// people security
The laptops your policy assumes are patched
L5 counts the devices your people actually use, and turns red on the ones carrying High or Critical vulnerabilities. Like L3, it needs nothing connected to be measurable.
// what it watches
What this layer watches
People Security has no “Set Up” state. It is measurable from your first day, without connecting anything, because the data it judges is data you already hold.
- Hardware assets associated with people in your organisation
- Vulnerability severity on each device, scored on CVSS v4
- Devices that have drifted out of their expected posture
- Joiners, movers and leavers, and the devices that follow them, handled through people management
// what turns it red
What turns it red
Each row is a live measurement on your own environment, not a checklist item. The third column is the part a compliance-first tool cannot offer.
| What is measured | What it says | Where clicking it takes you |
|---|---|---|
| Hardware assets carrying findings at Critical CVSS v4 severity | N Hardware Devices Need Fixing | The device list, filtered to High and Critical |
| Hardware assets carrying findings at High CVSS v4 severity | N Hardware Devices Need Fixing | The same list |
| Devices with no identifiable owner, or an owner who has left | N Hardware Devices Need Fixing | The device record and its assignment history |
| Devices that have drifted out of their expected posture | N Hardware Devices Need Fixing | The device record and its posture detail |
| Findings below High severity, tracked as work but not escalated to this layer | Not counted here | The device record, where every finding is listed |
This table is not the whole check
People, devices, onboarding state, training and policy acknowledgement are all tracked together. Only High and Critical device findings turn this layer red, so it stays a signal rather than a wall of noise.
// getting to green
What it takes to go green
- Devices arrive on the asset spine alongside the people they belong to.
- Only High and Critical severity turns this layer red, so it stays a signal rather than a wall of noise.
- Each affected device becomes tracked work owned by someone who can actually patch it.
- The layer clears when no device carries a High or Critical finding.
// the evidence
The evidence this produces
None of this is collected for the auditor's benefit. It is the by-product of work that had to happen anyway, which is why it holds up when someone checks.
- Endpoint and asset management evidence across your frameworks — see the asset inventory guide
- A device inventory tied to the people who hold them
- Remediation history per device, with dates
// questions this answers
People and device coverage, answered directly
Why does L5 only count High and Critical devices?
So the layer stays a signal rather than a wall of noise. Only hardware assets carrying High or Critical CVSS v4 severity turn it red; lower-severity findings are still tracked, but they do not claim your attention at the coverage level.
Does device coverage need an MDM integration to be measurable?
No. Like supply chain, L5 has no Set Up state. Devices arrive on the asset spine alongside the people they belong to, so the layer reports from day one.
What happens to a device when someone leaves?
Joiners, movers and leavers are tracked with the devices that follow them, so a device does not quietly drop out of scope when its owner changes or departs.
// keep reading
Where this goes deeper
Want to see this one live?
Book 30 minutes and we will walk through “The laptops your policy assumes are patched” in the actual platform, using your environment as the example.