Skip to content

All notes  /  Operations

The Report Worth Producing

One page that says whether the system works, whether it is being acted on, and whether the governance is real.

Reference

A deployment with no periodic report is a deployment nobody can say anything about, which is the state most of them are in.

The measures

Recall and precision from the last evaluation, with the date. If it is older than a quarter, say so.

Alerts per operator per shift.

Time to acknowledge, trended.

Dismissal rate without action, which is the fatigue signal.

Override rate at human review. Near zero means rubber-stamping.

Camera health: offline time, image quality flags.

The outcome measure the system exists to affect — incidents, defects, events — alongside the detection count.

Access log review result, including a clean one.

Eight numbers. Each names a specific failure when it moves the wrong way.

The pairing that matters most

Detections and the outcome measure, on the same chart.

Both falling: the intervention is working.

Detections falling, outcome flat: the system is being avoided, has degraded, or the threshold moved. Investigate before celebrating.

Detections rising, outcome flat: false alarms are rising, or the threshold moved the other way.

A detection count alone is uninterpretable, and reporting it alone is how a degraded system produces a reassuring chart for a year.

What to leave out

Total detections as a headline, for the reason above.

Accuracy without a date and a threshold.

Hours of footage stored, which measures the storage bill.

Uptime, which says nothing about whether the system is detecting correctly.

Anything per individual, which is the boundary this whole collection holds.

Governance items on the same page

Deployments in the register without an owner.

Assessments older than their review date.

Notices that do not match current capability, which is a standing audit finding and takes one comparison to check.

Retention exceptions and active legal holds.

Interim measures past their date for the physical control they stand in for.

Who it goes to

Whoever relies on the system, who are currently assuming it works at the number they were told at installation.

Whoever owns safety, where the application is safety.

Whoever owns data protection, for the governance items.

Into an existing forum, not a dedicated one.

Visible to the people subject to it where that is possible, which is unusual and disproportionately reassuring.

The annual version

Performance now against a year ago, same method.

What changed and what it moved.

What the evaluation found, including where it was worse than expected.

Would you deploy this today? The question that produces the decommissioning decisions, and the one nobody asks unless the report asks it.

The interpretation line

One sentence per number, written by a person, that makes the report readable.

What the number is doing and whether it is inside its normal range.

Why, if known.

What is being done, and by whom.

Updated when it changes, not restated monthly.

Written by the owner of the measure, which is also how you discover whether it has one.

Numbers without interpretation get read as noise, and readers supply their own explanation, which is usually wrong.

Making it visible to the people in frame

Unusual, cheap, and disproportionately effective.

Publish the summary where the people subject to the system can see it: what it detects, how often, what the evaluation found.

Not the detections themselves, and not anything individual.

It answers the question people actually have better than any notice.

It also invites correction: the people who work there know when a camera has been pointing at a wall for a month.

Few organisations do this and the ones that do have markedly less trouble.