Academy
Technical · Course T7

Lesson 4 of 4

Reporting, alerts, and evidence

7 min read
In this lesson you'll learn to
  • Pick the right report type and schedule it to the right recipients
  • Use alerts as the fleet's early-warning system
  • Answer a customer's 'who did what' question from the audit log

Fleet activity that nobody sees isn't managed — it's just busy. This lesson covers the three surfaces that turn operations into something a customer can read: reports for the scheduled view, alerts for the urgent view, and audit logs for the retrospective one.

Reports

WeGuard ships eleven report types, each answering a specific fleet question:

ReportAnswers
Device OSWhich OS versions are we running?
Device EnrollmentWhat's enrolled, and when did it happen?
Device TypeWhich manufacturers and models?
Device StatusWho's online, offline, pending?
WeGuard Version DistributionWhich agent versions are deployed?
Battery PercentageBattery health across the fleet
WiFi & Network InfoConnectivity picture
Custom Application DistributionIs our enterprise app installed everywhere?
Store Application DistributionSame, for public store apps
Device ComplianceWho's failing policy?
Boot Logo StatusAndroid boot-logo customization state

The two application reports ask you to pick a specific app during creation — they're per-app, not fleet-wide summaries.

Formats: PDF (shareable, with optional charts), CSV (analysis), Excel. Reports run immediately or on a schedule, and the Schedules tab is where the operational value lives: daily (time picker), weekly (day-of-week plus time), or monthly (day-of-month and month selectors plus time), with email recipients attached. Report runs carry a status — Scheduled, In Progress, Completed, Failed, Canceled — and both tabs filter by type and status.

The partner move here is simple and underused: at handover, set up the customer's recurring reports for them. A weekly compliance report landing in their security lead's inbox every Monday is a standing reminder of who runs their fleet.

Alerts

Where reports are scheduled, alerts are reactive — the fleet telling you something changed. The compliance dimensions from Policy Mastery surface here as typed events: battery and data-usage thresholds (WARNING/CRITICAL), SIM_REMOVED and SIM_CHANGED (the theft signals), ROOTED_ENROLL, UNINSTALL_WEGUARD, kiosk lock/unlock, device reboot and shutdown, memory and storage pressure, and geofence IN_FENCE / OUT_FENCE crossings.

Alert rules are configured per policy (Android and Windows) on the policy's Alerts tab. Treat the alert list as a work queue, not a notification stream: the critical tier — rooted enrollment, SIM removal, agent uninstall attempts — is where a managed-service partner earns trust by responding before the customer notices.

Audit and usage

The audit log records every remote action with its actor and timestamp, filterable and exportable to CSV. This is the answer to "who wiped that device?" and, more importantly, the artifact that makes remote administration acceptable to a customer's security review — the honest framing is "every action we can take on your fleet is logged, and you can export the log yourself."

Two adjacent surfaces complete the operational picture: Data Usage tracks mobile versus Wi-Fi consumption per device against Critical/Warning/Low thresholds (the answer to bill shock on cellular fleets), and Screen Time on Windows reports login/logout history, boot times, and usage per device.

Put together, day-two operations is a loop: alerts tell you something happened, commands let you act on it, reports prove the fleet's state over time, and the audit log records that it was you who acted — the difference between managing a fleet and merely owning one.

Knowledge check
1. A customer wants a compliance summary emailed to their security lead every Monday. What do you configure?
2. Which report format supports charts?
3. A customer asks who wiped a device last Tuesday. Where do you look?