CortexDocumentation
Portal · Coverage

Coverage

Confirm which devices, capture paths, and connected sources are current before interpreting Portal trends.

  • Capture pathsActive, inactive, or not configured
  • Connected sourcesCurrent, inactive, or needs authorization
  • Actionable gapsEach issue points to its recovery path
Check capture health
Coverage before conclusions

Coverage is the confidence check for every other Portal view. It separates a real change in AI use from a change in what Cortex can observe.

Read the Coverage cards

  • Capture pathsActive in the last 24 hours
  • Connected sourcesCurrent authorization
  • RemediationGaps with an available fix

Resolve a gap

What you seeWhere to go
Device never reportedDeployment and Defender sign-in
Device stopped reportingDefender health and troubleshooting
Capture path not configuredSupported AI tools and source setup
Browser missing, CLI presentBrowser routing and certificate setup
Connected source needs authorizationWorkplace connections

Work one row at a time. Restoring one device or source can clear several downstream gaps.

  • Confirm the expected number of devices is reporting.
  • Confirm the relevant capture paths were active for both periods.
  • Confirm app connections are current when the analysis depends on organization context.
  • Keep visibility and date range consistent.
A lower Portal total can mean less activity or less coverage. Coverage tells you which interpretation is supported.

Fix the underlying path

Was this helpful?