,048 MB2026-08-06 00:00 to 2026-08-13 17:00Bounded retained evidence; Guardian One does not alter Query Store configuration.

Query Store review candidates

Candidates are ranked by total duration within the configured bounded window. The captured query excerpt keeps the report useful after the Query Store window changes.

DatabaseQuery IDPlan IDCaptured queryExecutionsAverage durationAverage CPUAverage readsSafe next review
ERP_Core18427SELECT OrderId, CustomerId FROM dbo.Orders WHERE CustomerId = @CustomerId9201,180.5 ms612.4 ms18,400Review the identified query and plan in its application context. Validate plan history, parameters, concurrency, and business criticality before tuning or forcing a plan.