Overview
The Dashboard State Lifecycle governs the enablement of functionality and dashboards as a customer tenant transitions from initial provisioning to full operational readiness. Each state represents a controlled maturity level based on provisioning completeness, data ingestion progress, and data validation thresholds. This staged approach ensures a guided onboarding experience that progressively unlocks features as the tenant becomes ready for Exposure Management (EM) and later Cyber Risk Quantification (CRQ).
Customer Journey State Model
State | Definition | UI / Left Nav Access | Dashboards Enabled | Notes |
|---|---|---|---|---|
Provisioned | Tenant fully provisioned with required configuration parameters (e.g., Inference enablement, AI model version, sensor availability). Customer users can now be added. | Enabled: Data Sources only. Allows adding connectors, downloading sensor installers, and viewing connector/sensor installation status. | None | Starting point after tenant provisioning. |
Data Ingestion in Progress | Partial data flow — some connectors configured but not all required ones have completed a full ingestion cycle. | Enabled: Data Sources (carried forward), limited Inventory view (no exposure/risk insights), Activity Center, and Company Settings (Data Sources, Inventory, Data Analysis, Users & Access, Company Profile). Disabled: Group Management in Inventory Settings. | Data Quality, Visibility & Confidence (app widgets appear only when integrations are active). | “General Settings” available only to Balbix Super Admins and CS. |
Ready for EM | Data is validated and sufficient to begin Exposure Management. CRQ not yet available. | Enabled: All Left Nav modules per license entitlements. App widgets visible only if AppSec module licensed and integrations configured. | Exposure Summary, Infra Exposure, App Exposure (conditional), Inventory, Analytics (conditional). | BU-related widgets remain empty until BU groups are configured; they show inline guidance and link to BU Group Setup workflow. |
Ready for CRQ | Tenant has complete data coverage (exposure, vulnerabilities, controls, business context) to enable CRQ dashboards. | All modules enabled. | All dashboards enabled, including CRQ and risk quantification. | CRQ readiness validation guidance to be provided separately. |
1. Provisioned
Definition: The tenant has been successfully created and configured with the correct foundational settings — including inference enablement, AI model version selection, and optional sensor availability. At this stage, only administrative setup actions are allowed.
Functional Access:
Customer users may be provisioned using Add Dashboard User.
Data Sources becomes visible, allowing users to:
Add and configure connectors.
Download sensor installers.
View connector health and sensor installation progress.
Enabled Components:
Left Navigation: Data Sources only.
Dashboards: None.
Purpose: This state validates provisioning completeness while isolating data operations from exposure analysis.
2. Data Ingestion in Progress
Definition: The tenant has started data ingestion. One or more connectors are configured, but not all mandatory integrations have completed a full ingestion cycle. The platform begins surfacing data health and coverage metrics, but exposure-level analysis remains disabled.
Functional Access:
Incremental enablement of navigation modules to manage ingestion and monitor progress.
Left Navigation:
Enabled:
Data Sources (carried forward)
Inventory (limited, no exposure/risk insights)
Activity Center
Company Settings → Data Sources, Inventory, Data Analysis, Users & Access, Company Profile
Disabled:
Group Management in Inventory Settings
Dashboards Enabled:
Data Quality
Visibility & Confidence (App-specific widgets appear only when corresponding connectors are configured and running.)
Internal Access:
General Settings visible only to Balbix Super Admins and Customer Success (CS).
Purpose: Provide visibility into data ingestion and initial telemetry confidence before exposing analytical dashboards.
3. Ready for EM (Exposure Management)
Definition: At this stage, the tenant has sufficient validated data to enable Exposure Management workflows and dashboards. Vulnerability, control, and asset telemetry are consistent enough to generate actionable exposure insights. CRQ remains disabled until business context coverage is complete.
Functional Access:
All navigation modules are unlocked per entitlement.
Application widgets are dynamically displayed based on license and connector state.
Dashboards Enabled:
Exposure Summary – Core exposure overview.
Infra Exposure – Infrastructure risk breakdown.
App Exposure – Enabled only when AppSec module licensed and integrations configured.
Inventory – Complete asset view with exposure overlays.
Analytics – Enabled with app widgets when licensed.
Notes:
BU (Business Unit) Widgets: Display placeholder messages if no BU groups exist, with a direct link to the BU Group Setup workflow.
Purpose: Transition from ingestion verification to active exposure analysis.
4. Ready for CRQ
Definition: The tenant now has comprehensive coverage across exposure, vulnerability, control, and business context dimensions. This enables Cyber Risk Quantification (CRQ) dashboards and reports.
Functional Access:
All left navigation modules and dashboards enabled.
CRQ and financial risk models activated.
Dashboards Enabled:
All dashboards, including CRQ, Financial Impact, and Loss Distribution views.
Guidance: Detailed CRQ readiness requirements (coverage thresholds, telemetry validation, and business mapping) will be released separately.
Purpose: Deliver full operational maturity with quantifiable, business-aligned risk insights.
State Transition Model
From State | To State | Trigger Condition |
|---|---|---|
Provisioned | Data Ingestion in Progress | At least one connector configured and initial ingestion initiated. |
Data Ingestion in Progress | Ready for EM | All required connectors have completed one full ingestion cycle and passed validation checks. |
Ready for EM | Ready for CRQ | Business context, vulnerability, and control telemetry coverage thresholds achieved. |