Reporting & Analytics

Turn data into decisions. Instantly.

Unified reporting across policies, risks, assets, and incidents. Get board-ready summaries, drill into details, and export defensible evidence without spreadsheet wrangling.

Explore report packs Governance & trust
Cross-modulepolicies • risks • assets • incidents
ExportsPDF • CSV • links
Schedulesemail & chat digests
RBACrow & field aware
Report summary mock / image placeholder

What Reporting & Analytics does

Everything decision-makers need, from high-level rollups to drillable evidence.

Board views

Executive summaries

Policy adoption, risk posture, incident trends, and asset coverage in one narrative page with plain-English callouts.

Drill-through

From score → evidence

Every metric links to the underlying register rows, activity logs, and attachments for quick validation.

Schedules

Push insights

Automated weekly/monthly digests to email or chat channels with links back to live reports.

Packs

Curated report packs

Prebuilt bundles for Boards, Audit Readiness, Risk & Treatment, Incident Ops, and Asset Governance.

Filters

Slice by what matters

Business unit, service, severity, owner, environment, or date window — saved views for quick recall.

Traceability

Cross-module linking

Metrics are derived from the same single source of truth used by Policy, Risk, Asset, and Incident modules.

Clear definitions: Every metric includes a definition and calculation note so stakeholders interpret numbers consistently.

What you’ll see on day one

A practical set of questions answered out-of-the-box — no BI setup required.

Policy adoption

Who has acknowledged which policy? What’s unread? Which policies are due for review in the next 30 days?

Risk posture

High/Critical open risks by owner, service, or BU; treatment progress; residual vs inherent risk deltas.

Asset coverage

% assets with owners, classification coverage, EOL exposure, and dependency hotspots.

Incident performance

MTTA/MTTR by severity and service, reopen rate, SLA compliance, and category breakdowns.

Audit readiness

Evidence completeness, repeated findings, overdue CAPA, and control coverage by framework.

Executive rollup

Quarterly snapshot with narrative highlights: what improved, what regressed, and where to focus next.

Report gallery

Pick a pack, apply filters, and share. Each card links to a prebuilt report bundle.

Board Pack

Executive summary, risk posture trend, major incidents overview, policy adoption, and key actions.

Preview Export PDF

Audit Readiness

Evidence checklist completion, overdue CAPA, repeat findings, control coverage by framework.

Preview Export CSV

Risk & Treatment

High/Critical open risks, owners, due dates, and treatment progress with residual risk deltas.

Preview Export PDF

Asset Governance

Ownership coverage, classification, EOL/EOS exposure, and dependency hotspots by service.

Preview Export CSV
Custom reports: Need a specific metric or layout? Save a filtered view as a private or shared report in one click.

Governance & trust

Data that stands up to scrutiny — internally and with auditors.

RBAC & data scoping

Users only see data they’re permitted to. Row/field awareness respects tenant, BU, and role boundaries.

Metric definitions

Each KPI includes a canonical definition, formula, and data source so everyone speaks the same language.

Schedules & lineage

Snapshots are time-stamped; every export includes a “generated at” marker and filter context.

Exports

PDF for board packs, CSV for analysis, and signed links for external reviewers with expiries.

Privacy & retention

PII minimisation in exports, configurable retention windows, and legal holds when needed.

Audit trail

Immutable logs of report views and exports with user, timestamp, and scope.

FAQs

Quick answers for stakeholders and auditors.

Can we schedule reports to email or chat?
Yes. Set frequency and recipients; messages include a summary and links back to the live report.
Do reports respect permissions?
Absolutely. Reports inherit the same role-based access and data scoping rules as the rest of PurpleWASP.
Can we add our logo or custom footer?
Yes — brand the header/footer of exports and include your compliance statement if needed.
What formats are supported?
PDF and CSV out of the box; shareable signed links for external reviewers.

Open Reporting

Start with the Board Pack or Audit Readiness bundle, then save filtered views as your own reports.

Launch Reporting Preview Board Pack

Need a custom metric?

Tell us the definition and audience — we’ll template it and add it to your pack.

Request custom report Read Governance

All exports include a timestamp, scope, and metric definitions for defensibility.