Capability by Area reports show where your teams have skill gaps and which areas need attention. You can see who's covering which capabilities, identify single points of failure, and track progress over time.
You'll find Capability by Area under Reports in the main navigation menu.

What you can track
These reports help you:
- Spot capability gaps across your organization
- Identify which skills are covered (and by how many people)
- Find critical resource dependencies
- Monitor Crisis Sim performance
- See which labs users abandon
- Get recommendations for training priorities
Who can see what
Organization Managers see data for the entire organization.
Team Admins see only their teams and team members. They can't access the Crisis Responders Dashboard.
Crisis Sim Managers see only the Crisis Responders Dashboard (unless they're also Team Admins or Organization Managers).
Available dashboards
Capability by Area includes seven dashboards:
- Security Teams – Cyber security teams' coverage and gaps
- Application Security – AppSec teams' vulnerability and code security skills
- Cloud Security – Cloud security teams' platform and configuration skills
- Crisis Responders – Executive and leadership crisis decision-making
- Workforce
- Workforce Baseline
- Assessment Metrics
Note: You'll only see dashboards for content you're licensed to access. If you don't have AppSec content, you won't see the Application Security dashboard.
Security Teams Dashboard
Track how your security teams cover cyber capabilities, from fundamentals to advanced offensive and defensive skills.
| Who's included |
Users with access to:
|
| Capability gaps |
Interactive scatter plot showing:
|
| What to look for |
Hover over points to see the content area. Click for a table to then export that data to CSV. |
| Coverage breakdown |
Table showing coverage by content category:
|
| Lab recommendations |
Suggested labs based on:
Use these to build custom collections. |
| Critical resource dependencies |
List of individuals who've uniquely completed the most labs in:
These are your single points of failure – if they leave, you lose that capability. |
| Assigned lab abandonments |
Labs users started but didn't finish:
Calculation period: Labs started between selected date and 90 days before. |
| When to use Security Teams |
Use this dashboard to:
|
Application Security Dashboard
Track how your AppSec teams cover code security, vulnerabilities, and secure development practices.
| Who's included | Users with access to Application Security (AppSec) content – labs focused on finding and fixing vulnerabilities in real code. |
| Capability gaps |
Helps you identify where to upskill to minimize risk. |
| Coverage by App Sec language |
Percentage coverage by programming language:
Helps you make strategic upskilling decisions – see which languages your team knows. |
| Coverage breakdown |
Coverage of labs in each AppSec area:
|
| Lab recommendations | Suggested labs based on what your team has completed and what they're missing. |
| Assigned lab abandonments |
Assigned labs users started but didn't complete:
|
| When to use Application Security |
Use this dashboard to:
|
Cloud Security Dashboard
Track how your cloud teams cover platform security, configuration, and cloud-native protection.
| Who's included | Users with access to Cloud Security content – labs covering how to secure organizations in the cloud. |
| Capability gaps |
Shows where you need more people trained. |
| Coverage by subcategory |
Coverage of labs in each cloud security area:
|
| Lab recommendations | Suggested labs based on your team's activity and coverage gaps. |
| Assigned lab abandonments | Assigned labs started but not completed (same criteria as other dashboards). |
| When to use Cloud Security |
Use this dashboard to:
|
Crisis Responders Dashboard
Track how your executives and leadership teams perform in crisis decision-making exercises.
| Who's included | Any user who's participated in a Crisis Sim exercise. |
| Exercises activity |
Table showing all assigned Crisis Sim exercises:
Includes both running exercises and closed ones. Click on data points to drill in and export to CSV. |
| Low capability themes |
High-risk themes across crisis scenarios:
|
| Low score injects |
Decision points your team struggled with:
|
| Lower risk teams | Teams with the highest average overall scores – your best performers. |
| Higher risk teams |
Teams with the lowest average overall scores:
|
| Average score vs average confidence |
Capability by user:
|
| What to look for |
|
| Capability by inject |
Shows which decision points users struggled with and where upskilling is needed. |
How scores are calculated
Each decision is given a decision and confidence score. This is then aggregated to give a participant decision and confidence score, and aggregated again to give an exercise level decision and confidence score.
| Decision score (based on option selected): |
Then averaged across all participants. |
| Confidence score (based on user's stated confidence): |
|
|
When to use Crisis Responders
|
Use this dashboard to:
|
Workforce Dashboard
Track how your workforce covers workforce exercises.
| Exercises Assigned |
Table showing all assigned Workforce exercises.
|
| Risk Areas Exercised |
Table of Risk Areas that have been exercised.
|
| Higher Scoring Teams | Teams which have an average decision score above 50% |
| Lower Scoring Teams | Teams which have an average decision score below 50% |
| Average Score vs Average Confidence |
Capability by Team
Capability by Risk Area
|
Workforce Baseline Dashboard
Security Hygiene Compass
Provides a risk profile of your workforce.
| What’s included |
Users exercised: Count of users who have completed a workforce exercise User Breakdown: A table showing, email, score, risk and teams. Higher Risk Users: Count of users that are high risk Overall score: Percentage score |
| Score by Risk Area | Heatmap of your workforce’s overall score across the different risk areas. |
| Users by Risk Label | Graph showing users grouped by their overall score. |
| Team Breakdown |
Table showing teams that have completed the baseline scenario.
|
| Available filters |
Filter the dashboard by:
Use this dashboard to prioritize and address high-risk areas. |
Assessment Metrics
View Adaptive Assessment scores
| What’s included |
Overview:
|
| Skill distribution by assessment |
Table showing:
|
| Re-assessment overview |
The Re-assessment overview section only appears after you select a specific assessment title from the filter menu.
Average Score: First vs. Latest Attempt Graph plotting first score vs latest score |
| User breakdown |
Table showing:
|
| Available filters |
|
Available filters
Security Teams, Application Security, and Cloud Security
Team name – Drill down to specific teams (Organization Managers only)
License type – Break down by product (e.g., see how Crisis Sim users engage with security content)
Report as of – Look back in time to see improvement (default: today, shows 90 days prior)
Has current license (Y/N) – Include or exclude former users
Email (AppSec and Cloud Security only) – Search for specific users
AppSec language (Application Security only) – Filter by programming language
Cloud technology (Cloud Security only) – Filter by cloud platform
Crisis Responders
Email – Search for specific users
Team name – Filter by team (doesn't include presentation mode exercises)
Scenario name – Filter by specific crisis scenario template
Exercise name – Filter by specific exercise instance
Selected date range – Choose custom time period
Working with the dashboards
Interactive features
All dashboards are interactive:
- Hover over charts to see details
- Click on data points to drill in
- Export detailed data to CSV
- Filter to narrow your view
Using the scatter plots
In the Security Teams capability gaps chart:
- Hover over a dot to see the content area
- Click the dot to open detailed data
- Export that specific data to CSV
- Track that area over time
Understanding abandonments
Lab abandonments help you spot:
- Content that's too difficult
- Users who need support
- Skill gaps across teams
Remember: Only assigned labs count as abandonments. Self-directed learning that's paused doesn't appear here.
Making decisions with the data
| High coverage + few people = risk |
When only a few people have a skill:
|
| Low coverage + many people trying = opportunity |
When lots of people are attempting but not completing:
|
| Low coverage + few people = gap |
When a skill is under-represented:
|
Common workflows
Quarterly capability review
- Check Security Teams – Overall capability gaps
- Review AppSec/Cloud (if licensed) – Specialized skill gaps
- Look at Crisis Responders – Leadership preparedness
- Export findings to CSV for reporting
Succession planning
- Go to Security Teams – Find critical resource dependencies
- Note single points of failure
- Check Coverage breakdown – See what they know
- Assign cross-training to other team members
Training prioritization
- Review Lab recommendations – See suggested content
- Check Capability gaps – Find areas with few people
- Look at Assigned lab abandonments – Find where people struggle
- Build custom collections addressing these gaps
Crisis readiness assessment
- Open Crisis Responders – Overall scores
- Check Low capability themes – Risky scenarios
- Review Higher risk teams – Teams needing support
- Look at Average score vs confidence – Individual needs
Tips for using Capability reports
Compare over time
Use the "Report as of" filter to:
- Set a date 90 days ago
- Compare to today's data
- Track improvement
Focus on single points of failure
Critical resource dependencies are your biggest risk. If those people leave:
- You lose that capability
- Projects might stop
- Response times increase
Cross-train others on their unique skills.
Don't ignore confidence mismatches
In Crisis Responders, users with:
- High confidence + low score need immediate support (dangerous combination)
- Low confidence + high score need encouragement (they're better than they think)
Use lab recommendations
The recommendations tool isn't random. It's based on:
- What your users have completed
- Adjacent content they'd likely succeed at
- Coverage gaps in your organization
Trust it to guide training decisions.
Filter by team for targeted action
Organization Managers can:
- Compare teams
- Find which teams excel
- Identify which teams need support
- Share best practices from high performers
Next steps
- Export data to CSV for deeper analysis
- Create custom collections based on recommendations
- Assign training to address capability gaps
- Check Platform Activity Reports for engagement tracking
- See Metrics Tracker for benchmark comparisons