Assessments

Assessments and schedules: why the Security Score is never a stale snapshot

A score is only as good as the last time it was recalculated. Assessments run on demand or on a recurring schedule, and every run is recorded with its duration, target and result.

Blog

August 10, 2026 · 8 min read

01

A history of every run

Every assessment executed against a scan target is logged: when it ran, how long it took, which target it covered and what it found. That history is what makes a Security Score change explainable — it is tied to a specific, inspectable run.

Assessments: history of executed evaluations with date, duration, target and result.
Assessments: history of executed evaluations with date, duration, target and result.
02

Recurring, not one-off

Assessment schedules keep evidence current without someone remembering to trigger a re-run. A scan target can be evaluated on a recurring cadence, so the score reflects the third party's environment as it changes, not as it looked at onboarding.

  • On-demand assessments for immediate re-evaluation after a fix
  • Recurring schedules per scan target
  • Real-time progress while an assessment is running
Assessment schedules: recurring evaluation configured per scan target.
Assessment schedules: recurring evaluation configured per scan target.
1stone Research

Talk to the team about a third-party program

A working session against your actual third-party portfolio: how workspaces are created, which accounts get connected first, and what the Security Score looks like in week one.

Request a walkthrough