Skip to content

Scoring and attribution

This page describes the live scorecard and the live attribution labels.
It does not describe an Impact findings decision screen. That screen is not in the dashboard.

Attribution

A report is an attributed event.
Ownership is first-party, joint, or third-party.

Attribution confidence is a separate number from severity.

  • Severity answers “how urgent.”
  • Confidence answers “how sure we are this belongs as labeled.”

Low confidence still shows the row after the finding is in your tenant.
It does not remove the row from Reports or Vendor Monitoring.

Vendor posture score

Vendor Monitoring shows a grade and a 0–100 score.

The live formula:

  1. Start at 100.
  2. For each active incident, deduct severity × 2 × confidence weight.
  3. Floor at 0.

Letter grades from that score:

GradeScore
A90 or higher
B80 or higher
C70 or higher
D60 or higher
FBelow 60

This is vendor posture. It is not “does this reach us.”

Confidence weight

ConfidenceEffect on the deduction
MissingFull weight (legacy). The incident deducts as if weight is 1.
LowerSmaller deduction. The incident still appears.
HigherLarger share of severity × 2.

The vendor detail page can show a weighted deduction chip on an incident.

Report severity labels

Reports filter severity as Low, Medium, High, or Critical.

Alert rules use the same labels. Numeric map:

LabelNumber
Low1
Medium2
High3
Critical4

Exposure severity stays 0–10 on the Exposures page.

Evidence you can see

The dashboard shows:

  • Repository link and file on Exposures
  • Ownership, confidence, and the report body on Reports
  • Incident summary, severity, confidence, and category on vendor detail

You decide from those fields.
A letter grade is extra posture context. It is not the close reason.