Indicators & Events

How to set KRI thresholds on Mac

You can do this with RiskOS, a risk register for macOS. Two lines on every indicator, read inclusively, and a direction that decides which side of them is the bad one.

A threshold is a decision taken while nothing is going wrong. You write down the number at which you would want to know, and the number at which somebody has to act, and from then on the measurement argues with you rather than the other way round. Two values and a direction are all it takes, and setting them well is most of what separates an indicator that changes a rating from one nobody reads.

Note

Thresholds are inclusive. A reading that lands exactly on the warning level is a warning, and one that lands exactly on the breach level is a breach. There is no gap between the states for a number to fall through.

Where KRI thresholds live

Choose Indicators in the sidebar, under Signals. RiskOS lists indicators worst first, so anything breached sits at the top before you have searched for it. The columns are the reference, the indicator with its direction, the latest reading, the status, the trend, the thresholds themselves, the number of risks the indicator watches, and when the next reading is due.

Select a row and the panel on the right holds the rest of it: the direction, the warning and breach thresholds, an optional target, the cadence you measure on, the reading history with its chart, and the risks this indicator is linked to. The thresholds column in the list is the short version of the same thing, so a dozen indicators can be scanned without opening one. Changes save as you type.

Set a warning and a breach threshold

  1. Open the indicator you want to set

    Choose Indicators in the sidebar and click the row you want. If the indicator does not exist yet, press N while you are in this section and RiskOS creates one here, ready to name. Give it a title that names the measurement rather than the worry — Critical patches outstanding beyond SLA rather than Patching — because that title is what the thresholds will be read against for the next year.

  2. Say which direction is bad

    Set the direction before you touch either threshold. On a count of critical patches outstanding, higher is the bad direction. On a backup restore test success rate, lower is. RiskOS uses the direction to decide which side of each line a reading falls on, which is why a success rate of 72 % reads as a breach rather than as a comfortable margin above zero.

  3. Set the warning threshold

    Enter the value at which you would want to know. This is the level that should still leave you time: the point where the measure has moved far enough to be worth a conversation, not the point where the harm has already landed. On a higher-is-bad indicator the warning sits below the breach; on a lower-is-bad one it sits above it.

  4. Set the breach threshold

    Enter the value at which the position is no longer acceptable. A useful test before you commit to it: if the number reached this level tomorrow morning, would somebody have to do something about it? If the honest answer is no, the level is in the wrong place. A breach that produces no action teaches everyone in the organisation to ignore the colour.

  5. Add a target if you have one

    The target is optional, and it is not a third threshold. Warning and breach describe where tolerance ends. The target describes where you intend the measure to sit once the work behind it is finished. Leave it empty until there is a plan that justifies a number, then set it and let the distance between the latest reading and the target stand as the size of the job.

  6. Record a reading and check where it lands

    Record a reading with its value, the date it was taken and a short note saying where the number came from. The status updates at once, the trend follows the readings before it, and the reading history chart draws your threshold lines across the series, so every past reading is read against the lines rather than against memory.

  7. Set the cadence you will measure on

    An indicator is a number measured repeatedly, so tell RiskOS how often you intend to take it. The Next Due column then carries the date, and an indicator that misses its cadence is marked overdue. That is a signal in its own right: a measure nobody has taken for two months is not the same thing as a measure sitting comfortably in tolerance.

  8. Link the indicator to every risk it says something about. The Risks column then counts them, and each linked risk carries the indicator with its live status in its own panel, under Intelligence. The link is what turns a measurement into evidence at the moment somebody is deciding whether a rating still holds.

Direction decides what the numbers mean

Most indicators worth watching are counts and delays, where a rising number is the worrying one. A meaningful minority are rates and success percentages, where the worry is the fall. The same pair of values means opposite things in those two worlds, so the direction is not a detail you set afterwards — it is the thing that gives the thresholds their meaning.

The practical consequence is an ordering rule. When higher is bad, warning is the smaller value and breach the larger one. When lower is bad, warning is the larger value and breach the smaller one. Read the pair aloud as a sentence before you leave the panel: warn me at ninety per cent, call it a breach at eighty.

Direction, warning and breach on four worked indicators
IndicatorDirectionWarningBreachLatestStatus
Critical patches outstanding beyond SLAHigher is bad51014Breached
Backup restore test success rateLower is bad90 %80 %72 %Breached
Vendor assurance reviews overdueHigher is bad363Warning
Days to detect a security eventHigher is bad373 daysWarning

Those four are worth reading as a set. Two are breached, and the two in warning are sitting exactly on their warning value rather than past it. That is the inclusive rule doing its work, and it is the behaviour most people are surprised by once and never again.

Thresholds are inclusive

A reading that equals a threshold has reached it. Three vendor assurance reviews overdue against a warning level of three is a warning, not the last quiet moment before one. Seventy-two per cent against a breach level of eighty is well past the line, and eighty itself would already have been the breach.

This matters most when you choose the numbers. If you want the warning to fire only once the fourth review has slipped, set the warning at four. Writing three and hoping it means more than three gives you a state you did not intend, on a day when you are unlikely to be reading carefully. Say the number you mean, and let the equality be deliberate.

What the status column tells you

The status is a plain reading of the latest value against the two lines, with one honest extra state for the case where there is no value at all. Colour is never the only carrier of state, so every status is written out as a word beside the colour and the list reads the same to someone who cannot separate the two ends of the scale.

Indicator states and what each one asks of you
StatusWhat it meansWhat it asks of you
No dataThe indicator exists, but nothing has been recorded against it.Take the first reading. Until then the thresholds have nothing to judge.
In toleranceThe latest reading has not reached the warning level.Nothing beyond keeping to the cadence.
WarningThe latest reading has reached the warning level but not the breach level.Look at the trend and at the risks the indicator is linked to.
BreachedThe latest reading has reached the breach level.Open the linked risks and decide whether their ratings and treatment still stand.
OverdueThe cadence has passed without a reading being recorded.Record a reading, or pause the indicator if there is genuinely nothing to measure.

No data is not the same as in tolerance

An indicator with no readings reads as no data, and RiskOS keeps that state separate on purpose. An empty measure looks reassuring in every direction, and a register that quietly showed it as green would be reporting safety it has no evidence for. If a new indicator sits at no data for a month, the honest conclusion is that nobody has been able to collect the number, which is usually a sign that the measure is harder to gather than it looked.

Overdue is about the measuring, not the measurement

Overdue says the cadence has passed without anybody recording a value. The underlying number may be fine; you do not know, and neither does the register. Treat a run of overdue indicators as a question about who owns the measurement rather than as a question about the risk.

Pausing an indicator

Pause and resume live in the list. Pause an indicator when there is honestly nothing to measure for a while — a service switched off, a supplier in transition, a rehearsal deferred by a quarter — and resume it from the same place when the measurement means something again. It is a better answer than deleting a measure you will want back, and a far better one than leaving it overdue for six weeks so that the state stops carrying information.

Choosing numbers you will act on

The mechanics take a minute. The judgement is the part worth spending time on, and it is mostly a matter of working backwards from what you would do.

Start from the action, then find the number

Ask what you would actually do if the measure got bad, and how bad it would have to be before you did it. Set the breach at that value. A threshold derived from an action is defensible in a meeting; a round number chosen because it looked tidy is not, and it tends to be the first thing questioned when the breach is inconvenient.

Put the warning where it still buys time

The gap between the warning and the breach is the amount of notice you are giving yourself. Too narrow and the two states arrive together, which means you have one threshold with extra steps. Too wide and the warning fires constantly and stops meaning anything. Use the reading history to see how fast the measure normally moves, and leave enough room for at least one or two readings between the lines.

Use the history you already have

Record a handful of past readings before fixing the thresholds, with their real dates. The chart will then show the ordinary range of the measure, and you can place the lines relative to something rather than in the abstract. It also tells you quickly if a measure is too noisy to threshold sensibly, which is worth knowing before it is linked to six risks.

Change thresholds deliberately, not in a bad week

Moving a line because a number crossed it is how an indicator loses its authority. If a threshold turns out to be wrong, change it because the reasoning was wrong, note why in the next reading, and leave it alone for a quarter. The point of writing the number down in advance was to remove that argument from the moment it matters.

Troubleshooting

A good number is showing as a breach

The direction is set the wrong way round. On a success rate, a restore percentage or any measure where you want the number to be high, lower is the bad direction, and the warning value has to be the higher of the two. Change the direction, check that the pair reads correctly as a sentence, and the status of the latest reading corrects itself.

A reading exactly on the line changed the status

That is the intended behaviour. Thresholds are inclusive, so reaching the value counts as reaching the state. If you meant the state to begin one step further out, move the threshold by one step rather than trying to read the equality as a near miss.

The indicator shows no data although I have set the thresholds

Thresholds are the lines; readings are what gets measured against them. Until a reading exists there is nothing to place, and RiskOS says so rather than defaulting to a comfortable state. Record a reading with its value and date and the status resolves immediately.

It is marked overdue but nothing has gone wrong

Overdue reports on the cadence, not on the value. The last reading may have been perfectly healthy; the point is that the next one has not arrived. Record the current value, or, if the measurement genuinely does not apply at the moment, pause the indicator from the list until it does.

I moved a threshold and the whole chart changed

The chart draws the current threshold lines across the whole reading history, so moving a line moves it for every reading on the chart. Nothing about the readings themselves has changed — each one keeps the value, the date and the note you recorded — and the new picture is the same series judged against the rule you have written.

Habits that keep thresholds honest

  • Write the direction first. It is the field that gives the other two their meaning, and the one that causes every inverted status.
  • Say the pair aloud. Warn me at five, call it a breach at ten. If the sentence sounds wrong, the numbers are wrong.
  • Set the breach where action begins. A breach nobody responds to is worse than no indicator, because it trains people to look past the colour.
  • Keep a gap you can see across. Leave enough room between warning and breach for a reading or two of notice.
  • Link every indicator to a risk. A measure with no risk attached is a number on a screen; linked, it appears with its live status where the rating is being decided.
  • Keep the cadence honest. Record on time, or pause deliberately. Overdue should be rare enough that it still means something.
  • Note where the number came from. The note on a reading is what makes the series readable a year later, and it is what a reviewer asks for first.
  • Let a breached indicator reach the register. Open the linked risks, look at the residual score and the treatment plan, and decide in the open whether either still stands.

Frequently asked questions

How do I set a warning and a breach threshold for a KRI?

Open the indicator under Signals ▸ Indicators, set which direction counts as bad, then enter the warning value and the breach value. The warning is the level at which you want to know; the breach is the level at which somebody has to act. Record a reading and the status, the trend and the chart lines all follow at once.

What does direction mean on a key risk indicator?

It tells RiskOS which way is the wrong way. On counts and delays, higher is usually bad, so the warning value sits below the breach. On success rates and coverage percentages, lower is bad, so the warning sits above the breach. Direction is what lets the same two numbers mean the right thing on both kinds of measure.

Is a reading exactly on the threshold counted as a breach?

Yes. Thresholds are inclusive, so a value that reaches the breach level is a breach and a value that reaches the warning level is a warning. Three overdue vendor reviews against a warning of three is a warning. If you want the state to start one step further out, set the threshold one step further out.

What is the difference between a target and a threshold on a KRI?

Thresholds describe where tolerance ends, and they set the status. The target is optional and describes where you intend the measure to sit once the work behind it is done. A target does not create a state of its own; it gives you a distance to close, which is useful when the indicator is attached to a risk you are actively treating.

Why does my risk indicator say no data?

Because no reading has been recorded against it yet. RiskOS keeps no data separate from being in tolerance rather than showing an empty measure as healthy. Record a reading with its value and the date it was taken, and the thresholds have something to judge from that moment on.

Why is my KRI marked overdue?

The cadence you set has passed without a reading being recorded. It is a statement about the measuring, not about the measurement — the underlying number may be fine, but nobody has checked. Record the current value to clear it, or pause the indicator from the list if there is genuinely nothing to measure for a while.

Can I change a KRI threshold after recording readings?

Yes. The readings keep their values, dates and notes, and the chart redraws the threshold lines across the whole history so the series is judged against the new rule. Change a threshold because the reasoning behind it was wrong, rather than because a number has crossed it, and note the reason in the next reading.

Do KRI thresholds change a risk score?

No. A breach does not re-score anything on its own. Residual scores come from the effectiveness of the controls you link, or from a value you set by hand. What a linked indicator does is put its live status in the risk's own panel, under Intelligence, so the evidence is in front of whoever is deciding whether the current rating still holds.