> ## Documentation Index
> Fetch the complete documentation index at: https://helpdocs.getthread.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Liongard Webroot Read

> Interrogate a client's Webroot (GSM) console through the Liongard Webroot inspector — protected endpoints, agent status, infection/threat state, policy assignment, sites. Use for "are their Webroot endpoints protected?", coverage-gap checks, or AV posture questions during triage.

<Info>
  **Category:** Liongard Inspectors · [View source ↗](https://github.com/bryan-getthread/skills/blob/main/skills/liongard-inspectors/liongard-webroot/SKILL.md)
</Info>

**Connectors:** `Liongard`

**Role:** [Technician](/start-here/roles/technician)

**Outcome:** Faster Resolution & Response, Risk & Compliance

**When to use:** "Are \<client>'s Webroot endpoints protected and reporting?", a malware/AV ticket needing the infection picture, "which endpoints are flagged infected or needing attention?", "which sites/policies is a device assigned to?", or "did a policy assignment change?".

**Run it:** on one client — name the client and the Webroot question.

## Prompt

```
Read Webroot (Global Site Manager) state for CLIENT_NAME from the Liongard Webroot inspector. Read-only — Webroot policy and enrollment are a technician's job in the console.

1. Resolve the client's environment, then find the Webroot inspector and confirm it ran recently — carry "as of <timestamp>." Endpoint state changes, so an old data read on an active incident deserves a "verify live" caveat.
2. Read the values from its latest dataprint for the angle you need, verifying every field angle against the live dataprint (schemas vary by inspector version):
   - Coverage: endpoint list with protection status — count unprotected / not-reporting.
   - Infections: endpoints flagged infected or needing attention.
   - Policy: policy/site assignment per device.
   - Versions: agents on outdated versions.
3. "What changed?" → check what changed on the Webroot side: policy changes, endpoint adds/removes — ordered against the incident window. Pull anything already escalated too.
4. Sanity-check surprising zeros (zero endpoints) — usually a wrong field angle or partial inspection; re-probe broadly. Absence of an endpoint in Webroot is a coverage lead, not proof a machine is unprotected — reconcile against RMM/AD counts and verify before asserting.
5. Output: a compact table, source + data age line, flags (unprotected endpoints, infected devices, coverage gaps). Offer to leave a plain-text note. Degradation: no Webroot inspector → documentation → ticket history → "verify in console."
```


## Related topics

- [Liongard Duo Read](/skill-library/liongard-inspectors/liongard-duo.md)
- [Liongard Okta Read](/skill-library/liongard-inspectors/liongard-okta.md)
- [Liongard Azure Read](/skill-library/liongard-inspectors/liongard-azure.md)
