A PDF report is proof of your filtering compliance for a specific device, group, or your whole fleet on a specific day. Reports aren't stored files sitting somewhere waiting for you — each one is generated fresh the moment you ask for it.
Every report covers exactly one calendar date: a single device, a single group, or your entire fleet. If there's no scan data for that device, group, or fleet on the date you picked, you'll get a clear "no data" message instead of an empty or broken report — there's no such thing as a report with no date attached.
When you click Open or Download, the server builds the PDF from your scan data at that moment, sends it to your browser, and then deletes its own temporary copy. There's no stored file behind the scenes and no link you can bookmark and revisit later expecting the same file — clicking the same report again just regenerates it from whatever scan data still exists for that date.
There's no share link on these screens, and no email button next to a report. Sharing a report from here means downloading the PDF and sending it yourself, the same way you'd send any other file.
Every report link is the same request with one thing changed: whether it opens in your browser tab or downloads as a file. On your Scan History page, both a device's report and a group's report give you an Open button and a Download button side by side. Your fleet-wide report on the same page also has both — unless you're a group-scoped team member, in which case both fleet buttons are disabled with the same explanation: fleet reports cover every device on the account and aren't available for group-scoped accounts.
A device's own details page only ever opens its report inline — there's no download button there. If you want to download a device's PDF rather than just view it, Scan History is where that option lives.
The account owner can always download reports. For team members, it depends on role: Admin, Technician, and Viewer can all download reports. Billing cannot — the Billing role's access is scoped to billing information only.
If you're a team member scoped to specific groups rather than the whole fleet, the same boundary described in what group-scoped team members can see applies here: you can get reports for devices and groups within your scope, but a fleet-wide report — which by definition covers devices outside any single group — is denied outright, not filtered down to what you can see.