Guardian One

SQL Server Assessment Report

Guardian One

SQL Server Assessment Report

GO-DEMO-SQL02\ERP

Assessment date: 2026-08-13 17:00

Overall status: Red — immediate review

Assign accountable owners and review the red and highest-priority findings before approving related change.

Governance view: This report provides retained, point-in-time evidence for leadership decisions, control review and audit follow-up.

Executive Summary

AreaStatusKey message
Overall healthRed — immediate reviewAssign accountable owners and review the red and highest-priority findings before approving related change.
SecurityAttention2 item(s) require review
Backup & recoveryAttention2 recovery signals retained
PerformanceOKNo immediate performance issue identified
CapacityAttentionLog volume requires review
ComplianceAttention2 item(s) require review

Top 3 actions

  1. Validate the backup schedule and complete a governed restore test before closing the finding.
  2. Compare retained growth with the operational forecast, then pre-size files or storage through approved change control.
  3. Validate the workload and proposed key order in a representative environment before change.

Key Findings

HIGH — Backup

Finding: ERP reporting database full backup outside target

Risk: The latest retained full-backup evidence is older than the demonstration recovery target.

Recommended action: Validate the backup schedule and complete a governed restore test before closing the finding.

Owner
DBA
Priority
Immediate
Status
Open

MEDIUM — Capacity

Finding: Transaction-log volume headroom requires review

Risk: The log volume had 18% free capacity at the assessment point.

Recommended action: Compare retained growth with the operational forecast, then pre-size files or storage through approved change control.

Owner
DBA
Priority
Review
Status
Open

High attention — Index design

Finding: Review an index for a frequently joined ERP relationship.

Risk: Referential operations may scan more data than necessary.

Recommended action: Validate the workload and proposed key order in a representative environment before change.

Owner
DBA
Priority
Review
Status
Open

SQL Server Overview

ServerGO-DEMO-SQL02InstanceERPSQL Server15.0.4430.1 Enterprise EditionAssessment2026-08-13 17:00
CPU45% utilised
Memory128 GB
SQL memory90 GB
Log volume82% used
Databases6

What this means: These are point-in-time indicators derived from retained evidence; validate trends and workload context before changing capacity or configuration.

Security & Compliance

ControlResultAction
Sensitive-data classification metadata reviewedNeeds attentionComplete the classification review with the application and data owners.
SQL Server patch levelNot assessedConfigure or confirm the organisation's approved SQL Server patch baseline before assessing this control; the recorded build alone is not evidence of failure or compliance.
SQL Server Browser service disabled unless requiredReview requiredConfirm the documented dependency and owner; disable the service if it is not required.
'xp_cmdshell' disabledPassNone
Database Engine uses a managed domain identityPassNone

Detailed control evidence and version-applicability notes remain in the technical evidence section.

Capacity & Performance

CPU45% utilised
Memory128 GB
SQL memory90 GB
Log volume82% used
Databases6

Interpretation: Indicators are bounded samples, not continuous monitoring or guaranteed exhaustion forecasts.

Database Summary

DatabaseSizeRecoveryBackupStatus
master512 MBSIMPLE2026-08-13 01:00No exception identified
model128 MBFULL2026-08-13 01:00No exception identified
msdb1024 MBSIMPLE2026-08-13 01:00No exception identified
tempdb8192 MBSIMPLENone recordedNo exception identified
ERP_Core286720 MBFULL2026-08-13 02:00Review
1 finding
ERP_Reporting92160 MBFULL2026-08-10 02:00No exception identified

Role-Based Assessment Summary

Shared evidence, different decisions: These summaries are derived from the detail below. They do not replace control-owner review, technical validation, or continuous monitoring.

Senior management

76/100

Point-in-time health is Review recommended. 3 prioritised SQL finding(s) and 2 compliance control(s) require accountable review.

Action

Confirm risk owners, priority and delivery dates.

Compliance and risk

2 attention

5 control(s) were represented: 1 not assessed and 0 approved exception(s). Unavailable or unassessed evidence is never treated as a pass.

Action

Validate scope, evidence period, exceptions and reviewer sign-off.

DBA and development leads

4 findings

1 application finding(s), 2 native assessment finding(s), and 1 optional-toolkit finding(s) need triage across 6 database(s).

Action

Allocate owners, validate dependencies and sequence safe changes.

Hands-on DBA and SQL development

3 prioritised

Use the SQL, application, maintenance and evidence sections for observed values and safe next reviews. Reproduce evidence before change and retain rollback and validation results.

Action

Investigate the highest-priority evidence first; do not apply recommendations autonomously.

Business-Risk Context

External context: Gallagher's UK Business Risk Index ranked cyber-crime third among the surveyed business risks. Guardian One only contributes bounded SQL/data-platform evidence; the customer owns likelihood, impact and enterprise-risk decisions.

Cyber-crime context

2 review signals

Counted from SQL security and relevant compliance evidence. This is not vulnerability scanning, attack detection, EDR, network assurance or incident response.

Operational and cost context

2 review signals

Backup, database and capacity findings may help prioritise avoidable SQL interruption or recovery exposure. Guardian One does not forecast cash flow, prices or supply-chain performance.

Assessment Snapshot

Evidence note: Overall status is shown in the executive summary. This section contains supporting technical evidence.

Best-practice summary: Use the snapshot to prioritise validation, not as proof of continuous health. Compare repeat assessments, business context, incidents, and owned monitoring before approving change.

Assessment health

76/100 — Review recommended

Point-in-time assessment score, not a live service indicator.

Findings by risk

Click a bar to filter findings; click it again to clear.

Largest databases

Click a database to filter findings; click it again to clear.

System databases

Machine Summary

Evidence note: Overall status is shown in the executive summary. This section contains supporting technical evidence.

Best-practice summary: Size CPU, memory, paging, and storage from representative demand with operating-system and virtual-host headroom. Confirm sustained patterns before changing platform resources.

Machine
GO-DEMO-SQL02
Windows evidence: CompletePersisted snapshot captured 2026-08-13T17:00:00+01:00.

Guardian One native coverage: Core SQL Server and Windows evidence, insights, risks and recommendations do not require third-party diagnostic tools. Approved third-party tool output supplements this baseline when installed and available.

Machine summary

Machine: GO-DEMO-SQL02

CPU: Latest SQL scheduler-health CPU shares: SQL Server 34%, Other processes 11%, Idle 55%. Windows host CPU was 45.0% at capture across 48 logical processor(s).

Storage: Storage capacity was reported for 2 paths; L: had the lowest headroom at 46.1 GB free of 256.0 GB (18% free).

Memory: SQL Server had allocated 90.0 GB of its 96.0 GB target (94%). Windows reported 28.0 GB available of 128.0 GB physical RAM and 36.0 GB available of its 144.0 GB commit limit.

Evidence: Windows host evidence was complete. No customer environment classification or machine-build template was configured.

Interpretation: These are point-in-time values; compare repeat assessments before changing capacity or configuration.

Machine build template

Environment: Not classified · Template: Not configured · Status: Not Assessed

Risk: Not assessed.
Recommendation: Review customer configuration.

Drive summary

D:Mount point: D: · 392.0 GB free of 1,024.0 GB · NTFS
62% used
L:Mount point: L: · 46.1 GB free of 256.0 GB · NTFS
82% used

Host I/O sample: 9.4 ms read, 3.8 ms write; 460.5 reads/s and 188.2 writes/s.

CPU usage

45%0%00+0100+01
  • SQL Server: 34%
  • Other processes: 11%
  • Idle: 55%

45.0% Windows CPU at capture; 2 socket(s), 24 core(s), 48 logical processor(s).

Recent scheduler-health samples provide SQL shares; Windows utilisation is a persisted point-in-time host sample.

Machine memory and page file

Windows memory and commit

28.0 GB available of 128.0 GB physical RAM

36.0 GB available of 144.0 GB commit limit

Page files

  • C:\pagefile.sys (system managed)2.0 of 16.0 GB used (12%)

SQL Server memory

104 GB52 GB0

90.0 GB allocated of 96.0 GB target

Remote SQL Server memory-manager counters. Trend uses periodic Guardian One assessments.

Largest caches and clerks

  • Ad hoc plan cache3,072 MB
  • Procedure plan cache1,536 MB

Machine detail

Server detailObserved value
Operating system, as Windows reports itMicrosoft Windows Server 2022 Standard
Windows version10.0.20348
Windows domainDEMO.EXAMPLE
Windows host started2026-08-06T07:30:00+01:00
Windows evidence captured2026-08-13T17:00:00+01:00
Machine nameGO-DEMO-SQL02
DomainDEMO.EXAMPLE
Operating systemMicrosoft Windows Server 2022 Standard

Machine insights and recommendations

AttentionInsightRiskRecommendationConfidence and limits
MEDIUMTransaction-log volume headroom requires review
The log volume had 18% free capacity at the assessment point.
Requires review.Compare retained growth with the operational forecast, then pre-size files or storage through approved change control.Not stated
Point-in-time evidence.

SQL Server Summary

Evidence note: Overall status is shown in the executive summary. This section contains supporting technical evidence.

Best-practice summary: Run a supported SQL Server build with tested cumulative updates; use dedicated least-privilege service identities; validate maximum memory, MAXDOP, cost threshold and tempdb against the workload; and review SQL Server and Agent errors after every scheduled assessment.

SQL Server
GO-DEMO-SQL02\ERP
Version
15.0.4430.1
Edition
Enterprise Edition
Product level
CU
Assessment completed
2026-08-13 17:00

Native baseline: This summary is produced from Guardian One collectors. Approved third-party diagnostics add supplementary evidence when available but are not required for the core assessment.

PropertyObserved value
Server and instanceGO-DEMO-SQL02\ERP
Machine nameGO-DEMO-SQL02
EditionEnterprise Edition
Product version15.0.4430.1
Product levelCU
Database Engine service accountDEMO\svc_sql_erp
Database Engine started2026-08-06 07:45
Default trace fileD:\SQLTrace\log.trc (Running)

Backup Encryption Evidence

This metadata identifies encryption associated with retained SQL Server backup records where the version exposes it. It does not prove key backup, key custody, restore recoverability or encryption of every backup file.

DatabaseEvidence statusEncryptor typeEncryptor thumbprint metadata
masterNot assessed — backup encryption metadata unavailableNot observedNot observed
modelNot assessed — backup encryption metadata unavailableNot observedNot observed
msdbNot assessed — backup encryption metadata unavailableNot observedNot observed
ERP_CoreNot assessed — backup encryption metadata unavailableNot observedNot observed
ERP_ReportingNot assessed — backup encryption metadata unavailableNot observedNot observed

SQL Server and SQL Agent Log Issues

Collection status: Not Assessed. Window: not recorded days. Retained rows matching the review window: 0. Safety cap: not recorded rows. Source status was not persisted.

Issue categoryCountPatternEarliest observedLatest observedSourceRiskRecommendation
No classified errors or failures were found in the bounded evidence that was successfully read. This does not guarantee that no issue exists; review collection status, scope, retention and external logs.

Default Trace Insights

Collection status: Not Assessed. Rows reviewed: 0 of 0. Trace retention and scope are limited.

InsightEventCountLatest observedDatabase scopeRiskRecommendation
No classified trace events were returned. This is not proof that no event occurred; review collection status and trace retention.

SQL Server Storage

Best-practice summary: Pre-size data, log, and TempDB for measured demand; prefer workload-tested fixed-MB growth, avoid routine shrink, and govern free capacity through customer monitoring.

Point-in-time SQL Server file placement, capacity, and automatic-growth configuration. Growth settings reduce operational surprises but do not replace capacity monitoring or workload-based sizing.

Database files

3

Files assessed across system and user databases.

Fixed growth

3

Files using predictable fixed-MB increments.

Percentage growth

0

Review and replace with workload-tested fixed increments.

Growth disabled

0

Confirm these files are intentionally fixed and adequately pre-sized.

Database File Growth Settings and Recommendations

DatabaseLogical fileTypeCurrent sizeMaximumGrowthResultRecommendation
ERP_CoreERP_Core_logLOG64.0 GB128.0 GB1.0 GBOKFixed growth and a file maximum are configured. Validate both against recent consumption, free volume capacity, maintenance windows, and recovery objectives.
ERP_CoreERP_CoreROWS240.0 GB600.0 GB1.0 GBOKFixed growth and a file maximum are configured. Validate both against recent consumption, free volume capacity, maintenance windows, and recovery objectives.
tempdbtempdevROWS8.0 GB32.0 GB512 MBOKFixed growth and a file maximum are configured. Validate both against recent consumption, free volume capacity, maintenance windows, and recovery objectives.

Database and Backup Growth Patterns

Full-backup size is a corroborating signal, not a direct measure of allocated file growth. Compression, changed-page density, backup scope, and data churn can affect the series. Longer-term forecasts should use retained database and file samples.

DatabaseEvidence windowFull backupsFirst sizeLatest sizeChangeAverageCurrent allocatedVolume freeInterpretation and next step
At least two dated, non-copy-only full-backup size samples are required for a growth pattern.

SQL Server Storage Locations

RoleConfigured or observed pathVolumeCapacityFiles
DataD:\SQLDataD:\401,408 MB free of 1,048,576 MB9
Transaction logsL:\SQLLogL:\47,186 MB free of 262,144 MB6
tempdb dataT:\SQLTempT:\98,304 MB free of 131,072 MB8
SQL binariesC:\Program Files\Microsoft SQL Server\MSSQL15.ERP\MSSQL\Binn\sqlservr.exeNot applicable — executable location onlyNot applicable
Default dataD:\SQLDataNot assessed — Windows storage evidence did not identify this path. Verify the path is accessible and included in volume discovery.Not assessed — directory count unavailable
Default transaction logsL:\SQLLogNot assessed — Windows storage evidence did not identify this path. Verify the path is accessible and included in volume discovery.Not assessed — directory count unavailable
Default backupsB:\SQLBackupNot assessed — Windows storage evidence did not identify this path. Verify the path is accessible and included in volume discovery.24

Database engine: SQL Server — GO-DEMO-SQL02\ERP

Best-practice summary: Validate each finding against workload, version, edition, dependencies, ownership, test evidence, approval, and rollback. Similar symptoms can have different causes.

Consolidated point-in-time findings from Guardian One assessment rules and supporting diagnostic evidence. Review recommendations with accountable service owners and qualified SQL specialists before making production changes.

Attention Group Finding Database Details Risk Recommendation Guidance summary
Immediate review
Priority 25
Backup ERP reporting database full backup outside target
Guardian One native rule
Instance level The latest retained full-backup evidence is older than the demonstration recovery target. The condition may affect the assessed SQL Server if left unresolved. Validate the backup schedule and complete a governed restore test before closing the finding. Guardian One assessment rule. Validate the evidence and proposed change with the responsible technical owner.
High attention
Priority 55
Index design Review an index for a frequently joined ERP relationship.
Guardian One application database assessment
ERP_Core Referential operations may scan more data than necessary. Validate the workload and proposed key order in a representative environment before change. No additional guidance summary is available.
High attention
Priority 75
Capacity Transaction-log volume headroom requires review
Guardian One native rule
Instance level The log volume had 18% free capacity at the assessment point. The condition may affect the assessed SQL Server if left unresolved. Compare retained growth with the operational forecast, then pre-size files or storage through approved change control. Guardian One assessment rule. Validate the evidence and proposed change with the responsible technical owner.

Maintenance Suggestions

Best-practice summary: Define maintenance from recovery objectives, workload, data change, and available windows. Prove backup recoverability and integrity outcomes; do not schedule commands merely because they are available.

Review-only maintenance starting points based on the retained evidence. Guardian One does not execute these commands, create schedules, or replace customer monitoring. Confirm recovery objectives, maintenance windows, edition support, storage, permissions, and change approval first.

What Why Suggested timing Example command Risks and validation Guidance summary

Application Database Checks

Best-practice summary: Preserve application contracts. Review schema, constraints, indexes, options, and query patterns with developers, then test correctness, concurrency, performance, and rollback before deployment.

Schema, integrity, configuration, indexing, and transaction-log checks for user databases. Findings are ordered by priority and should be validated against application behaviour before changes are made.

Persisted user-database inventory

This inventory provides assessment context even when no application-design exception was identified or persisted.

DatabaseStateRecovery modelCompatibilitySizeLast full backup
ERP_CoreONLINEFULL150286,720 MB2026-08-13 02:00
ERP_ReportingONLINEFULL15092,160 MB2026-08-10 02:00

Databases affected

1

User databases represented in the findings.

Filter by group

Findings identified

1

Items requiring review across user databases.

Filter by priority

Showing all 1 application findings.

AttentionGroupFindingDatabaseDetailsRiskRecommendation
High · P55 Index design Review an index for a frequently joined ERP relationship. ERP_Core Referential operations may scan more data than necessary. Validate the workload and proposed key order in a representative environment before change.

System Database Checks

Best-practice summary: Protect master, model, msdb, and TempDB according to their distinct recovery and operational roles. Test restoration and rebuild procedures before an incident.

Availability, access, recovery configuration, capacity, and backup evidence for SQL Server system databases.

System databases

4 of 4

Expected system databases discovered.

Needs attention

0

System database records with an exception.

Full backups recorded

3 of 3

Backup evidence for master, model, and msdb.

DatabaseStateAccessibleRecoveryCompatibilitySizeLast full backupAssessmentRecommended action
masterONLINEYesSIMPLE150512 MB2026-08-13 01:00No exception identifiedRetain the evidence and continue scheduled review of availability, access, recovery configuration, and backups.
modelONLINEYesFULL150128 MB2026-08-13 01:00No exception identifiedRetain the evidence and continue scheduled review of availability, access, recovery configuration, and backups.
msdbONLINEYesSIMPLE1501,024 MB2026-08-13 01:00No exception identifiedRetain the evidence and continue scheduled review of availability, access, recovery configuration, and backups.
tempdbONLINEYesSIMPLE1508,192 MBNot applicableNo exception identifiedRetain the evidence and continue scheduled review of availability, access, recovery configuration, and backups.

Database High Availability

Best-practice summary: Match each database's availability mechanism to what that database is for, and confirm the recovery model supports it — log shipping, mirroring and availability groups all require a database in full recovery.

Database mirroring, Always On availability groups, log shipping and replication, read from the instance catalogue. This reports what is configured; whether a database needs to be highly available is a decision about that database's role, not one this assessment makes.

DatabaseStateRecovery modelProtected by
masterONLINESIMPLENone configured
modelONLINEFULLNone configured
msdbONLINESIMPLENone configured
tempdbONLINESIMPLENone configured
ERP_CoreONLINEFULLAvailability group (primary - SYNCHRONIZED)
ERP_ReportingONLINEFULLLog shipping (Secondary)
Replication (subscriber)

Control Drift

Best-practice summary: Agree a baseline, then review what moved away from it rather than re-reading every control each time. A change nobody expected is worth more attention than a failure everybody already knows about.

What changed against the baseline (run 41, 12 May 2026). Controls holding the same result are not listed, so this table is the difference and not a second copy of the compliance results above.

TopicControlPreviouslyNowChangeRecommended action
Secure configuration'xp_cmdshell' disabledNeeds attentionPassResolvedRetain the approved configuration.
Access governanceDatabase Engine uses a managed domain identityNot assessedPassNow passingRetain the approved identity and periodic access review.
Network securitySQL Server Browser service disabled unless requiredApproved exceptionReview requiredRegressedConfirm the documented dependency and owner; disable the service if it is not required.

Evidence Summary

Security

Evidence note: Overall status is shown in the executive summary. This section contains supporting technical evidence.

Best-practice summary: Keep the number of enabled logins small and the number holding system administrator smaller. Prefer Windows or domain authentication, disable the sa login, and review shared and service accounts against who actually needs them.

Who can reach this SQL Server and with what rights, as retained at the time of assessment. This is not penetration testing, vulnerability scanning or attack detection, and it does not confirm that an account in use is the account intended.

3logins retained
2enabled
1enabled sysadmin
0enabled SQL logins
2enabled Windows logins
disabledsa login
LoginTypeStateSystem administrator
DEMO\DBA-OperationsWindows GroupEnabledYes
saSql LoginDisabledYes
DEMO\svc_sql_erpWindows LoginEnabledNo

Sensitive Data Classification

Personal, financial, health and cardholder data identified from SQL Server's own sensitivity labels and from column naming. Naming is an indicator, not proof: a column may be named for data it does not hold, and data may be held in a column named for nothing in particular. No column value is read.

DatabaseLabelled columnsInferred columnsTransparent Data EncryptionEncrypted columnsProtection
ERP_Core3
Confidential, General
0
None inferred
Not enabled1Protected
ERP_Reporting0
No regulated category
1
Cardholder data
Not enabled0Unprotected

Not assessed: ERP_Archive. These databases could not be read, so they are absent from the table above rather than clear.

Classified and Inferred Columns

Column names are shown because this subscription includes classification detail. No column value is ever read or reported.

DatabaseTableColumnInformation typeSensitivity labelColumn encrypted
ERP_Coredbo.EmployeeNationalInsuranceNoNational IDConfidential - GDPRNo
ERP_Coredbo.EmployeeDateOfBirthDate Of BirthConfidential - GDPRNo
ERP_Coresales.CustomerEmailAddressContact InfoGeneral - InternalYes
ERP_Reportingdbo.PaymentSummaryCardNumberLast4Cardholder dataNo labelNo

Compliance Overview

Best-practice summary: Treat compliance as evidence of control operation, ownership, exceptions, and remediation—not a one-time score. Expire exceptions and retain approvals and validation records.

Evidence-led control overview for prioritisation and governance. This section does not constitute certification, formal attestation, or confirmation that all applicable organisational, contractual, or regulatory controls were tested.

Access governance

SQL Server administrative access controls. 1 control(s): 0 needing attention, 0 approved exception(s), 0 requiring review, 0 not assessed, 0 not applicable.

Network security

SQL Server network protocol controls. 1 control(s): 0 needing attention, 0 approved exception(s), 1 requiring review, 0 not assessed, 0 not applicable.

Secure configuration

SQL Server attack-surface configuration controls. 1 control(s): 0 needing attention, 0 approved exception(s), 0 requiring review, 0 not assessed, 0 not applicable.

Patch management

SQL Server build and update governance. 1 control(s): 0 needing attention, 0 approved exception(s), 0 requiring review, 1 not assessed, 0 not applicable.

Data governance

SQL sensitivity-classification metadata coverage. 1 control(s): 1 needing attention, 0 approved exception(s), 0 requiring review, 0 not assessed, 0 not applicable.

Compliance Control Results

TopicControlWhy this mattersExpected stateObserved stateResultRecommended action
Data governance Sensitive-data classification metadata reviewed Classification metadata supports accountable data handling. Documented review ERP_Core 72% classified Needs attention Complete the classification review with the application and data owners.
Network security SQL Server Browser service disabled unless required The service advertises instance information. Disabled unless approved Running for named-instance discovery Review required Confirm the documented dependency and owner; disable the service if it is not required.
Access governance Database Engine uses a managed domain identity Managed identities support central lifecycle control. Approved managed identity DEMO\svc_sql_erp Pass Retain the approved identity and periodic access review.
Secure configuration 'xp_cmdshell' disabled Operating-system command execution increases compromise impact. Disabled Disabled Pass Retain the approved configuration.
Patch management SQL Server patch level Build currency requires comparison with a maintained, customer-approved SQL Server patch baseline. The installed SQL Server build is supported by Microsoft and meets the organisation's approved patch baseline. Installed build: 15.0.4430.1; update level: CU Not assessed Configure or confirm the organisation's approved SQL Server patch baseline before assessing this control; the recorded build alone is not evidence of failure or compliance.

Weighted Control Assurance

Scope and limits: This position describes the technical controls Guardian One was able to observe on this SQL Server. It is not an audit, a certification, or an assessment against any external framework, and controls that could not be assessed are excluded from the score rather than treated as satisfied. The domain weights below are Guardian One's own and are shown so they can be disagreed with. This figure is not comparable with any other vendor's score.

Overall position: 66.7% — 75% of 4 control(s) produced an answer. 1 control(s) could not be assessed and are excluded from the score rather than counted as satisfied.

DomainWeightPositionPassedNeeds attentionAccepted exceptionNot assessed
Access governance30100%
100% of its controls were assessed
1000
Data governance250%
100% of its controls were assessed
0100
Secure configuration20100%
100% of its controls were assessed
1000
Patch management15Not scored
No control in this domain produced an answer
0000
Network security10Not scored
No control in this domain produced an answer
0001

Financial Reporting Control Evidence

Scope and limits: This mapping is evidence supporting review of IT controls. It is not an audit, not a certification, and not a statement that any control is satisfied. It does not test operating effectiveness over a period. The scope of financial reporting is determined by the customer, not by Guardian One, and every concern below also requires evidence the customer holds outside this assessment.

Control concernWhat this assessment showsCustomer evidence still required
Logical access and segregation1 control(s): 1 pass — 100% produced an answerAuthorised user and role matrix, joiner-mover-leaver approvals, periodic access-review sign-off and business-role segregation.
Change managementNo control in this assessment speaks to this concernApproved change ticket, separation of requester and approver, testing, release evidence and a complete audit trail beyond the bounded trace window.
Computer operations1 control(s): 1 needs attention — 100% produced an answerJob monitoring, incident records, restore-test results, approved recovery objectives, operational ownership and continuous alert evidence. Guardian One is a point-in-time assessment and does not monitor continuously.
Configuration management2 control(s): 1 pass, 1 not assessed — 50% produced an answerApproved baseline, change authority, compensating controls and periodic management review.
Evidence integrity and reviewNo control in this assessment speaks to this concernRepository access governance, retention policy, reviewer sign-off and auditor acceptance of the evidence source.

The same control may support more than one concern. That is normal in control-to-evidence mapping and does not multiply the assurance it provides.

Activity Overview

Best-practice summary: Activity evidence is a bounded sample. Correlate waits, blocking, grants, I/O, TempDB, and Query Store across representative periods before diagnosing a root cause.

Current requests and memory grants are a bounded point-in-time view. Current-request query text and user, host, and application identities are deliberately excluded.

Leading cumulative wait

PAGEIOLATCH_SH

Largest selected non-idle wait since the wait statistics were last reset.

Selected wait time

0.0 h

Total across the ten displayed wait types; waits can overlap across concurrent tasks.

Currently blocked requests

0

Requests blocked at the point of collection.

Quantum advisories

AreaObserved evidenceAdvisory
Current workload0 user request(s); 0 blocked at collection time.No blocking was sampled. Reassess during a representative busy period before concluding that blocking is absent.
Query memory0 active grant(s); 0 waiting without a grant.No grant wait was sampled. Use repeated assessments and Query Store evidence to validate workload behaviour.
Database file I/OWorst busy-file average: 9.4 ms read; 3.8 ms write.Correlate latency at or above 20 ms with waits, workload and storage telemetry; cumulative averages do not identify a single incident.
TempDB37.5% allocated; version store 6.2% of data-file capacity.Review allocation across several assessments, active versioning work, spills and autogrowth before resizing.
Historical query evidence1 database status row(s); 1 review candidate(s).Validate ranked candidates in their application context; do not force plans or change queries from aggregate evidence alone.

Current requests

Session / requestDatabaseState / commandWait / blockerElapsed / CPULogical reads / I/O
No user requests were active at the point of collection.

Query memory grants

Session / requestDatabaseRequestedGrantedUsedPeak usedWait
No query memory grants were active at the point of collection.

Database file I/O

Average latency is cumulative since SQL Server started or the file counters were reset. Physical paths are retained as repository evidence but omitted from this report.

ERP_CoreERP_CoreROWS185,0009.40 ms47,0003.80 ms240.0 GB

TempDB allocation

This is a point-in-time allocation view and does not establish a growth trend.

MeasureObservedInterpretation
Data-file capacity8,192.0 MBTotal configured TempDB data-file size at collection time.
Allocated37.5%5,120.0 MB remained unallocated.
Version store512.0 MBRow versions retained at collection time.
Internal / user objects1,024.0 / 256.0 MBWorkspace and user-object allocations.
Data files8Count only; file symmetry should be reviewed with the detailed file evidence.

Leading non-idle waits

Wait statistics are cumulative SQL Server evidence since the instance started or the counters were reset. Correlate them with current workload and query evidence.

Wait typeAreaWait timeShareTasksAverageSignalInterpretation and next review
PAGEIOLATCH_SHData file I/O82.0 sec100.0%180455.6 ms5.1%Check storage latency, memory pressure, large scans, and indexes before attributing the wait to storage alone.

Query Store coverage

DatabaseStateCapture modeStorageEvidence windowLimitations
ERP_CoreREAD_WRITEAUTO384.0 MB of 2,048 MB2026-08-06 00:00 to 2026-08-13 17:00Bounded retained evidence; Guardian One does not alter Query Store configuration.

Query Store review candidates

Candidates are ranked by total duration within the configured bounded window. The captured query excerpt keeps the report useful after the Query Store window changes.

DatabaseQuery IDPlan IDCaptured queryExecutionsAverage durationAverage CPUAverage readsSafe next review
ERP_Core18427SELECT OrderId, CustomerId FROM dbo.Orders WHERE CustomerId = @CustomerId9201,180.5 ms612.4 ms18,400Review the identified query and plan in its application context. Validate plan history, parameters, concurrency, and business criticality before tuning or forcing a plan.