Insights and Security Manager
Security Manager holds your policy data, and is where you change it. Insights holds the history of that data, the comparison against other FireMon customers, and the AI. Insights doesn't replace Security Manager. It reads what Security Manager already knows, and adds what only the cloud can produce.
What lives where
| Security Manager | Insights | |
|---|---|---|
| Rules, objects, devices, revisions | The source of truth | Measurements and inventory, not rule content |
| How current | Live | Collected once a day, so up to 24 hours old |
| History | Current state | A daily time series you can range over |
| Comparison with other customers | Not available | Percentile per metric, customer average, category baselines |
| Changing a rule | Where you do it | Read-only |
Insights also adds three AI features: an in-app assistant, written insights regenerated once a day, and an MCP server.
Insights takes measurement and inventory data. That means counts and scores, per device and per device group: total, unused and shadowed rules, object counts, control pass and fail counts, complexity, and SCI. It also takes each device's name and description, the vendor, name, type and version of its device pack, and the definitions of your controls and assessments.
Rule content isn't part of it. Control definitions are saved with their properties and filters stripped out, which are the parts that hold addresses, ports and match criteria. So a number with rules behind it links back to SIP instead of listing the rules.
Policy Planner is the exception. If you have it, Insights keeps the ticket records Policy Planner returns as well as the numbers worked out from them.
Benchmarking against other FireMon customers
Insights compares your numbers with those of every other FireMon customer, so you can tell whether critical controls failing on 2% of your rules is a lot. The comparison needs every customer's measurements in one place, and the cloud is where they are. Your SIP installation holds only yours.
Some pages draw the comparison. Others pass the baseline to the model that writes the page's insight, which quotes it in the text.
| Where | What you see |
|---|---|
| All Metrics | An Industry Comparison column — your percentile rank for each metric, meaning the percentage of FireMon customers with a value lower than yours |
| Metric charts | A dashed FireMon Customer Average reference line across the chart |
| Best Practices | The FireMon Customer Average (FCA) for each category, and how far above or below it your score sits |
| KPI | The same percentile All Metrics shows, on each tile, and a Similar Organizations median bar on carousel cards for proportional metrics |
| Generated insights | The baseline median, quoted in the written insight on KPI, Revision Analytics, and Network Object Groups |
Scope, sampling window and proportion all change what those numbers mean.
Every comparison is built from each customer's device group 1, the all-devices group. Narrow your own view to one device group and you're holding part of your devices up against all of everyone else's.
The sampling window isn't the same everywhere. The percentile, the customer average, and the baseline medians on KPI and Network Object Groups all use each customer's most recent daily batch from the last 30 days. That window is fixed, and ignores the date range you selected. The Best Practices FCA and the Revision Analytics baseline use the range you selected, so they move when you change it.
Metrics with a natural total are compared as proportions. Unused rules are compared against total rules, and control failures against total rules, so size alone does not move the ranking.
History
Security Manager shows your current state. Insights shows how that state has changed. The KPI, All Metrics, Change, Revision Analytics and Network Object Groups pages share one date-range control: 1w, 1mo, 6mo, 1yr or Max. Each reports the change across that period, comparing the start of it with the current value, instead of a single number.
Best Practices has a range control of its own — Last Month, Q/Q, 1yr and Max — and Ask AI has none.
Both use the same daily history underneath. That history is what makes quarter-over-quarter reporting possible, because last quarter's data is still there.
Insights AI
- Ask AI — the in-app assistant, for questions across your metrics, devices and controls.
- Generated insights — short written observations, regenerated once a day, shown on the KPI, Revision Analytics and Network Object Groups pages.
- The MCP server — connects your own AI system to your FireMon environment, so your model queries rules, devices, network paths and compliance data directly, and does its own reasoning.
Reporting you control
The KPI page is a report you build, not a fixed dashboard. Check the metrics that matter to you in All Metrics and they appear on your KPI page, in the order you arrange the rows there. Metrics with an ideal direction color their trend green or red. A raw count with no ideal direction, such as Total Application Objects, is shown without a judgment attached.
On Best Practices, Overall Posture is drawn by fiscal quarter: the current quarter to date plus the three before it. You set the fiscal year start month yourself, and it defaults to January.
From a number back to the rules
Insights tells you unused rules climbed this quarter. Security Manager tells you which rules. Three pages link the two, and each opens SIP in a new tab with a SIQL query already filled in:
- Metric detail pages open the query behind that metric, scoped to the device group you are viewing.
- Revision Analytics opens the change list for the device group over the date range you selected.
- Network Object Groups opens the object groups behind the count.
The button reads View in Policy Manager. For almost every metric it takes you to Security Manager. Three metrics are administrative rather than policy — Managed Devices, Unmanaged Devices and User Logins — and those take you to Administration instead.
The button only appears once Insights knows your SIP installation's address, which the installation sends itself after it connects. If the button is missing on every page, that address never arrived. See Connect your SIP instance.