How to Use the Dashboard to Track Supply Chain Health KPIs
Read the overview metrics, use time range and repository/client filters, and interpret violation trends by severity.
Overview
The Chainsaw overview dashboard provides a real-time view of your organization’s supply chain health. It surfaces key performance indicators (KPIs), violation trends, and activity patterns that help you assess risk posture, measure policy effectiveness, and communicate supply chain health to stakeholders.
Prerequisites
- Any role in Chainsaw (Member or above)
- Traffic flowing through the proxy
Step 1: Navigate to the Dashboard
Click Overview in the sidebar (or it loads by default after login). The dashboard shows several sections of metrics and charts.

Step 2: Understand the KPI Cards
The top of the dashboard shows key metric cards:
Blocked Packages
The total number of package requests blocked by policies in the selected time range. A high number may indicate active threats or overly aggressive policies.

Cache Hit Ratio
The percentage of package requests served from Chainsaw’s local cache versus fetched from upstream. A high ratio means faster builds and less reliance on external registries.

Compliance Score
An aggregate measure of how well your package consumption aligns with your policies. This reflects the percentage of packages passing all policy checks.

Active Exceptions
The number of currently active exceptions (packages explicitly allowed despite policy violations). A growing number may indicate policy debt.

Step 3: Use Time Range Filters
Adjust the time range to analyze different periods:
| Range | Use Case |
|---|---|
| Last 7 days | Daily monitoring, recent incident investigation |
| Last 30 days | Monthly review, trend analysis |
| Last 90 days | Quarterly compliance reporting |

All KPI cards and charts update dynamically when you change the time range.
Step 4: Filter by Repository and Client
Narrow the dashboard view to specific contexts:
Repository Filter
Select a specific repository to see metrics for just that ecosystem:

Client Filter
Select a specific client to see activity for a particular team or pipeline:

Step 5: Read the Violation Charts
Violations by Severity
A breakdown showing violations categorized as critical, high, medium, and low:

| Severity | Typical Trigger |
|---|---|
| Critical | CVSS >= 9.0, confirmed malware |
| High | CVSS >= 7.0, high-confidence typosquat |
| Medium | CVSS >= 4.0, blocked license, low trust score |
| Low | Freshness guard, informational flags |
Violation Trends
A time-series chart showing how violations change over time. Look for:
- Spikes — May indicate a new attack or a newly deployed policy
- Declining trends — Your policies are working and teams are upgrading
- Steady high numbers — May need policy tuning or developer education

Step 6: Explore Additional Metrics
Vulnerability Breakdown
See the distribution of vulnerabilities by CVSS/EPSS severity across your supply chain:

License Coverage
Track the ratio of packages with known vs unknown licenses:

Top Exceptions
See which packages have the most active exceptions — these represent your highest accepted-risk items:

Real-Time Event Feed
A live feed of package requests and their outcomes:

Patch Priority Widget
The Patch Priority Widget ranks the upgrades that retire the most known-exploited and high-EPSS risk per merge. The list is built by walking each direct dependency’s transitive closure (default depth 5) and combining KEV-pinned, EPSS ≥ 0.5, and “+N deps unblocked” badges into a single ordered queue.

| Badge | Meaning |
|---|---|
| KEV | At least one CVE in the upgrade’s closure is in the CISA Known-Exploited-Vulnerabilities catalog |
| EPSS ≥ 0.5 | Predicted exploitability probability is at or above 50% |
| +N deps | Upgrading this package unblocks N transitive dependencies that are currently pinned to vulnerable versions |
Click any row to drop into the simulator and preview exactly which CVEs clear and which transitives unblock — see How to Run the Patch Simulator.
Monitor-to-Enforce Nudge
When you have policies running in monitor mode that have collected enough samples to be promoted to block without breaking the build, a banner appears at the top of the overview prompting the upgrade.

The banner only fires when:
- The policy has been in
monitorfor at least the configured observation window (default 14 days). - The fire rate is non-zero (the policy is actually catching things).
- The rate of
monitor-fires that were later granted exceptions is below the no-noise threshold.
This keeps you from sitting on a working policy in monitor mode forever, which is the most common cause of the “we have Chainsaw but nothing is enforced” pattern.
Step 7: Build Stakeholder Reports
Use the dashboard for different audiences:
For Security Leadership
Focus on:
- Compliance score trend
- Critical/high severity violations
- Exception growth rate
- Overall trust score distribution
For Engineering Leadership
Focus on:
- Cache hit ratio (build speed)
- Blocked package impact (developer friction)
- Top violations by team (who needs help)
For Compliance Auditors
Focus on:
- Time-range filtered metrics for the audit period
- Violation counts by category
- Exception documentation
- Pair with SBOM and audit log exports
Dashboard Monitoring Cadence
| Frequency | What to Check |
|---|---|
| Daily | Event feed for anomalies, new violations |
| Weekly | Violation trends, exception count, policy effectiveness |
| Monthly | Compliance score, cache hit ratio, stakeholder report |
| Quarterly | Full supply chain health review, policy stack audit |
Next Steps
- How to Monitor Violations and Respond to Blocked Packages — Deep dive into violation handling
- How to Export Your SBOM in CycloneDX Format — Generate compliance artifacts
- How to Use Audit Logs to Track Consumption — Complement dashboard with audit trails
- How to Use Billy to Investigate and Draft Policies — Ask Billy about what the dashboard shows