Hey everyone! 👋 I just had one of those "why didn't we do this sooner?" moments and had to share. We've been rolling out FortiSASE across the company, and while the admin portal is powerful, our security operations team felt a bit in the dark. They needed visibility into the overall posture—things like connected users, high-risk locations, or policy hit counts—but didn't need, or want, the ability to change configurations.
So, this morning I challenged myself: could I build them a read-only, at-a-glance dashboard in under 15 minutes using only what FortiSASE provides? Turns out, you absolutely can! It's all about leveraging the built-in **Widgets** and **Custom Views**.
Here’s the quick step-by-step I followed:
* **Step 1: Define the "Need-to-Know"**
I grabbed coffee with a couple of our SecOps analysts and asked: "If you could only see five things about our SASE deployment on one screen, what would they be?" We landed on:
* Total connected remote users (right now)
* A breakdown of users by client application (FortiClient, browser, etc.)
* Top 5 locations by user count (spot unusual geographies)
* Firewall policy matches (which rules are getting the most hits)
* A simple list of any currently blocked sessions.
* **Step 2: Assemble the Dashboard**
I created a new custom role in the system with **Read-Only** permissions. Then, I logged in with that role to build the view, ensuring I couldn't accidentally change anything.
1. Went to the main dashboard in FortiSASE.
2. Clicked "Edit" and removed the default widgets that weren't on our list.
3. Used the "Add Widget" button to drag and drop the exact widgets we needed. The "Monitor" widgets section is your friend here—'Users', 'Network', 'Security'.
4. Arranged them into a clean, logical flow. The layout is super flexible!
* **Step 3: Share & Iterate**
I saved the view as "SecOps Overview" and shared the direct link with the team. The immediate feedback was great! They asked for one more thing: a widget showing tunnel health status. Added that in literally 60 seconds.
**Why this worked so well for us:**
- **Zero Cost & Zero Maintenance:** No external BI tools, no extra licenses, no data pipelines.
- **Real-Time Data:** The team sees live data, not yesterday's snapshot.
- **Focus:** It eliminates noise and prevents "config curiosity" for a team that just needs awareness.
Has anyone else built out similar read-only views for different teams (like networking, HR, or compliance)? I'd love to hear what widgets you found most valuable and if you ran into any limitations. This feels like a simple best practice we should all be doing!
keep building
keep building
Fifteen minutes? That's optimistic. Did your clock include the inevitable time spent arguing with the system about view permissions, or waiting for those custom widgets to actually populate with data?
You mentioned defining the need-to-know with the team. That's the part that always takes longer than fifteen minutes in the real world. SecOps will ask for six things, then remember a seventh, and then you'll find out the widget for the seventh metric is buried in a different subscription tier or needs an API call you can't make from a read-only view.
And "read-only using only what FortiSASE provides" - that's the real trick. Wait until you need to give a slightly different group a slightly different dashboard. Suddenly you're looking at their "advanced dashboarding" module and a conversation about extra licenses.
Read the contract