VISTASecurity
  • Vista Platform
  • How it works
  • Insights
  • Docs
  • Release status
  • Mailing list
Try Core
Vista Documentation
  • Editions
  • Vista Platform Platform Overview
  • Cbom
    • CBOM Artifacts
  • Features
    • Algorithm Reference
    • AI Assistant Integration (MCP)
    • Asset Approval Workflow
    • Asset Lifecycle Management
    • AWS Cloud Resource Discovery
    • Azure Cloud Resource Discovery
    • Certificate Chain Management
    • CMDB Integrations
    • CMDB Terminology Glossary
    • Compliance Framework Management
    • Crypto Risks Dashboard
    • Cryptographic Keys
    • Device Interrogation Feature
    • Discovery Feature
    • Fortinet Device Interrogation
    • Viewing Frameworks, Controls & Measurements
    • GCP Cloud Resource Discovery
    • Getting Started checklist
    • Global search (⌘K)
    • Inventory and Lenses
    • Measurement Templates
    • Inviting Members
    • Infrastructure Assets and Crypto Configurations
    • Network Spaces Feature
    • Operational Context
    • Page-local Export
    • PCAP File Ingestion
    • Remediation
    • Scopes
    • Enhanced Sensor Registration & Management Guide
    • Spreadsheet Import
    • Third-Party Systems and External Connections
    • Unified Crypto Inventory
  • Guides
    • Audit Logging User Guide
    • Cloud and Device Management Separation – Migration Guide
    • Device Auto-Discovery Troubleshooting Guide
    • Device Interrogation User Guide
    • Tenant Administrator Guide
    • Tenant User Guide
  • Operating VistaPlatform
    • Container runtime images (source of truth)
    • Platform Administrator Guide
    • Releases & Versioning
    • Service Startup and Shutdown Procedures
    • Configuration
      • Platform Integrations Configuration Guide
    • Deployment Documentation
      • Database Deployment Readiness – Sensor Management Enhancements
      • Database Migration Guide
      • Device Agent Deployment Guide
      • Managed vs In-Cluster Data Services (EKS)
      • Deployment Migration Checklist
      • Production Deployment Checklist
      • Deployment Propagation Guide
      • Vista RKE2 v1 — Customer Documentation
        • Vista — RKE2 Cluster Provisioning Guide
        • Vista Deployment Guide — RKE2 v1
        • Vista RKE2 Deployment — Pre-Flight Checklist
        • Vista Security Overview — RKE2 v1
        • Vista Support Bundle
    • Monitoring
      • Compliance Engine Event Processing Alerts
      • Compliance Log Management & Retention
      • Production Monitoring & Alerting Setup
      • System Monitoring & Alerting Guide
    • Operations
      • Notification Provider Integration Guide
    • Security
      • 🔒 Security Architecture for Cloud-Hosted Control Plane
      • Bootstrap Certificate Management
      • Certificate Management Operations Guide
      • Secrets Management Guide
    • Troubleshooting
      • Asset Approval Workflow Issues – Resolution Documentation
      • Troubleshooting Guide
      • Runbooks
        • Gateway Runbook
        • Recovery and Resume After Reboot
Vista/Docs

Page-local Export

When you're looking at the Inventory page, the Export button at the top right downloads whatever's currently on screen as a CSV. That's it. No template selection, no parameter dialog, no waiting on a server-side generation job — just the rows you see, in your spreadsheet.

This is the right tool for: filtering down to a few hundred rows, dropping the result into Excel, emailing it to a colleague, pasting it into a ticket. Anything where "I just want this list in CSV form" is the whole task.

What it isn't

It's not evidence. The CSV doesn't carry a content hash, a signature, or a provenance record. If you regenerate the same view tomorrow, you'll get different rows (new assets, expired certs, edited tags) — that's expected for a working view, but it means a CSV from this button is a snapshot in a notebook, not a snapshot in a vault.

For audit submissions, vendor questionnaires, or anything where the recipient needs to verify the artifact later, generate a CBOM instead (CBOM in the top nav). A CBOM:

  • Locks the rows by content hash so the recipient can verify integrity.
  • Captures scope_version so the boundary is reproducible.
  • Optionally signs the artifact (HMAC for v1; asymmetric is roadmap).
  • Optionally embeds a compliance-attestation layer.
  • Stays retrievable later from the CBOM list, with a comparison view against your prior artifacts.

Where the Export button lives

  • Inventory (/inventory) → top right of the page, next to "Discover Assets." Exports the current lens view (whichever lens is active, with whichever filters are applied).
  • Risk & Compliance (/risk-compliance) → Overview tab, top right next to the layout toggle. Exports your current risk-posture and compliance-standing numbers (severity and category counts, post-quantum readiness, per-framework compliance scores, finding counts).
  • Compliance Workspace (/compliance/workspace) → top right of the page header. Exports the controls currently shown in the table — including any family filter and sort you've applied.
  • Tickets (/tickets) → top right of the toolbar. Exports the tickets matching your current status / category / search filters.

On every page the button greys out when there's nothing to export, with a tooltip pointing you at the CBOM page for audit-grade output.

What's in the CSV

Whatever the page is showing. Each page owns its own column layout, and the button just downloads what's on screen:

  • Inventory — the columns the active lens shows. Switch lenses (Infrastructure → Certificates → Configuration → …) and the next click exports the new layout.
  • Risk & Compliance — a flat section, metric, value layout covering the Overview dashboard cards.
  • Compliance Workspace — control id, name, family, status, severity, failing-finding count, and last-seen.
  • Tickets — title, category, status, priority, severity, due date, assignee, external system/id, and created date.

The filename is <view>-<YYYY-MM-DD>.csv (e.g. inventory-certificate-2026-06-08.csv, tickets-2026-06-08.csv). The date is the local date at the moment you clicked.

Why this exists (Phase 5 background)

The legacy reporting surface had eight separate "lens reports" that produced PDFs of the same data you were already looking at. Each was a templated server-side generation job with its own filter dialog. We retired the whole thing in Phase 5 of the CBOM-centric reporting redesign — the surface was 90% redundant with the page itself.

This button is the replacement. It does exactly the job that wasn't worth a templated report: a CSV of the view you're already looking at, with zero ceremony.

For the part that did need ceremony — evidence-grade artifacts with provenance — that's now first-class at Risk & Compliance → CBOM (/risk-compliance/cbom), and the affordance is much better than the old "Generate Lens Report PDF" workflow.

← Operational Context PCAP File Ingestion →

View source on GitHub · Published from 470d8ee

On this page
  • What it isn't
  • Where the Export button lives
  • What's in the CSV
  • Why this exists (Phase 5 background)
VISTASecurity

Vista Platform is a self-hosted cryptographic system of record for continuous discovery, evaluation, action, and proof.

Vista Platform

How it works
Governance
Post-Quantum
Core, Enterprise & MSP
Try Core

Resources

About
Insights
Documentation
Release status
GitHub ↗
info@vistasecurity.io
Join the mailing list

© 2026 Lakeshore Labs LLC. Vista Security is a brand of Lakeshore Labs LLC. All rights reserved.