What's new in asset criticality
Release date: October 2026
Until now, an asset was either a crown jewel or it was not, and you wrote and maintained the queries that decided which. Asset criticality replaces that single flag with ordered levels, such as crown jewels, high value, standard, and low impact. An AI agent studies your environment and proposes the levels and the J1QL queries that fill them, so you start from a complete setup instead of a blank page. You review every level and query before anything takes effect, and JupiterOne keeps every asset's level current from then on.
What is new
| Feature | What it means for you |
|---|---|
| Criticality levels | Two to six ordered levels with names you choose, replacing the single crown jewel flag |
| Agent-proposed setup | The agent analyzes your environment and proposes your levels and their queries in one to two minutes |
| Start from your policy | Give the agent your asset classification policy, and it builds a setup that follows your policy and matches your environment |
| Review before anything changes | Rename levels, edit or move queries, see match counts, and ask the agent for changes in plain language before you apply |
| Always current | Levels run every hour, so new assets are classified as they arrive. Run history shows what each run changed. |
| Levels in the risk score | Each level has its own multiplier in the UVM risk configuration, so vulnerabilities on your most critical assets rank highest |
| Queryable everywhere | Every classified asset carries j1.criticality and j1.normalizedCriticality, for use in J1QL, alert rules, and dashboards |
An agent-proposed setup
The hardest part of asset criticality has always been the setup: deciding the levels and writing queries that hold up across a large environment. Select Set up for me on Assets > Asset criticality, and the agent proposes a complete setup from what JupiterOne already knows about your environment. It judges each asset by consequence—what breaks if the asset is lost or compromised—and keeps production assets in the most critical levels.
If you already have a classification policy, select Start from our policy instead. If you prefer to write every query yourself, select Build it myself.
You stay in control
Nothing the agent proposes takes effect until you apply it. On the Review your setup page, every query shows its J1QL and how many assets it matches today. You can rename levels, edit, move, or remove queries, or describe a change in plain language and let the agent revise the proposal. Preview changes shows an estimate of how your assets will be distributed before you click Apply setup.
After you apply a setup, you can edit levels and queries at any time, draft new queries with AI, or run the agent again.
Criticality levels in the risk score
The UVM risk score now uses criticality levels in its context layer. Each level has its own multiplier, which you set in the Risk configuration panel, so a vulnerability on an asset at your most critical level ranks above the same vulnerability on a less critical asset. See Risk scoring.
Upgrading from crown jewels
- Crown jewel queries you defined before this release were carried into your asset criticality setup. Open Assets > Asset criticality to review them, refine them, or run the agent to build a fuller setup.
- The
tag.crownJewelproperty no longer affects the risk score. If your alert rules, dashboards, or saved queries filter ontag.crownJewel, update them to filter onj1.criticalityorj1.normalizedCriticality.
Getting started
- Confirm you have the Vulnerabilities: Admin or Full Admin Access: Admin permission
- Navigate to Assets > Asset criticality and select Set up for me
- Review the proposed levels and queries, and ask the agent for any changes
- Click Preview changes, then Apply setup
- Open the Risk configuration panel in Vulnerabilities and review the multiplier for each level
For full feature documentation, see Asset criticality.