The Scorecard gives every Unician a weekly pulse on the health of the business. It replaces gut-feel with objective numbers. Every metric has a single owner — not a team, one person — and a weekly target. The Scorecard is reviewed in the first 5 minutes of every Level 10 Meeting.
⚠️ Rule: The Scorecard is not a project status report. It measures the health of the business, not the completion of tasks. Rocks and To-Dos live in OpenProject.
| # | Metric | Owner | Weekly Target | Tool / Source | Category | Standard |
|---|---|---|---|---|---|---|
| 1 | New trial signups | Predrag | 3 | Mautic / Matomo | Business | — |
| 2 | MRR (Monthly Recurring Revenue) | Predrag | Track weekly delta | Dolibarr | Business | — |
| 3 | Open support tickets (unresolved >48h) | Predrag | < 5 | FreeScout | Business | — |
| 4 | GitHub PRs merged (platform) | Peter | ≥ 3 | GitHub | Product | — |
| 5 | EU project deliverables on track (%) | Alexander | 100% | OpenProject | Projects | — |
| 6 | Platform uptime (%) | Peter | ≥ 99.5% | status.unicis.tech / Grafana | Service | ISO 20000-1 |
| 7 | Newsletter open rate (last send) | Ksenija | ≥ 35% | Mautic | Marketing | — |
| 8 | Active paying organisations | Predrag | Track weekly delta | Dolibarr | Business | — |
| 9 | Critical security alerts (CrowdSec) | Peter | 0 unresolved | Grafana / Matrix alerts | Security | ISO 27001 |
| 10 | Website organic sessions (week-over-week) | Ksenija | ↑ vs prior week | Matomo | Marketing | — |
| 11 | P1 incident response time (avg) | Peter | ≤ 2 hours | FreeScout / incident log | Service | ISO 20000-1 |
| 12 | Security patch deployment (critical) | Peter | ≤ 7 days | Vulnerability scanner log | Security | ISO 27001 |
| 13 | Access provisioning time (new hires) | Alexander | ≤ 1 day | Access control log | Security | ISO 27001 |
| 14 | Deployment success rate (%) | Peter | ≥ 99% | GitHub Actions / incident log | Service | ISO 20000-1 |
Business & Product: Core company health (revenue, signups, code quality)
Service (ISO 20000-1): Platform reliability and availability commitments
Security (ISO 27001): Information security and incident response performance
Each person in each seat is accountable for at least one number per week. These feed into the Company Scorecard or stand alone as seat-level health indicators.
Leadership Role: SMS Sponsor & ISMS Sponsor — Oversees both ISO 20000-1 and ISO 27001 systems
Leadership Role: Service Delivery Owner & Information Security Implementation — Responsible for service reliability and security controls
Leadership Role: Support Manager & Access Control Manager — Responsible for operational service delivery and security access control
Leadership Role: Communications & Security Awareness Lead
The live Scorecard is maintained as a shared wiki page in OpenProject and updated by each owner before the Monday Level 10 meeting.
→ Open Scorecard in OpenProject
If you do not have access to OpenProject, contact the CEO.
Metrics should be stable — don't change them frequently or they lose meaning. To propose a new metric or retire an existing one:
A metric should be removed if it stays green for 8+ consecutive weeks without anyone looking at it — it has served its purpose.
→ Back to V/TO | → Rocks & Level 10 Meetings | → Accountability Chart | → ISO 20000-1 Service Metrics | → ISO 27001 Security Metrics
Last reviewed: October 2026 — next review: Q4 2026 (Updated with ISO 20000-1 & ISO 27001 metrics)