Skip to content

Guard Health Heatmap

3. Guard Health Heatmap

The Guard Health Heatmap provides a longitudinal, day-by-day view of the health status of every active guard across the past 30 days. It enables operators to spot recurring degradation patterns or identify guards that are chronically elevated.

3.1 Heatmap Grid

The grid is organized as:

  • Rows — Each active Guard kernel (sorted alphabetically)
  • Columns — Time intervals (dates/hours over the 30-day window)
  • Cells — Color-coded by the worst drift severity observed in that time period

Cell Color Legend

Color State Meaning
Green Healthy No significant drift in this period
Amber Elevated Drift Drift detected, within acceptable thresholds
Red Critical Breach Drift exceeded guard thresholds
Gray Inactive No traffic recorded for this guard in this period

3.2 Cell Tooltip

Hovering over any cell in the grid reveals a tooltip with: - Guard name - Time period - Severity classification for that period - Total event count in that period

A search bar above the heatmap filters the visible guard rows by name, allowing operators to focus on specific guards without losing the time dimension context.

3.4 Interpreting the Heatmap

  • A guard with consistently amber or red cells across the 30-day window may need its probe set retuned or its policy thresholds adjusted
  • A guard that transitions from green to red on a specific date may indicate a model update, a new agent deployment, or a policy change that needs investigation
  • Inactive guards (all gray) are typically archived or not yet assigned to active agents