Graften Docsgraften.io
Docs / Knowledge Base / Client Health Score

Client Health Score

Security Intelligence

The health score is a weighted average of six components, each scored 0–100:

ComponentWeightSource
Essential Eight maturity30%Latest InfraAudit e8_score
Patch compliance20%% of managed endpoints currently compliant
MFA coverage20%Latest measured MFA coverage (Microsoft 365 or AWS IAM)
Asset hygiene15%% of assets with a known OS
Open incidents10%100 less 10 per open critical risk, floored at 50
Security awareness training5%Phishing simulation non-click rate, plus a report-rate bonus

The weights total 100%, so a client with perfect data across all six scores 100.

A component with nothing measured behind it (no RMM endpoints, no asset inventory, no phishing simulation, no audit score) is dropped and its weight is shared across the components that were measured, so a missing measurement is neither a free pass nor a zero. If the measured evidence covers less than 40% of the total weight, the client shows Not assessed (grade N/A) instead of a number. Open incidents is always counted but is not evidence, so it never counts towards that 40%. Each score records how many of the five evidence measures it rests on, shown as "Based on N of 5 measures".

Grades: A ≥ 90 · B 80–89 · C 70–79 · D 60–69 · F below 60.

Open severity caps the grade

The numeric score alone can hide an unmitigated problem: a client with strong scores everywhere and one open critical risk still arithmetically lands in the 90s. Because this grade is quoted in insurance questionnaires and evidence packs — where a single unresolved critical finding is treated as disqualifying — severity caps the letter regardless of the number:

The numeric score is left untouched, so trend lines stay smooth and a client can still see week-to-week progress while capped. A risk stops counting once it is resolved or formally accepted in the Risk Register — accepting a risk is a deliberate, recorded decision, which is why it lifts the cap.

Every client report states this methodology in its footer, and the reason for any cap is shown beneath the grade, so a client or their insurer never sees a letter without an explanation.

Scores are recalculated by the scheduler (daily per client, and after each audit completes) and stored for historical trending. Run InfraAudit first so all component data is fresh — a component with no data behind it is reported as not assessed rather than as a zero.

The score.changed webhook

Subscribe to score.changed under Automation & Webhooks to be told when a client's score or grade moves. It fires only when the client has a real score and that score or grade differs from the previous snapshot — never for a client that is Not assessed, and not on a recalculation that produced the same result. The payload carries client_id, score, grade, previous_score (null for a first score) and assessed_measures / total_measures.

Open in the interactive docs