Scorecard
The Scorecard gives every Unician a weekly pulse on the health of the business. It replaces gut-feel with objective numbers. Every metric has a single owner — not a team, one person — and a weekly target. The Scorecard is reviewed in the first 5 minutes of every Level 10 Meeting.
How the Scorecard Works
- Each metric has one owner (the person accountable, not necessarily the one doing the work)
- Each metric has a weekly target — a number, not a feeling
- Green = on or above target. Red = below target
- Red numbers go on the Issues List for IDS — they are not discussed during Scorecard review
- The goal is 13 consecutive weeks of green
⚠️ Rule: The Scorecard is not a project status report. It measures the health of the business, not the completion of tasks. Rocks and To-Dos live in OpenProject.
Company Scorecard
| # | Metric | Owner | Weekly Target | Tool / Source | Category | Standard |
|---|---|---|---|---|---|---|
| 1 | New trial signups | Predrag | 3 | Mautic / Matomo | Business | — |
| 2 | MRR (Monthly Recurring Revenue) | Predrag | Track weekly delta | Dolibarr | Business | — |
| 3 | Open support tickets (unresolved >48h) | Predrag | < 5 | FreeScout | Business | — |
| 4 | GitHub PRs merged (platform) | Peter | ≥ 3 | GitHub | Product | — |
| 5 | EU project deliverables on track (%) | Alexander | 100% | OpenProject | Projects | — |
| 6 | Platform uptime (%) | Peter | ≥ 99.5% | status.unicis.tech / Grafana | Service | ISO 20000-1 |
| 7 | Newsletter open rate (last send) | Ksenija | ≥ 35% | Mautic | Marketing | — |
| 8 | Active paying organisations | Predrag | Track weekly delta | Dolibarr | Business | — |
| 9 | Critical security alerts (CrowdSec) | Peter | 0 unresolved | Grafana / Matrix alerts | Security | ISO 27001 |
| 10 | Website organic sessions (week-over-week) | Ksenija | ↑ vs prior week | Matomo | Marketing | — |
| 11 | P1 incident response time (avg) | Peter | ≤ 2 hours | FreeScout / incident log | Service | ISO 20000-1 |
| 12 | Security patch deployment (critical) | Peter | ≤ 7 days | Vulnerability scanner log | Security | ISO 27001 |
| 13 | Access provisioning time (new hires) | Alexander | ≤ 1 day | Access control log | Security | ISO 27001 |
| 14 | Deployment success rate (%) | Peter | ≥ 99% | GitHub Actions / incident log | Service | ISO 20000-1 |
Understanding the Categories
Business & Product: Core company health (revenue, signups, code quality)
Service (ISO 20000-1): Platform reliability and availability commitments
- See ISO 20000-1:2018 Overview for details on service commitments
- See Service Strategy for SLA targets
Security (ISO 27001): Information security and incident response performance
- See ISO 27001:2022 Overview for details on security commitments
- See Information Security Policy for commitment details
Individual Measurables by Seat
Each person in each seat is accountable for at least one number per week. These feed into the Company Scorecard or stand alone as seat-level health indicators.
Predrag — CEO (runs all functions)
- New trial signups this week
- MRR delta (week-over-week)
- Outbound partner conversations (calls/emails sent)
- Support tickets unresolved >48h (FreeScout)
Leadership Role: SMS Sponsor & ISMS Sponsor — Oversees both ISO 20000-1 and ISO 27001 systems
Peter — Technical Development & Service Delivery
- PRs merged to main branch
- Open critical bugs (P0/P1) unresolved
- Platform uptime %
- P1 incident response time (average) ← ISO 20000-1
- Security patch deployment time (critical vulns) ← ISO 27001
- Deployment success rate % ← ISO 20000-1
Leadership Role: Service Delivery Owner & Information Security Implementation — Responsible for service reliability and security controls
Alexander — Stakeholder & Support / Service Delivery
- EU project deliverables on track (% of active milestones green in OpenProject)
- Stakeholder communications sent this week
- Community GitHub activity (issues opened/closed/commented)
- P2 incident response time (average) ← ISO 20000-1
- Access provisioning time (new hires, days) ← ISO 27001
Leadership Role: Support Manager & Access Control Manager — Responsible for operational service delivery and security access control
Ksenija — Marketing & SEO Strategy
- Website organic sessions (Matomo, week-over-week)
- Newsletter open rate (Mautic, last send)
- New content published (blog posts / social posts)
Leadership Role: Communications & Security Awareness Lead
Scorecard in OpenProject
The live Scorecard is maintained as a shared wiki page in OpenProject and updated by each owner before the Monday Level 10 meeting.
→ Open Scorecard in OpenProject
If you do not have access to OpenProject, contact the CEO.
Adding or Changing a Metric
Metrics should be stable — don't change them frequently or they lose meaning. To propose a new metric or retire an existing one:
- Add it to the Issues List in the next Level 10 Meeting
- Discuss and agree as a leadership team (IDS process)
- Update this page and the OpenProject Scorecard together
A metric should be removed if it stays green for 8+ consecutive weeks without anyone looking at it — it has served its purpose.
Related Standards & Documentation
- ISO 20000-1:2018 — IT Service Management System (service metrics)
- ISO 27001:2022 — Information Security Management System (security metrics)
- Service Strategy & Commitments — SLA targets and how we deliver
- Information Security Policy — Security commitments and governance
- Risk Assessment Framework — How we manage risks affecting these metrics
- Accountability Chart — Leadership roles and responsibilities
- Quarterly Planning & Reviews — How we use metrics to improve
→ Back to V/TO | → Rocks & Level 10 Meetings | → Accountability Chart | → ISO 20000-1 Service Metrics | → ISO 27001 Security Metrics
Last reviewed: October 2026 — next review: Q4 2026 (Updated with ISO 20000-1 & ISO 27001 metrics)