Operations Cockpit
exoCortex Core Β· Operator view (multi-tenant)
Servizi attivi:

KPI operativi

KPI qualitΓ 

KPI economici

Domain health gauges

92%
NOC health
78%
SOC posture
85%
XDR coverage
88%
GRC compliance
71%
ICC risk index
94%
Help Desk CSAT
Ticket trend Β· 30g tk/giorno
Opened vs Resolved Β· backlog (asse dx) Β· annot: MI-2026-013
PrioritΓ  live count
snapshot Β· click su slice per filtro
P1 Critico8
P2 Alta47
P3 Media312
P4 Bassa724
P5 Plan203
SLA breakdown %
First Response
96.2%
Resolution
94.0%
Escalation
91.4%
At Risk
18 tk
Mean margin
2h 14m
Aging buckets tk per bucket
EtΓ  dei ticket aperti raggruppata in 5 bucket Β· accumulo backlog
Performance KPI tempo / %
MTTA
14m
MTTR
3h 42m
MTTC
5h 11m
Reopen rate
6.0%
Escalation
12.0%
Volume per dominio Β· 14g tk/g stacked
Click su barra β†’ drill-down dominio
Forecast Β· prossimi 14g tk/g
regressione lineare + banda confidence 80%
predictive Β· Ξ²

Ticket per issuetype

Per dominio total ticket
aggregato sui domini canonici
Top issuetype Β· creati ultimi N giorni total / open / closed
click su barra β†’ drill-down ticket browser
Issuetype Β· dettaglio top 30 by volume
β€” types
IssuetypeDomainTotalOpenClosedP1P2SLA breachSLA %
⏳ caricamento…

Operational deep-dive

State distribution count per status
Distribuzione ticket per status workflow (donut)
Escalation funnel L1β†’L2β†’L3 + customer
Funnel escalation per tier + escalation verso customer
Top 10 event types issuetype
Top 10 segnalazioni per tipo di evento
SLA Met vs Breached split per severity
Ticket conformi vs in violazione SLA per livello severity
In SLA vs Fuori SLA Β· tempo chiusura timeline
Ticket chiusi IN SLA (verde) vs FUORI SLA (rosso)
MTTE per severity min in escalation
Tempo medio passato in escalation per severitΓ 
True-Positive vs False-Positive (SOC) qualifier
Split TP/FP/Pending ticket SOC del periodo
SLA targets contrattuali min per severity
Tabella target SLA contrattuali per livello severity
β€” targets
SeverityFirst ResponseResolutionEscalation
⏳ caricamento…
SLA % per tenant MSSP comparison
Confronto SLA % per ciascun tenant cliente attivo
β€” tenant
TenantTotal tkSLA breachSLA %
⏳ caricamento (sadmin only)…
Active alerts count
237
β–Ό 12vs ieri
Critical count
14
β–² 34h
Device availability %
99.4%
β†’1,247 dev
Network avail %
99.91%
β–² 0.02pp
Latency p95 ms
38ms
β–Ό 4ms
Packet loss %
0.18%
β–Ό 0.04pp
Predicted outages 48h
3
capacity model
Alert timeline Β· severitΓ  Β· 30g alert/g
live Β· annot: window manutenzione 28-30 maggio
Capacity usage %
watch
CPU avg cluster
64%
RAM avg
71%
Storage
82%
Bandwidth
45%
Connections
58%
Packet loss Β· 7g %
Andamento packet loss medio sulla rete (rolling 7g)
Latency Β· 7g ms (p50/p95/p99)
Latenza ms ai percentili p50/p95/p99 (7g)
Bandwidth Β· in/out Mb/s
Bandwidth in/out aggregata della rete (Mb/s, 7g)
Service availability SLA % rolling 30g
avg 99.84%
ServizioSLA 30gDowntimeMTBFStatoOwner
api-gateway99.97%13m72hOKNOC-IT
email-mx99.94%26m48hOKNOC-IT
edge-cdn99.88%52m14hdegradedNOC-IT
auth-idp99.99%4m168hOKSEC-IT
db-cluster99.92%35m96hOKNOC-IT
backup-s399.45%3h 58m8hincidentNOC-IT
Security incidents count
42
β–² 730g
Critical threats count
5
β–Ό 1contained 3/5
MTTD min
12m
β–Ό 4m
MTTC (contain) min
38m
β–Ό 8m
MTTR security h:m
4h 12m
β†’
IOC detected count
1,287
β–² 18%
MITRE ATT&CK coverage
14 tactics Β· 88% mapped Β· click cella per dettagli technique
88%
Initial
12
12/14
Execution
9
9/11
Persistence
14
14/19
Priv Esc
11
11/12
Def Ev
18
18/24
Cred Acc
14
14/15
Discovery
22
22/24
Lateral
6
6/9
Collection
14
14/17
C2
12
12/16
Exfil
8
8/9
Impact
9
9/13
Recon
9
9/10
Res Dev
3
3/7
Top threats Β· 7g hits
ThreatHitsSev
Phishing (M365)184crit
Ransomware probe67crit
Brute SSH1,243high
C2 callback38high
DGA domain22med
RDP scan478med
Alert volume Β· severitΓ  Β· 30g alert/g stacked
annot: SOC-INC-0142 escalation
Detection sources alert/30g
Distribuzione detection sources (SIEM/EDR/NDR/Email/Cloud/TI)
Correlated alerts count
3,124
β–² 8%
Attack chains count
14
β–² 28 stopped
Endpoint threats count
87
β–Ό 11
Cloud threats count
32
β–² 4
Identity threats count
18
β†’
Auto remediation %
76%
β–² 6pp
Attack chain map Β· live days Γ— severity score
bubble size = host coinvolti Β· click su bubble β†’ chain detail
14 active
Threat surface count attivi
Threat surface Β· distribuzione minacce per superficie attacco
Active attack chains 14 active Β· 8 contained
ChainSevStageHostsIdentityFirst seenAuto action
CHN-2941P1Exfiltration3m.rossi@…2h faisolated
CHN-2937P1Lateral mov7svc-jenkins4h famanual
CHN-2934P2Cred dump2admin@…6h faremediated
CHN-2929P2Initial access1user-guest1g facontained
CHN-2918P3Recon1β€”1g facontained
Open risks count
87
β–Ό 4
Critical risks count
11
β†’
Compliance score %
88%
β–² 2pp
Open audits count
7
2 closing 30g
Non-conformities count
23
β–Ό 5
Remediation % progress
64%
β–² 7pp
Framework scorecard % controls passed
ISO 27001:2022
92%
NIST CSF 2.0
87%
SOC 2 Type II
91%
GDPR
84%
PCI-DSS 4.0
79%
NIS2
72%
Risk heatmap likelihood Γ— impact
bubble size = rischi nella cella Β· color = sev
Top risks register 11 critical
IDRiskOwnerSevStatusTreatmentDue
RSK-0142SaaS vendor concentration (M365)A. BianchicritIn treatmentMulti-cloud BCP2026-09-30
RSK-0138Ransomware exposure (legacy AD)L. RossicritMitigationTier0 isolation2026-07-15
RSK-0131GDPR DPIA Marketing platformS. VerdihighOpenVendor review2026-08-01
RSK-0127Backup integrity untestedM. NerihighIn progressRestore drill Q32026-09-15
Cross-domain incidents count
18
β–² 3
Services impacted count
7
3 customer-facing
Customers impacted count
142
β–Ό 14
Crisis events count
2
war room open
Business impact €
€ 18.4K
est. losses
Recovery time min
42m
β–Ό 8m
Cross-domain impact Β· 14g incident impact score
Impatto incident cross-domain (customer/internal/infra) 14g
Active war rooms count
2
WRTopicP
WR-08Payment gateway degradationP1
WR-07M365 mail deliveryP2
Avg participants
8.4
Avg duration
1h 42m
Auto-bridge calls
14/14
Major incidents register
MITitleStatusMTTRImpactCustomersStarted
MI-2026-014Payment gateway 5xx burstactiveβ€”crit8732m fa
MI-2026-013M365 mail delivery slowcontained1h 12mhigh552h fa
MI-2026-012VPN concentrator failureresolved2h 38mhigh2402g fa
CSAT /5
4.6/5
β–² 0.1
NPS [-100..+100]
+47
β–² 4
CES [1..7] lower=better
1.8
FCR %
72%
β–² 3pp
Self-service %
28%
β–² 5pp
Deflection tk evitati/7g
412
€ 4.1K saved
CSAT trend + Survey volume Β· 30g score (sx) Β· surveys (dx)
multi-axis Β· target line 4.5
Agents real-time count
Distribuzione stati operatori real-time (Available/Busy/Break/Offline)
Available14
Busy22
Break3
Offline8
tk/agent
18.3
Workload
72%
Productivity
84%
Channel mix Β· 30g tk/g per canale
Volume tk per canale di apertura 30g (Portal/Email/Chat/Phone/AI)
Knowledge top articoli views / deflection
ArticoloViewsHelpfultk evitati
Reset password M3651,28494%87
Connessione VPN MacOS87291%58
Sblocco BitLocker54188%42
Printing Office Roma43178%21
Onboarding nuovo dipendente31896%14
AI generated tk count/30g
1,847
β–² 22%
AI resolved count/30g
709
β–² 18%
Resolution rate %
38.4%
β–² 5pp
Accuracy %
94.2%
Escal. to human %
11.6%
β–Ό 1.4pp
Cost saving €
€ 24.8K
vs human baseline
Autonomous actions count/7g
3,124
β–² 412
Agent activity Β· 7g Β· top 12 run/agente stacked
Run per agente AI 7g Β· successful / escalated / failed
Cost & tokens (7g)
Tokens spent
14.2M
Cost €
€ 142
Cost / tk
€ 0.20
Governor budget
€142/€500
Sentinel block
0.3%
Agent registry Β· 34 active Β· 3 paused success/cost/tokens
AgentPopulationDominioStatusRun 7gSuccessAvg €TokensSentinel
TC Ticket ClassifieroperatorITSMactive1,24796.4%€0.022.1Mβ€”
MF Metric ForecasterexpertNOCactive18491.2%€0.180.6Mβ€”
SH Self-Heal GatekeepersentinelNOCguarded42188.4%€0.041.2M4 blk
MI MI DeclarersentinelICCactive14100%€0.120.1Mβ€”
OP OnCall PageroperatorALLactive31299.4%€0.010.4Mβ€”
EM Email Thread MinerexpertITSMactive87294.1%€0.063.4Mβ€”
MT MITRE MapperexpertSOCactive6792.8%€0.210.4Mβ€”
AS AI ScribeoperatorHDactive1,58497.2%€0.034.8Mβ€”
SR SAM Right-SizerexpertFinOpspaused0β€”β€”β€”β€”
KH KB Auto-HealsentinelHDactive18494.6%€0.080.7Mβ€”
FE FinOps EnforcersentinelFinOpsactive4296.4%€0.150.3M2 blk
DR Discovery RunneroperatorCMDBactive11289.3%€0.050.2Mβ€”
Population mix agenti per popolazione
Distribuzione agenti per popolazione (operator/expert/sentinel)
Sentinel events Β· 30g eventi/g per tipo
Eventi sentinel 30g per tipo (cost block / blast radius / bias)
NH Β· Operations Cockpit v0.2 mockup Β· 2026-06-04 Β· Operator view (multi-tenant)
Chart