How to Use the Dashboard to Track Supply Chain Health KPIs

Beginner 15 minutes All Personas Dashboard & Analytics

Read the overview metrics, use time range and repository/client filters, and interpret violation trends by severity.

Overview

The Chainsaw overview dashboard provides a real-time view of your organization’s supply chain health. It surfaces key performance indicators (KPIs), violation trends, and activity patterns that help you assess risk posture, measure policy effectiveness, and communicate supply chain health to stakeholders.

Prerequisites

  • Any role in Chainsaw (Member or above)
  • Traffic flowing through the proxy

Step 1: Navigate to the Dashboard

Click Overview in the sidebar (or it loads by default after login). The dashboard shows several sections of metrics and charts.

Full dashboard overview
The overview dashboard provides a comprehensive view of supply chain health

Step 2: Understand the KPI Cards

The top of the dashboard shows key metric cards:

Blocked Packages

The total number of package requests blocked by policies in the selected time range. A high number may indicate active threats or overly aggressive policies.

Blocked packages KPI card
Total blocked requests — monitor for spikes indicating attacks or policy issues

Cache Hit Ratio

The percentage of package requests served from Chainsaw’s local cache versus fetched from upstream. A high ratio means faster builds and less reliance on external registries.

Cache hit ratio KPI card
Higher cache hit ratios mean faster builds and reduced upstream dependency

Compliance Score

An aggregate measure of how well your package consumption aligns with your policies. This reflects the percentage of packages passing all policy checks.

Compliance score KPI card
Your compliance score shows overall policy adherence

Active Exceptions

The number of currently active exceptions (packages explicitly allowed despite policy violations). A growing number may indicate policy debt.

Active exceptions KPI card
Track active exceptions — too many may indicate policy tuning is needed

Step 3: Use Time Range Filters

Adjust the time range to analyze different periods:

RangeUse Case
Last 7 daysDaily monitoring, recent incident investigation
Last 30 daysMonthly review, trend analysis
Last 90 daysQuarterly compliance reporting
Time range filter
Switch between 7-day, 30-day, and 90-day views

All KPI cards and charts update dynamically when you change the time range.

Step 4: Filter by Repository and Client

Narrow the dashboard view to specific contexts:

Repository Filter

Select a specific repository to see metrics for just that ecosystem:

Repository filter dropdown
Filter to see metrics for a specific package ecosystem

Client Filter

Select a specific client to see activity for a particular team or pipeline:

Client filter dropdown
Filter to see a specific team's or pipeline's supply chain metrics
Combine repository and client filters to answer specific questions like “How many npm violations did the frontend team’s production pipeline trigger this month?”

Step 5: Read the Violation Charts

Violations by Severity

A breakdown showing violations categorized as critical, high, medium, and low:

Violations by severity chart
Understand the severity distribution of policy violations
SeverityTypical Trigger
CriticalCVSS >= 9.0, confirmed malware
HighCVSS >= 7.0, high-confidence typosquat
MediumCVSS >= 4.0, blocked license, low trust score
LowFreshness guard, informational flags

A time-series chart showing how violations change over time. Look for:

  • Spikes — May indicate a new attack or a newly deployed policy
  • Declining trends — Your policies are working and teams are upgrading
  • Steady high numbers — May need policy tuning or developer education
Violation trends over time
Track how violations change over time to measure policy effectiveness

Step 6: Explore Additional Metrics

Vulnerability Breakdown

See the distribution of vulnerabilities by CVSS/EPSS severity across your supply chain:

Vulnerability severity breakdown
Distribution of vulnerabilities by severity in your package consumption

License Coverage

Track the ratio of packages with known vs unknown licenses:

License coverage analysis
Monitor how many of your packages have identifiable licenses

Top Exceptions

See which packages have the most active exceptions — these represent your highest accepted-risk items:

Top exceptions list
Identify which packages have the most active risk exceptions

Real-Time Event Feed

A live feed of package requests and their outcomes:

Real-time event feed
Watch package requests flow through the proxy in real time

Patch Priority Widget

The Patch Priority Widget ranks the upgrades that retire the most known-exploited and high-EPSS risk per merge. The list is built by walking each direct dependency’s transitive closure (default depth 5) and combining KEV-pinned, EPSS ≥ 0.5, and “+N deps unblocked” badges into a single ordered queue.

Patch Priority Widget on the overview
The widget surfaces the next upgrade to schedule — KEV-pinned items rise to the top, with badges showing how many transitive dependencies the upgrade unblocks
BadgeMeaning
KEVAt least one CVE in the upgrade’s closure is in the CISA Known-Exploited-Vulnerabilities catalog
EPSS ≥ 0.5Predicted exploitability probability is at or above 50%
+N depsUpgrading this package unblocks N transitive dependencies that are currently pinned to vulnerable versions

Click any row to drop into the simulator and preview exactly which CVEs clear and which transitives unblock — see How to Run the Patch Simulator.

Monitor-to-Enforce Nudge

When you have policies running in monitor mode that have collected enough samples to be promoted to block without breaking the build, a banner appears at the top of the overview prompting the upgrade.

Monitor-to-enforce nudge banner
Once a monitor-mode policy has a clean false-positive rate over the observation window, the dashboard surfaces a one-click promotion to enforce

The banner only fires when:

  • The policy has been in monitor for at least the configured observation window (default 14 days).
  • The fire rate is non-zero (the policy is actually catching things).
  • The rate of monitor-fires that were later granted exceptions is below the no-noise threshold.

This keeps you from sitting on a working policy in monitor mode forever, which is the most common cause of the “we have Chainsaw but nothing is enforced” pattern.

Step 7: Build Stakeholder Reports

Use the dashboard for different audiences:

For Security Leadership

Focus on:

  • Compliance score trend
  • Critical/high severity violations
  • Exception growth rate
  • Overall trust score distribution

For Engineering Leadership

Focus on:

  • Cache hit ratio (build speed)
  • Blocked package impact (developer friction)
  • Top violations by team (who needs help)

For Compliance Auditors

Focus on:

  • Time-range filtered metrics for the audit period
  • Violation counts by category
  • Exception documentation
  • Pair with SBOM and audit log exports
Take screenshots of the dashboard for inclusion in compliance reports, or use the CSV/SBOM export features for machine-readable evidence.

Dashboard Monitoring Cadence

FrequencyWhat to Check
DailyEvent feed for anomalies, new violations
WeeklyViolation trends, exception count, policy effectiveness
MonthlyCompliance score, cache hit ratio, stakeholder report
QuarterlyFull supply chain health review, policy stack audit

Next Steps