Appearance
Scoring and attribution
This page describes the live scorecard and the live attribution labels.
It does not describe an Impact findings decision screen. That screen is not in the dashboard.
Attribution
A report is an attributed event.
Ownership is first-party, joint, or third-party.
Attribution confidence is a separate number from severity.
- Severity answers “how urgent.”
- Confidence answers “how sure we are this belongs as labeled.”
Low confidence still shows the row after the finding is in your tenant.
It does not remove the row from Reports or Vendor Monitoring.
Vendor posture score
Vendor Monitoring shows a grade and a 0–100 score.
The live formula:
- Start at 100.
- For each active incident, deduct
severity × 2 × confidence weight. - Floor at 0.
Letter grades from that score:
| Grade | Score |
|---|---|
| A | 90 or higher |
| B | 80 or higher |
| C | 70 or higher |
| D | 60 or higher |
| F | Below 60 |
This is vendor posture. It is not “does this reach us.”
Confidence weight
| Confidence | Effect on the deduction |
|---|---|
| Missing | Full weight (legacy). The incident deducts as if weight is 1. |
| Lower | Smaller deduction. The incident still appears. |
| Higher | Larger share of severity × 2. |
The vendor detail page can show a weighted deduction chip on an incident.
Report severity labels
Reports filter severity as Low, Medium, High, or Critical.
Alert rules use the same labels. Numeric map:
| Label | Number |
|---|---|
| Low | 1 |
| Medium | 2 |
| High | 3 |
| Critical | 4 |
Exposure severity stays 0–10 on the Exposures page.
Evidence you can see
The dashboard shows:
- Repository link and file on Exposures
- Ownership, confidence, and the report body on Reports
- Incident summary, severity, confidence, and category on vendor detail
You decide from those fields.
A letter grade is extra posture context. It is not the close reason.