Trend Tracker: Secure Score and Backlog Trends
Overview
Trend Tracker in Spotto shows your secure score history over time (from Microsoft Defender for Cloud) alongside recommendation activity, so you can see whether your security posture trend is getting better, worse, or just noisier. It is designed for the recurring question: “Did we actually improve this month, or did we just talk about it?”
Use Timeline to see movement over time. Use Compare Snapshots to compare two points in time and see what changed.
Feature overview
Trend Tracker has two views:
- Timeline: chart secure score, Azure Advisor scores, resource footprint, and recommendation trends across selected subscriptions.
- Compare Snapshots: compare daily, weekly, or monthly snapshots for one subscription and review the score, cost, resource, and recommendation changes between those dates.
The timeline view tracks:
- Secure Score (0–100%) over time.
- Azure Advisor Score and its Cost, Security, Performance, Reliability, and Operational Excellence pillars over time.
- Resources (your footprint) over time.
- Recommendations over time, including Unique recommendations and Spotto (custom) recommendations.
- Recommendation categories over time (Cost, Security, Reliability, etc.) so you can see where things are rising or falling.
The comparison view highlights:
- Secure Score, Advisor Score, and 30 Day Cost changes.
- Recommendation backlog changes, including added, removed, and changed recommendations.
- Impacted resource changes, so you can see whether a recommendation now affects more or fewer resources.
- Category filtering, such as focusing on Security when investigating a secure score movement.
Quick definitions (so charts make sense)
- Recommendations: Total recommendation volume over time (your backlog trend).
- Unique Recommendations: Recommendations de-duplicated by ID (a single recommendation affecting many resources is counted once).
- Spotto Recommendations: Recommendations created by Spotto (custom guidance), shown alongside provider-native guidance.
Why use this? (Jobs, pains, gains)
Jobs to be done
- When we ship security work, I want to see secure score trend lines, so I can validate that posture is improving (not just “we closed tickets”).
- When recommendation volume changes, I want to see what’s increasing or decreasing, so I can focus attention on the right category (often Security and Cost).
- When we manage multiple subscriptions, I want to compare trends across subscriptions, so I can spot outliers and prioritize the worst offenders.
- When a score changes between two reporting periods, I want to compare the before and after state, so I can explain what drove the movement.
Common pains
- Secure score snapshots are easy to find; secure score history with context is harder.
- Recommendation backlogs can grow quietly until you’ve got a “why is this so bad?” meeting on your calendar.
- Multi-subscription environments make it hard to tell whether improvements are real or just averaged out elsewhere.
What you gain
- A fast “are we improving?” view that combines posture + workload + guidance in one place.
- Better prioritization by seeing which categories (Security, Cost, Reliability, etc.) are trending up or down.
- Evidence for planning: you can see whether recommendations are being addressed, piling up, or holding steady over time.
- Clear month-to-month reporting: compare the current month with a previous month and show the changes behind the score.
Turn the evidence into a decision
Select the labelled briefcase Business Value button beside Notes. The brief combines live Secure Score, recommendation-backlog, resource, and period-delta evidence with an improvement decision.
The displayed movement remains live and does not prove causation. Generate tailors only the narrative for permitted users and saves it to the exact scope. Clear removes that saved narrative and immediately restores the standard Business Value content without deleting Customer Context or changing live facts. Regenerate when evidence changes. Above 100 subscriptions, the curated live brief remains available without tailoring.
Current position and priority work
Investigate sustained security regressions or backlog growth rather than reacting to one snapshot. Confirm what work caused improvement, then set measurable targets and a review cadence for the indicators leadership will use.
Business outcomes
Trend review shows whether cloud posture is genuinely improving rather than reporting isolated snapshots. It helps customers connect funded work to sustained movement in score, resources, and recommendation backlog.
Cost of delay
A growing backlog or declining posture can become normalized when snapshots are viewed in isolation. Customers may continue funding activity without being able to demonstrate improvement or explain regressions.
Decision required
Approve the target measures, accountable owners, improvement actions, and date leadership will review progress or accept the trend.
Validate with stakeholders
When you can manage Company Notes, select any question in the portal to retain the answer in the relevant Customer Context note.
- Which trend represents a meaningful business or risk outcome?
- What environmental changes explain the movement?
- What target, owner, and review cadence should govern improvement?
Key capabilities
Where to find it
In the Spotto Portal, open your company and navigate to Investigate -> Monitor -> Trend Tracker.
Select one or many subscriptions
Use the subscription picker at the top of the page to select one or more ready subscriptions. Trend Tracker will plot a separate line per subscription so you can compare them directly.
Switch metrics without changing context
The timeline chart lets you switch between:
- Secure Score
- Azure Advisor Score
- Azure Advisor Score: Cost
- Azure Advisor Score: Security
- Azure Advisor Score: Performance
- Azure Advisor Score: Reliability
- Azure Advisor Score: Operational Excellence
- Resources
- Recommendations
- Unique Recommendations
- Spotto Recommendations
This makes it easy to correlate changes. Example: a sudden recommendation increase might coincide with a resource spike or a posture dip.
See where recommendations are rising or falling
The category chart shows recommendation totals by category over time (stacked), which is useful for spotting:
- Categories where backlogs are growing (attention needed).
- Categories where work is paying off (totals trending down).
You can toggle the category chart between All recommendations and Spotto recommendations.
Compare two snapshots
Open the Compare Snapshots tab when you need to explain what changed between two points in time.
- Choose a History cadence: Daily, Weekly, or Monthly.
- Select the subscription you want to review.
- Choose the Compare from and Compare to snapshots.
- Review Score and spend for Secure Score, Advisor Score, 30 Day Cost, and security recommendation changes.
- Review Backlog and resources for recommendation volume, impacted resources, total resources, and Max Monthly Savings.
- Use Recommendation changes to see which recommendations were added, removed, or changed.
- Use the Category filter to focus the recommendation lists, for example on Security or Cost.
Changed recommendations show how the affected resource count moved between the two snapshots, which helps explain whether the same recommendation became more or less significant.
What Spotto compares
| Area | Details |
|---|---|
| Scores | Secure Score and Advisor Score for the selected subscription. |
| Cost | 30 Day Cost movement and potential monthly savings where available. |
| Recommendations | Added, removed, and changed recommendations, including category, impact, and affected resource count changes. |
| History range | Recent daily snapshots, weekly snapshots, and monthly snapshots when enough history is available. |
| Multiple subscriptions | The Timeline view can compare multiple subscriptions. Compare Snapshots focuses on one subscription at a time so the recommendation changes are clear. |
How it differs from Azure-native views
Azure-native tooling can show secure score and recommendations, but Trend Tracker is optimized for the “trend + action” loop:
- It puts secure score history, recommendation trends, and category trends together.
- It supports comparing multiple subscriptions in one workflow.
- It can compare two retained snapshots and show the recommendation changes behind the movement.
- It surfaces Spotto recommendations alongside provider-native guidance so you can see what additional lift Spotto is providing.
How it works (high level)
- Spotto keeps recent daily, weekly, and monthly snapshots for each subscription.
- Trend Tracker fetches that history and renders:
- A per-subscription timeline for the selected metric.
- A category timeline based on recommendation summaries.
- A comparison view between two selected snapshots.
- The Spotto mode in the category chart is an estimate based on how many Spotto recommendations exist at each point in time (because the per-category breakdown may not be available for Spotto-only recommendations).
Limitations (honest, boring, useful)
- Trend Tracker isn’t real-time. It depends on successful subscription syncs and the history they produce.
- If a subscription is new, you’ll see empty states until enough history exists.
- Compare Snapshots needs at least two retained snapshots for the selected cadence.
- The Spotto category view is an estimate, because Spotto-only recommendations may not have a full category breakdown available in history.
Troubleshooting
“No ready subscriptions available”
What you’re seeing: The Trend Tracker page shows an empty state. Likely causes:
- No subscription has completed syncing yet.
- Subscriptions are present but not marked ready.
How to fix:
- Confirm the subscription sync has completed successfully.
- Wait for ingestion to populate history, then refresh Trend Tracker.
Timeline shows “No timeline data is available yet”
What you’re seeing: The chart renders a “no data” state for the selected metric. Likely causes:
- Not enough history has been collected (common for newly added subscriptions).
- History exists, but not for the metric you selected.
How to fix:
- Switch the metric selector to Secure Score or Recommendations and check again.
- Revisit after the next successful sync(s) so more daily points are available.
Compare Snapshots shows “Not enough history snapshots”
What you’re seeing: The comparison tab cannot compare the selected cadence yet. Likely causes:
- The subscription is new.
- The selected cadence does not yet have two retained snapshots.
How to fix:
- Try another cadence, such as Daily if Monthly history is not available yet.
- Revisit after more subscription syncs have completed.
“Select a subscription to view trends”
What you’re seeing: The page asks you to select a subscription before it shows charts. Likely causes:
- No subscription is selected in the picker (common after clearing cookies or opening a bookmarked URL).
How to fix:
- Use the subscription picker to select one or more subscriptions.
- If every subscription is unavailable, confirm at least one subscription is fully synced and marked ready.
“Spotto” category view looks empty or unexpectedly low
What you’re seeing: Category totals in Spotto mode are much lower than All mode, or some categories show zero. Likely causes:
- Spotto recommendations are a smaller subset of total recommendations.
- Spotto category totals are estimated from overall Spotto vs total recommendation ratios.
How to fix:
- Compare the timeline Spotto Recommendations metric against total recommendations to sanity-check the ratio.
- Use All mode to understand the full backlog; use Spotto mode to understand the additional lift Spotto is adding.
Looking to enhance your cloud setup for cost efficiency, performance, reliability, or security?
Talk to a cloud specialist. Email us or schedule a 30-minute consultation and let's optimize your cloud environment together.
Book a Free Consultation