A saved view is a named dashboard filter set that can be reused without rebuilding the same query each time. It gives analysts a fast way to switch between recurring slices of risk, such as critical internet-facing assets or one team’s backlog, while keeping reporting consistent.
Expanded Definition
A saved view is more than a convenience feature. In security operations, it is a reusable, named representation of a query, filter, or dashboard state that helps analysts return to the same scoped dataset without reconstructing criteria each time. That makes it useful for recurring tasks such as reviewing high-severity findings, tracking a business unit’s open items, or monitoring internet-exposed assets. Because usage varies across platforms, definitions are still evolving and there is no single standard that governs saved views as a security control. NHI Management Group treats the term as an operational reporting construct, not as a policy decision or access control mechanism.
The distinction matters because a saved view can improve consistency without changing the underlying data or entitlements. It does not grant access to information; it only preserves how already permitted information is displayed. This is why it should be understood alongside governance concepts in NIST Cybersecurity Framework 2.0, where repeatable visibility supports better risk management. The most common misapplication is treating a saved view as a security boundary, which occurs when teams assume a saved filter prevents users from reaching data they are already authorised to query.
Examples and Use Cases
Implementing saved views rigorously often introduces governance overhead, because organisations must decide who can create, edit, share, or standardise them, and whether the view should be personal, team-based, or organisation-wide.
- A vulnerability analyst saves a view for critical findings on internet-facing assets so the same risk slice can be reviewed every morning without rebuilding the query.
- A cloud security team creates a shared saved view for publicly exposed storage buckets and attaches it to recurring reporting workflows aligned with the NIST Cybersecurity Framework 2.0.
- An identity team saves a view of high-risk non-human identities with long-lived credentials, allowing faster review of service accounts, tokens, and certificates that need rotation or ownership checks.
- A compliance team uses a saved view for unresolved exceptions in a specific business unit so weekly meetings always reflect the same scoping rules.
- An incident response lead keeps a saved view for assets tied to an active investigation, reducing time lost to repeated filtering during live triage.
Where environments include IAM, PAM, or NHI governance tools, saved views are often the practical layer that makes investigation repeatable across teams and shifts. They also help reduce reporting drift when different analysts would otherwise apply slightly different filters to the same problem.
Why It Matters for Security Teams
Saved views matter because security teams depend on repeatable visibility to make decisions they can defend. If a saved view is poorly governed, two analysts may believe they are looking at the same risk population while actually comparing different filters, time ranges, or ownership scopes. That creates avoidable confusion in metrics, audit evidence, and escalation paths. In mature programs, saved views support operational consistency, but they also need change control where teams rely on them for executive reporting or control validation.
The identity and NHI connection becomes important when saved views are used to monitor standing privileges, dormant accounts, service principals, API keys, or certificate sprawl. In those cases, the view becomes a practical investigation aid, not a substitute for access policy or entitlement review. It can help teams spot drift faster, but only if the underlying data model is accurate and the view logic is transparent. Saved views also intersect with broader cyber governance because they influence how risk is surfaced under NIST Cybersecurity Framework 2.0.
Organisations typically encounter the cost of inconsistent saved views only after a reporting dispute, failed audit request, or missed investigation clue, at which point the term becomes operationally unavoidable to address.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.RM-01 | CSF 2.0 emphasizes governed, repeatable risk visibility across teams. |
| NIST SP 800-53 Rev 5 | AU-6 | Audit review and analysis depends on consistent filters for evidence retrieval. |
| NIST SP 800-63 | Identity operations rely on consistent review of account and authenticator state. |
Apply saved views to recurring identity reviews without treating them as access controls.