> ## Documentation Index
> Fetch the complete documentation index at: https://docs.safesquid.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Reports

> Reports entry point for SafeSquid SWG policy evidence, forensic investigation, SIEM forwarding, and operational review.

# Reports

Use **Reports** to prove what SafeSquid allowed, blocked, inspected, bypassed, or forwarded. A policy without reportable evidence cannot support audit, incident response, or executive risk decisions.

The Application Eco-system source identifies SIEM log forwarding over UDP for real-time access, extended, and native logs. Treat Reports as the console entry point for that evidence flow.

## Evidence to review

* access outcomes by user, group, source, destination, and policy
* blocked malware, phishing, category, and application events
* bypass or exception activity
* configuration and privileged-access changes
* SIEM forwarding status for real-time investigation

## Verification

After a policy change, trigger a controlled request and confirm:

1. The expected allow or block decision appears in Reports.
2. The event includes enough identity and destination context for investigation.
3. The same event reaches the SIEM when forwarding is configured.

## Next steps

* Use [Reporting Service](/safesquid_swg/interface/reporting_service) for deployment patterns and troubleshooting.
* Use [Configure](/safesquid_swg/policy_management_console/configure) to adjust the policy that generated the report.


## Related topics

- [Tools and Reports](/admin_guide/start_here/tools_and_reports.md)
- [Blank Report Page](/troubleshooting/blank_report_page.md)
- [Logging and Reporting](/deployment/logging_and_reporting.md)
- [Reporting Module](/use_cases/audit_and_forensics/reporting_module.md)
- [Reporting & Forensics](/safesquid_swg/interface/reporting_service.md)
