CommandThe Practice Console One console · Every client · One analyst
CommandSeat 02 · Practice Console

Run a dozen programs.
From one console.

You run security for a dozen companies. Stop re-deriving the same status across a dozen spreadsheets the night before every QBR. Every client's program stays live in one place, and Hudson tells you which one needs you today.

See the console

Fig. 01 · Practice Console · the client book

The Practice Console showing every client program side by side with maturity, trend and open criticals

A dozen clients means a dozen spreadsheets. Status gets re-derived by hand the night before every QBR, and the program that is slipping hides in a tab nobody opened. The Practice Console keeps every client's program live in one place, with the one that needs you today already at the top.

§ 01The book

Every client's program,
side by side.

Maturity, 30-day trend, open criticals and audit status on one screen, normalized so a 3.2 at one client means the same thing as a 3.2 at another. Sorted by what is slipping, not alphabetically.

Practice Console Client book
11 active programs · 2 need youClient book
3.2/5book average
ClientMaturity30dCriticalsStatus
NPNovaPayFintech · SOC 22.8▼ 0.34 openNeeds you
VHVireo HealthHealthtech · HIPAA2.4▼ 0.32 openNeeds you
LYLoomyardSaaS · ISO 270013.9▲ 0.20 openHealthy
CTCedar TrustBanking · CIS v83.2▲ 0.31 openHealthy
HPHapworthLogistics · NIST CSF3.6▲ 0.10 openOn track
Hudson
§ 02Risk stories

The QBR narrative,
already written.

Hudson reads every assessment, finding, trend and peer benchmark for each program, then writes the story in plain English. Not a score with no explanation. The paragraph you were going to have to write yourself on Sunday night.

Practice Console Risk stories
3 programs need attentionRisk stories
NovaPay2.7 / 5GradeC

Four critical findings are still open and the program sits at 2.7 out of 5, below where it should be for a SOC 2 commitment. Detection and response are the weakest areas, and nothing has improved in the last 30 days. This one needs attention before the next client review.

Review findings →Raise concern →
Vireo Health2.4 / 5GradeD

Vireo is going backwards. The program slipped 0.3 points last month to 2.4 out of 5, with two criticals still open. Every domain is weak in the same way, so this is a broad capability gap rather than a one-off.

Review findings →Raise concern →
§ 03Across the book

Go deeper
on any signal.

Four questions come up in every practice: who is behind on which framework, what work is rotting in a client backlog, what the outside world can see, and who moved this month. All four read across the whole book, not one client at a time.

Practice Console Framework coverage
Every client, every frameworkCoverage
ClientNISTISOCISSOC 2
LYLoomyard94%88%81%96%
HPHapworth86%79%68%90%
CTCedar Trust78%64%61%82%
NPNovaPay41%22%30%52%

Coverage, every framework, every clientOne matrix of how far each client has gotten against everything they are held to, so the gap stands out without opening a file.

Practice Console Action queue
Across every clientAction queue
15overdue
NPNo documented offline backup testNovaPay71d
LYNo backup recovery runbookLoomyard66d
NPDMARC policy still at p=noneNovaPay61d
VHBackup restore untested in 14 monthsVireo Health55d

The overdue work, across the bookEvery overdue finding from every client in one queue, ranked by age, so nothing rots in a backlog you do not open weekly.

Practice Console External monitoring
Loomyard · updated 3d ago · monitor onlyAttack surface
86score
SSLB
HeadersA+
DNSA+
EmailB
No threats detected
Posture score
Subdomains 62Open ports 26

What the outside world seesContinuous external scans on every program: SSL, headers, DNS, email posture and breach signals, scored and tracked without touching the client's network.

Practice Console Risk movers
Last 30 daysRisk movers
Improving
Cedar Trust2.9 → 3.2+0.3
Loomyard3.7 → 3.9+0.2
Degrading
Vireo Health2.7 → 2.4−0.3
NovaPay3.0 → 2.8−0.2

Who moved, this monthMomentum surfaced on its own, so a slipping program is visible weeks before the review, not at it.

§ 04Assessments

The assessment
that writes itself.

Walk any client's framework out loud on the call you were already having. Command transcribes, drafts the status and maturity for every control, and pulls the evidence it already holds. You review instead of type, and the report is done when the call ends.

NovaPay SOC 2 CC6.1 Access controls
Listening · 14:32Rec
Analyst

How do you manage and review access to production systems?

Client · CISO

Access is provisioned through Okta with role-based groups, and we run a quarterly access review with system owners.

Analyst

Is the quarterly review documented anywhere?

Client · CISO

Yes, the Q2 review is signed off in Command with the owner attestations

Ambient capture · nobody is taking notes

Hudson · drafting

Access is provisioned via Okta with role-based groups. A quarterly access review is performed with system owners and signed off in Command with owner attestations.

Suggested statusMet
Maturity4.0
Evidence pulled · 1
Q2-Access-Review.pdfJun 26
ApproveOverride
§ 05Other seats

Same record.
Different chair.

The Practice Console is one of three seats on the same program model. Nothing is rebuilt when a client grows into their own team, or when a sponsor wants the portfolio view.

§ 06Next

Bring your book.
We will run it.

Tell us how many clients you carry and which frameworks they are held to. We will walk through what your book looks like in the Practice Console, with your material rather than a demo tenant.

Command overview