Email a security report to your client
Send a weekly or monthly security report to the people who pay for a site, with your name and logo, from BetterShield Ultra’s Client report tab.
The client report is an email for the people who pay for a site and never sign in to it: where the site stands, what was put right, and what happened since the last report. Set it up on BetterShield › Ultra › Client report, part of BetterShield Ultra. It is off until you turn it on.
Set it up
| Option | What it does | Default |
|---|---|---|
| Send this report | Turns the schedule on. | Off |
| How often | Monthly or Weekly. | Monthly |
| Day of the month | For a monthly report, 1 to 28, a day every month has. | 1 |
| Day of the week | For a weekly report, Sunday to Saturday. | Monday |
| Prepared by | Your name or your agency’s, printed at the end of the report. | Empty |
| Send it to | Up to five email addresses. Add an address adds a row, Remove takes one off. | Empty |
| Include how accounts sign in | Adds two-factor and passkey counts by role. Counts only: the list of who a policy is waiting on stays on the Sign-in report. | On |
Press Save. If the report is on with no address to send it to, the card says so.
The day follows the site’s time zone. The report goes out on that day as an HTML email, through the site’s own mail setup.
Read it, or send one now
- Read it opens The report as it will arrive, built from the saved settings.
- Send one now asks once more, then emails the saved addresses straight away. The next scheduled report still arrives on its day.
Both wait until your changes are saved, and Send one now waits for at least one saved address. Under the buttons, the card says when the last report was sent (in UTC); the next one covers everything since. Before the first, it says none has been sent yet and that the first covers the period before it.
What the report contains
- Where the site stands: the Security score, Grade and Open items.
- What changed: what was Put right, and what Opened, and being looked at. A quiet period says so plainly and the report still goes out.
- Recorded activity, grouped by the area of the site it happened in.
- How accounts sign in, when it is included: each role’s accounts, and how many have a second step.
- Your Prepared by name, and a closing line saying the detail behind every figure is in the site’s own security record, which its administrator can open.
It is dressed with the logo and accent color from Sign-in screens, so what the client receives matches the screens they sign in through.
It is written for somebody without a login, so it carries no links into the dashboard, no finding keys and no next step addressed to the reader. Nothing is sold in it, to them or to you.
Delivery and the record
- Each send, scheduled or not, is recorded in the activity log as Alert sent, with how many addresses it went to and whether it was accepted, never the addresses themselves.
- If the site’s mail refuses it, the period does not count as reported, and the next report covers it.
- The schedule is checked daily on BetterShield’s own task runner, so a site whose scheduled tasks have stopped still sends it when someone opens the dashboard.
- Mute all alerts does not hold it back. Turn off Send this report instead.
Good to know
- If the installed BetterShield is too old for the report, the card says to update it, and the switch waits until you do.
- With Ask for my password before an action that removes a protection on (Settings › General), saving and sending ask for your password.
- On multisite, each site has its own report and recipients.