> ## Documentation Index
> Fetch the complete documentation index at: https://iru-kbee-63-enhance-rts-documentation.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Prism Data Analytics

> Use Prism in Iru to query and visualize device fleet data. Build custom reports, filter by attributes, and export results for analysis.

Prism is Iru's device data collection and analytics platform. It gathers inventory and configuration data from your fleet and feeds [Iru AI](/en/iru/iru-ai/using-iru-ai), so you can ask questions about your devices and get recommendations based on that data.

## About Prism

Prism stores the device data Iru AI uses to answer questions and surface recommendations. Collection and organization happen in Prism. Iru AI then makes that data available in conversation and through proactive insights.

## Prism Data Categories

Prism organizes device data into these categories:

<CardGroup cols={2}>
  <Card title="Devices" icon="desktop">
    General information about your enrolled devices.
  </Card>

  <Card title="Activation Lock" icon="lock">
    Device and user Activation Lock status, bypass code escrow, and related settings for iOS, iPadOS, visionOS, and macOS devices.
  </Card>

  <Card title="Application Firewall" icon="shield">
    Built-in macOS application firewall status, including block all incoming, stealth mode, logging, allow signed applications, and firewall unloading. Firewall exceptions are not included here; they will ship later in their own category.
  </Card>

  <Card title="Apps" icon="list">
    Application inventory for iOS, iPadOS, tvOS, visionOS, and macOS devices, including source, signature, Team ID, and install or download state. On Mac, the Iru Agent also records each app's last-opened date and timestamp.
  </Card>

  <Card title="Cellular" icon="signal">
    Cellular details for iOS and iPadOS devices, including dual-SIM Slot 1 and Slot 2 data such as carrier, roaming, personal hotspot, IMEI, ICCID, and EID.
  </Card>

  <Card title="Certificates" icon="certificate">
    Installed certificates on macOS, iOS, iPadOS, and tvOS devices, reported with common name and whether each is an identity certificate.
  </Card>

  <Card title="Desktop & Screensaver" icon="image">
    Screensaver path and interval, clock display, and hot corners per user account on macOS devices.
  </Card>

  <Card title="FileVault" icon="lock">
    FileVault status on macOS devices, including recovery key type, escrow status, regeneration needed, and next scheduled rotation.
  </Card>

  <Card title="Gatekeeper & XProtect" icon="shield">
    Gatekeeper status and mode on macOS, plus Gatekeeper, Opaque, XProtect, and MRT versions. Gatekeeper exceptions will arrive later as a separate category.
  </Card>

  <Card title="Installed Profiles" icon="folder">
    All installed profiles on Apple devices, including profiles not installed by Iru Endpoint, with managed, removable, signed, encrypted, and removal passcode attributes.
  </Card>

  <Card title="Kernel Extensions" icon="puzzle-piece">
    Installed kernel extensions and their status on macOS devices.
  </Card>

  <Card title="Launch Agents & Daemons" icon="cog">
    Launch agents and daemons on macOS devices, including load and disabled state, domain, program arguments, and the local user for user agents.
  </Card>

  <Card title="Local Users" icon="user">
    Local users on macOS devices, including Administrator or Standard type, Secure Token, FileVault User, Volume Owner, Mobile Account, and Home Folder Secured.
  </Card>

  <Card title="Startup Settings" icon="power-off">
    Core macOS security settings such as System Integrity Protection (SIP), Authenticated Root Volume, Bootstrap Token, and Secure Boot.
  </Card>

  <Card title="System Extensions" icon="puzzle-piece">
    Installed system extensions on macOS devices, including state, MDM Managed, Team ID, and version details.
  </Card>

  <Card title="Transparency Database" icon="database">
    Transparency, Consent, and Control (TCC) entries on macOS devices, including service, application, Allowed or Denied status, and status reason (User Set, System Set, or MDM Policy).
  </Card>
</CardGroup>

## Using Prism

Open **Devices**, then select the **Prism** tab.

<Frame>
  <img src="https://mintcdn.com/iru-kbee-63-enhance-rts-documentation/dKtbhylV9s4ij-nR/assets/media/images/iru-prism-view.png?fit=max&auto=format&n=dKtbhylV9s4ij-nR&q=85&s=7a8149c566615ab464c3d58800140403" alt="Prism Devices category view with sidebar categories, filters, columns, and CSV export controls" width="2860" height="1848" data-path="assets/media/images/iru-prism-view.png" />
</Frame>

### Global Filters

Use the **Device** and **Blueprint** filters to narrow Prism results across all categories. Categories that do not apply to the filtered platform may be grayed out. For example, FileVault grays out when you filter to iOS devices.

#### Device

Filter by platform. Options include:

* **Apple**, with nested choices for **Mac**, **iPhone**, **iPad**, **Apple TV**, and **Vision**
* **Windows**
* **Android**

Select one or more platforms, then use **Reset** to clear the Device filter.

#### Blueprint

Filter by Blueprint. Search Blueprints, choose **Select all**, or select individual Blueprints. Use **Clear** to remove Blueprint selections.

### Expand and Collapse Table View

Click **Expand table view** to hide the Prism category sidebar and give the table more room. Click **Collapse table view** to show the sidebar again.

<Frame>
  <img src="https://mintcdn.com/iru-kbee-63-enhance-rts-documentation/dKtbhylV9s4ij-nR/assets/media/images/iru-prism-expand-table.png?fit=max&auto=format&n=dKtbhylV9s4ij-nR&q=85&s=1ef4bec441fe50ce839f88054eed7270" alt="Prism Expand table view control above the Devices table" width="684" height="392" data-path="assets/media/images/iru-prism-expand-table.png" />
</Frame>

### Manage Tags

From the Devices page (including Prism), open the ellipsis menu and select **Manage tags** to search for, add, edit, or delete tags for your tenant. For full steps, see [Tags for Devices](/en/endpoint/devices/device-record-management/tags-for-devices#managing-tags).

### View Settings

Use **View settings** to choose which attributes appear in the table for the current category.

<Steps>
  <Step title="Click View settings">
    Click **View settings**.

    <Frame>
      <img src="https://mintcdn.com/iru-kbee-63-enhance-rts-documentation/dKtbhylV9s4ij-nR/assets/media/images/iru-prism-view-settings.png?fit=max&auto=format&n=dKtbhylV9s4ij-nR&q=85&s=d1ce3930fdb2fe3160d8bdcabbbcb99c" alt="Prism View settings control above the Devices table" width="676" height="476" data-path="assets/media/images/iru-prism-view-settings.png" />
    </Frame>
  </Step>

  <Step title="Search for a field">
    Search for a specific attribute if you have one in mind.
  </Step>

  <Step title="Hide all">
    Click **Hide all** to turn off all optional columns.
  </Step>

  <Step title="Uncheck columns">
    Uncheck individual columns to hide them from the table.
  </Step>

  <Step title="Reorder columns">
    Click and drag the **drag-and-drop** icon to reorder columns.
  </Step>

  <Step title="Show all">
    Click **Show all** to turn on all columns.
  </Step>

  <Step title="Check hidden items">
    Check items in the hidden list to show them in the table again.
  </Step>

  <Step title="Close View settings">
    Click **X** to close **View settings**.

    <Frame>
      <img src="https://mintcdn.com/iru-kbee-63-enhance-rts-documentation/dKtbhylV9s4ij-nR/assets/media/images/iru-prism-view-settings-options.png?fit=max&auto=format&n=dKtbhylV9s4ij-nR&q=85&s=24228bb1eba184f919ad3014bb12d2f2" alt="Prism View settings panel for searching, showing, and hiding table columns" width="814" height="1484" data-path="assets/media/images/iru-prism-view-settings-options.png" />
    </Frame>
  </Step>
</Steps>

### CSV Export

Export the contents of the category you are viewing.

<Steps>
  <Step title="Click Export CSV">
    Click **Export CSV**.
  </Step>

  <Step title="Choose what to include">
    Select **Current View** or **All Attributes**:

    * **Current View**: Includes only the data currently visible in the table, plus any applied filters.
    * **All Attributes**: Includes all data for this category, even columns that are not visible in the table.
  </Step>

  <Step title="Start export">
    Click **Start export**.

    <Frame>
      <img src="https://mintcdn.com/iru-kbee-63-enhance-rts-documentation/dKtbhylV9s4ij-nR/assets/media/images/iru-prim-export-csv.png?fit=max&auto=format&n=dKtbhylV9s4ij-nR&q=85&s=fec116e6eaf6b7cd65517c9262bee332" alt="Prism Export CSV dialog with Current View and All Attributes options" width="1172" height="606" data-path="assets/media/images/iru-prim-export-csv.png" />
    </Frame>
  </Step>
</Steps>

### Add Filters

Use **+ Filter** to narrow the table by any attribute in the category. For example, in FileVault you can show devices where the recovery key is not escrowed.

<Steps>
  <Step title="Click + Filter">
    Click **+ Filter**.
  </Step>

  <Step title="Search">
    Search for the attribute you want to filter on.
  </Step>

  <Step title="Select filter">
    Select the filter from the list.
  </Step>

  <Step title="Select status">
    Choose the status or value for the filter.
  </Step>

  <Step title="Click Apply">
    Click **Apply**.

    <Frame>
      <img src="https://mintcdn.com/iru-kbee-63-enhance-rts-documentation/dKtbhylV9s4ij-nR/assets/media/images/iru-prism-add-filter.png?fit=max&auto=format&n=dKtbhylV9s4ij-nR&q=85&s=8a49ff5c339afeefa72716080e8a08f1" alt="Prism Add Filter workflow showing search, Recovery Key Escrowed filter, status options, and Apply" width="1332" height="768" data-path="assets/media/images/iru-prism-add-filter.png" />
    </Frame>
  </Step>
</Steps>

### Remove a Filter

Click the **X** on an applied filter to remove it.

<Frame>
  <img src="https://mintcdn.com/iru-kbee-63-enhance-rts-documentation/dKtbhylV9s4ij-nR/assets/media/images/iru-prism-remove-filter.png?fit=max&auto=format&n=dKtbhylV9s4ij-nR&q=85&s=d654db2a35f4a2dc023a05f522dabbe6" alt="Prism applied filter chip with X control to remove the Recovery Key Escrowed filter" width="586" height="288" data-path="assets/media/images/iru-prism-remove-filter.png" />
</Frame>

### Attribute Values

Prism attributes appear in one of these states:

* **Value**: A returned value such as a boolean (true/false, yes/no, on/off), string, or number
* **Empty**: The attribute applies, but no value is present. For example, a launch daemon with no program arguments
* **Null**: The attribute does not apply to the device platform. For example, application signature on iOS, because Apple does not expose application signing information over the MDM protocol

### Cross-Category Shared Attributes

These attributes appear in every Prism category:

| Attribute                | Description                                                                                                                                               |
| ------------------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Device ID**            | The unique identifier for the enrolled device                                                                                                             |
| **Device Name**          | The name of the enrolled device. Links to the device record                                                                                               |
| **Device Family**        | The device platform family, such as Mac, iPhone, iPad, or Windows                                                                                         |
| **Device User ID**       | The unique identifier for the assigned device user                                                                                                        |
| **Device User**          | The assigned user of the device record. Links to the user record                                                                                          |
| **Device User Email**    | The email address of the assigned device user                                                                                                             |
| **Blueprint ID**         | The unique identifier for the assigned Blueprint                                                                                                          |
| **Blueprint Name**       | The assigned Blueprint for the device. Links to the Blueprint record                                                                                      |
| **Tags**                 | Tags applied to the device                                                                                                                                |
| **Asset Tag**            | The asset tag value on the device record, if set                                                                                                          |
| **Device Serial Number** | The device serial number                                                                                                                                  |
| **First Seen**           | The first time Prism recorded this row of data                                                                                                            |
| **Last Updated**         | The last time this row was updated in Prism                                                                                                               |
| **Last Collected**       | The last time the data was collected                                                                                                                      |
| **Last Changed**         | The last time the data was collected and the values differed from the previous collection. For example, FileVault status was collected and changed to On. |

## Collection Frequency

This table shows how often Prism collects each type of data, and which method it uses.

| <Icon icon="folder" size={14} /> **Data** | <Icon icon="server" size={14} /> **Source** | <Icon icon="clock" size={14} /> **Collection Frequency**                                            | <Icon icon="mobile-screen" size={14} /> **Compatibility**                                                                     |
| ----------------------------------------- | ------------------------------------------- | --------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------- |
| **Devices**                               | Agent/MDM                                   | 24 Hours (Apple platforms)<br />Daily (Windows)<br />When something changes on the device (Android) | <Icon icon="apple" size={14} /> Apple, <Icon icon="microsoft" size={14} /> Windows, <Icon icon="android" size={14} /> Android |
| **Activation Lock**                       | MDM                                         | 24 Hours                                                                                            | <Icon icon="apple" size={14} /> iOS, iPadOS, visionOS, macOS                                                                  |
| **Application Firewall**                  | Agent/MDM                                   | 15 Minutes / 24 Hours                                                                               | <Icon icon="apple" size={14} /> macOS                                                                                         |
| **Apps**                                  | Agent/MDM                                   | 24 Hours (iOS, iPadOS, tvOS, visionOS)<br />Near-instant (macOS)                                    | <Icon icon="apple" size={14} /> iOS, iPadOS, tvOS, visionOS, macOS                                                            |
| **App Last Opened**                       | Agent                                       | Daily (at agent check-in)                                                                           | <Icon icon="apple" size={14} /> macOS                                                                                         |
| **Cellular**                              | MDM                                         | 24 Hours                                                                                            | <Icon icon="apple" size={14} /> iOS, iPadOS                                                                                   |
| **Certificates**                          | MDM                                         | 24 Hours                                                                                            | <Icon icon="apple" size={14} /> macOS, iOS, iPadOS, tvOS                                                                      |
| **Desktop & Screensaver**                 | Agent                                       | 15 Minutes                                                                                          | <Icon icon="apple" size={14} /> macOS                                                                                         |
| **FileVault**                             | Agent/MDM                                   | 15 Minutes                                                                                          | <Icon icon="apple" size={14} /> macOS                                                                                         |
| **Gatekeeper & XProtect**                 | Agent                                       | 15 Minutes                                                                                          | <Icon icon="apple" size={14} /> macOS                                                                                         |
| **Installed Profiles**                    | MDM                                         | 24 Hours                                                                                            | <Icon icon="apple" size={14} /> iOS, iPadOS, tvOS, visionOS, macOS                                                            |
| **Kernel Extensions**                     | Agent                                       | 15 Minutes                                                                                          | <Icon icon="apple" size={14} /> macOS                                                                                         |
| **Launch Agents & Daemons**               | Agent                                       | 15 Minutes                                                                                          | <Icon icon="apple" size={14} /> macOS                                                                                         |
| **Local Users**                           | Agent                                       | Hourly                                                                                              | <Icon icon="apple" size={14} /> macOS                                                                                         |
| **Startup Settings**                      | MDM                                         | 24 Hours                                                                                            | <Icon icon="apple" size={14} /> macOS                                                                                         |
| **System Extensions**                     | Agent                                       | 15 Minutes                                                                                          | <Icon icon="apple" size={14} /> macOS                                                                                         |
| **Transparency Database**                 | Agent                                       | 15 Minutes                                                                                          | <Icon icon="apple" size={14} /> macOS                                                                                         |
| **Security Patch Level**                  | MDM                                         | Status report sent upon attribute change                                                            | <Icon icon="android" size={14} /> Android                                                                                     |
| **API Level**                             | MDM                                         | Status report sent upon attribute change                                                            | <Icon icon="android" size={14} /> Android                                                                                     |

## Platform-Specific Data Collection

<Tabs>
  <Tab title="Apple" icon="apple" iconType="brands">
    <AccordionGroup>
      <Accordion title="Hardware information">
        * Device model and specifications
        * Serial number and UDID
        * Storage capacity and usage
        * Battery health and status
      </Accordion>

      <Accordion title="Software information">
        * Operating system version and build
        * Installed applications and versions
        * Mac app last-opened date/timestamp (daily from the agent; macOS updates as apps are used)
        * System extensions and kernel extensions
        * Launch agents and daemons
      </Accordion>

      <Accordion title="Security information">
        * FileVault encryption status
        * Gatekeeper and XProtect status
        * Activation Lock status
        * Installed security profiles
      </Accordion>

      <Accordion title="User information">
        * Local user accounts, including Secure Token, FileVault User, Volume Owner, Mobile Account, Home Folder Secured, and logged-in state
        * Desktop and screensaver settings per user account, including screensaver path/interval and hot corners
      </Accordion>
    </AccordionGroup>
  </Tab>

  <Tab title="Windows" icon="microsoft" iconType="brands">
    <AccordionGroup>
      <Accordion title="Hardware information">
        * Device model and manufacturer
        * Serial number and device identifiers
        * Storage capacity and usage
        * Processor architecture
        * Network information
      </Accordion>

      <Accordion title="Software information">
        * Operating system name, version, and edition
        * OS build and Update Build Revision (UBR)
        * Full software version
        * Agent installation status and version
      </Accordion>
    </AccordionGroup>
  </Tab>

  <Tab title="Android" icon="android" iconType="brands">
    <AccordionGroup>
      <Accordion title="Hardware information">
        * Device model and specifications
        * Storage capacity and usage
        * Network connectivity status
      </Accordion>

      <Accordion title="Software information">
        * Android version and API level
        * System updates and patches
        * Installed applications in the work profile
        * Application versions and sources
        * Work profile configuration
      </Accordion>

      <Accordion title="Security information">
        * Security patch level
        * Device compliance status
        * Work profile security settings
        * Certificate and encryption status
      </Accordion>
    </AccordionGroup>
  </Tab>
</Tabs>

## Data Collection Methods

<AccordionGroup>
  <Accordion title="Agent-based collection">
    The Iru Agent gathers data by:

    * **System APIs**: Reading system information and status directly
    * **File system monitoring**: Tracking changes to system files and configurations
    * **Process monitoring**: Watching running processes and services
    * **Event logging**: Collecting system events and security logs
  </Accordion>

  <Accordion title="MDM-based collection">
    MDM protocols gather data by:

    * **Device queries**: Requesting specific device information
    * **Status reports**: Receiving automatic status updates
    * **Command responses**: Collecting data returned from MDM commands
    * **Profile information**: Reading data from installed configuration profiles
  </Accordion>
</AccordionGroup>

## Privacy and Security

<AccordionGroup>
  <Accordion title="Data protection">
    Iru protects Prism data with:

    * **Encryption**: Data is encrypted in transit and at rest
    * **Access controls**: Access controls limit who can view device data
    * **Audit logging**: Data access is logged and auditable
    * **Data retention**: Retention policies you can configure
  </Accordion>

  <Accordion title="Compliance">
    Prism data collection aligns with:

    * **GDPR**: European data protection regulations
    * **CCPA**: California consumer privacy laws
    * **SOC 2**: Security and availability standards
    * **ISO 27001**: Information security management
  </Accordion>
</AccordionGroup>

## API Access

Prism was built API-first. Anything you can do in the web app is also available through the [Iru API](/en/endpoint/api/iru-api-overview).

With the Prism API, you can:

* Query any category with any subset of filters
* Request a CSV export of any category and retrieve the result set asynchronously

## Best Practices

<CardGroup cols={2}>
  <Card title="Review regularly" icon="eye">
    Check Prism often enough to catch security issues and compliance gaps before they linger.
  </Card>

  <Card title="Inform policy decisions" icon="chart-line">
    Use fleet data in Prism when you change device management policies.
  </Card>

  <Card title="Watch security signals" icon="shield">
    Treat FileVault, Gatekeeper, TCC, and related categories as early signals for hardening work.
  </Card>

  <Card title="Track compliance" icon="clipboard-check">
    Use Prism to confirm devices still meet your compliance requirements.
  </Card>
</CardGroup>

## Troubleshooting

<AccordionGroup>
  <Accordion title="Data not updating">
    **Possible causes:**

    * Device offline or not checking in
    * Agent not running
    * Network connectivity issues

    **Solutions:**

    * Confirm the device is online
    * Verify the agent is running
    * Test network connectivity
  </Accordion>

  <Accordion title="Missing data categories">
    **Possible causes:**

    * Platform limitations
    * Agent version mismatch
    * Permission issues

    **Solutions:**

    * Confirm the category is available for the device platform
    * Update the agent to the latest version
    * Verify required permissions
  </Accordion>

  <Accordion title="Inaccurate data">
    **Possible causes:**

    * Timing of the last collection cycle
    * System state changing during collection
    * Agent sync problems

    **Solutions:**

    * Wait for the next collection cycle
    * Force a device check-in
    * Restart the agent if needed
  </Accordion>
</AccordionGroup>
