Analytics and benchmarking

Two read-only views: Analytics charts your own compliance, risk and policy figures over a window you choose and can narrate them with AI, and Benchmarking sets those figures beside anonymised peers.

These two pages answer different questions about the same programme. Analytics looks inward — how are our own numbers moving, and why? Benchmarking looks outward — how do we compare with organisations like ours? Both gather figures that already exist elsewhere in Aegis and present them as cards and charts. Neither lets you edit a record; to change a figure you go to the module it comes from.

Who uses it

Analytics opens to Contributor and above; a Viewer who types the address is sent to the access-denied page. Benchmarking opens to every role, Viewer included, but it is a licensed feature: when Peer Benchmarking is not on your licence the page shows a short notice instead of the cards. Some controls inside Analytics are gated by permission rather than by role name — the AI buttons and the two AI panels below the header need the report-read permission, and Export Dashboard needs the report-export permission, which a Contributor does not hold. That is why the capture below shows no export button, while a Manager or Admin sees one.

What's on this screen

/analytics sits under the Reporting group in the left menu and opens as one scrolling page. The header carries the title Analytics with the line "Advanced reporting and trend analysis", and on the right a row of buttons: Exec summary (AI), Trend narrative (AI), Why did this change? (AI) and Generate Report.

Below the header sit two panels holding the output of past AI runs. Saved AI insights lists insights you chose to keep; in the captured tenant nothing has been kept yet, so it reads "No AI insights saved yet. Run an AI action and choose 'Save as record' to keep it here." Under it, Action items from AI lists the follow-ups those runs produced — the capture holds one, "AI executive summary", showing the status In progress and the source Analytics Exec Summary. The small circle at the left of a row is its status control.

Next comes a row of six figures: Compliance Score, Total Risks, Critical Risks, Total Policies, Total Vendors and Open Incidents — in the capture 0%, 498, 62, 120, 200 and 3. Then the Trend Charts heading with a date-range list on its right (the capture shows Last 30 days) and the charts: Risk Trends holding the risk heatmap (impact against likelihood, "498 risks plotted, 62 critical"), Compliance Score Over Time holding the trend line, and below the fold Policy Status Distribution, Vendor Risk Overview, Incident Trends and Evidence & GDPR Summary.

Open Analytics and read the figures

  1. Open the Reporting group in the left menu and choose Analytics. The page loads the six figure cards first, then the charts underneath.
  2. Select Exec summary (AI) in the header. A window opens over the page explaining what the summary will cover, with a Write summary button — nothing is generated until you press it.
  3. In Action items from AI, select the circle at the left of a row to move it on: Open becomes In progress, then Done, then back to Open. The label under the title changes as soon as it saves.
  4. Read the Risk Heatmap under Trend Charts. The grid runs impact against likelihood, but on this page it is filled by severity band (the level a risk's impact × likelihood score falls into): each band's total sits in one representative cell, coloured to match the legend below the grid. So a shaded cell is a band's count, not a count of risks at exactly those coordinates. The figures in the corner name the population — in the capture, "498 risks plotted, 62 critical". Risks with no score are not plotted.
  5. Select a shaded cell. Cells holding at least one risk are links — Aegis opens the risk register filtered to that cell's likelihood and impact coordinates and to open statuses (Open and InProgress). Because the cell counts a whole severity band and the link filters on one pair of coordinates, the register will usually list fewer rows than the number in the cell. Cells reading 0 are not clickable.
  6. Read Compliance Trend on the right for the same window. The percentage and change indicator sit above the line; with nothing to plot the panel says No compliance data available rather than drawing a flat line.
Analytics: AI actions, saved insights, action items, figure cards and trend charts — /analytics.
Analytics: AI actions, saved insights, action items, figure cards and trend charts — /analytics.
When a panel reads "No data" or "Coming soon"

Every chart needs records inside the chosen window. A new tenant, or one with no frameworks activated, shows sparse charts — the compliance panel reads No compliance data available, and Incident Trends can read Coming soon where that breakdown is still being built out. That is the page being honest, not an error. Widen the range, or add the data in the source module.

Change the window

  1. Open the date-range list beside the Trend Charts heading and pick Last 7 days, Last 30 days, Last 90 days or Last 12 months. The charts redraw against the new window straight away.
  2. Note what does not move: the six figure cards at the top are a snapshot of today and ignore the range. Only the trend charts respond to it.
  3. Set the range before running an AI action: the AI reads the window you have chosen, and changing it afterwards does not rewrite an answer already on screen.

Run an AI read-out

Three AI actions sit in the header, all working over the selected window and all read-only. Exec summary (AI) writes a board-ready summary — bottom line, what is working, what needs attention, a recommendation. Trend narrative (AI) describes how the compliance, risk and vendor figures moved, leading with what is deteriorating or standing still. Why did this change? (AI) drills into one metric you pick: overall compliance score, total open risks, critical risks, average risk score, active vendors or critical-risk vendors.

  1. Choose your window, then select one of the three AI buttons. A window opens describing what the action does — and, for Why did this change?, a Metric to explain list. Pick the metric before you start.
  2. Select the start button (Write summary, Write narrative or Explain change). Aegis works through named steps — reading the posture, classifying the direction of travel, then writing — and the text streams in as it is produced.
  3. Read the answer against the figures it was grounded in. Where the action reports them, a Verified figures block and a Confidence indicator sit with the text; check the wording against your own numbers before using it.
  4. Decide what to keep: Copy to the clipboard, Export DOCX or Export PDF to download, Save as record to keep it in Saved AI insights on this page, Create action item to add a row to Action items from AI, or run it again from the button that names the action — Rewrite summary, Rewrite narrative or Explain again.

Generate a report or export the dashboard

  1. Select Generate Report at the top right. A short menu opens beneath it with Executive Summary, Compliance Status, Risk Overview and View All Reports.
  2. Pick a template and Aegis opens the report builder already set to it; pick View All Reports for the Reports list instead. Nothing on the Analytics page changes either way.
  3. If your role holds the report-export permission, use Export Dashboard beside it: Export as PDF gives a branded document, Export as CSV the flat figures, both for the selected window. If an export fails, a message says so and nothing is downloaded.

What's on the benchmarking screen

/benchmarking sits under the Compliance group. It opens with the title Peer Benchmarking and a line naming the segment you are compared against — in the capture, "Industry: Financial Services. Size: Micro." Below it, a blue notice appears while the tenant has not opted in: an administrator sees a link to Settings → Benchmarking, everyone else is told to ask an administrator. Then five metric cards — Control Compliance, Audit Readiness, Evidence Freshness, Policies and Vendors — each with a tier badge beside its title, your value, and a comparison block underneath. Peer Comparison & Maturity follows below them.

  1. Open the Compliance group in the left menu and choose Benchmarking. Read the line under the title first — it tells you which industry and size band the figures are matched to.
  2. Scroll past the five cards to Peer Comparison & Maturity, below the bottom of the capture. It holds a maturity score, a radar chart of your values against the peer average, and a table of five dimensions — policy coverage, risk maturity, incident response, vendor management, evidence freshness — each with your value, the peer average, your percentile and the trend. The whole section only appears once comparison data has loaded, and the table says No comparison data available. when there is nothing to compare.
Peer benchmark cards with tier badges, percentiles and sources — /benchmarking.
Peer benchmark cards with tier badges, percentiles and sources — /benchmarking.

Each card carries the same five parts:

Part of the card What it means
Your value Your own figure, with a line saying how it is counted.
Tier badge A banding of your percentile: Excellent from the 75th, Good from the 50th, Average from the 25th, otherwise Below Average.
Source label Industry Benchmark means a published baseline. Where enough peers have opted in, the rows read Peer Average and Peer Median instead, with a peer count.
Average and median The middle of the comparison set; one outlier moves the average.
Your Rank and source line Your percentile within that set, and the study the baseline came from — the capture cites ISACA/Ponemon 2025 and PCI DSS/SOX audits 2025, among others.
Read the tier badge together with the underlying figure

In the capture, Evidence Freshness shows 100% with an Excellent badge at the 99th percentile, while Control Compliance shows 0% with Below Average at the 0th. The badge only bands your percentile within the comparison set, and a thin or baseline-driven set can push a figure into a flattering or an unflattering band. Read the badge with your own value, the median and the source line before drawing any conclusion.

The AI assist

The three AI actions write about figures Aegis has already calculated; they do not calculate them. Direction of travel — improving, deteriorating or standing still — is classified by Aegis from the stored snapshots, and the AI narrates that classification. Every run is started by a person, over a window that person chose, and the result stays on screen until someone copies, exports, saves or discards it. Saving an insight or creating an action item are deliberate choices; the AI never edits a record, changes a status or files anything by itself. Each billable AI action draws one credit from your tenant's monthly allowance.

Tips and limits

Where this connects

The figures come from Compliance frameworks, Risks, Policies, Vendors, Incidents and Evidence. Follow-ups collect in Action items; documents are built in Reports and Board reports; the peer opt-in lives in Settings. Roles are set out in What each role can do.