Vault adoption per joiner cohortDays from HRIS start date to first vault enrolment, per role family, country and cohort.
Password-health concentrationWeak, reused and compromised passwords per team, BU and country, with the worst named.
Leaver-access cleanup timeHours from HR termination to vault disable and shared-credential revoke, per site and BU.
Sharing-group reach versus roleCredentials shared past their owner team, with the cross-team exposure counted per group.
Shadow-SaaS detection (Omnix)Non-vault credentials detected on apps outside the SSO catalogue, named per team.
Dark-web hit response timeHours from a Dashlane dark-web alert to credential rotation closed, per worker and team.
Admin-action audit trailAdmin policy changes, group edits and seat moves over time, per admin and tenant scope.
Seat usage per BUProvisioned seats versus active vaults per business unit and country, against contract.
MFA enforcement coverageWorkers in scope of mandatory 2FA versus enrolled in practice, per group and policy.
Policy exception agingSharing or password-policy exceptions open past their review window, per owner and team.
SSO coverage gapApps with credentials in Dashlane but no SSO contract, named per team and renewal date.
Audit-pack throughputDays from access-review request to closed pack, per requester, scope and quarter.