Compliance Benchmarks harden your fleet, but many rules change what your end users see and do on their devices, how they log in, which features are available, and in some cases whether they can log in at all. Addigy now labels every rule with the kind of disruption it causes, explains that impact in plain language, and warns you before you assign a benchmark that will disrupt users.
This article covers where those labels appear, what each one means, and how to read the disruption summary you see at assignment time.
How It Works
Every rule in a benchmark is evaluated for its effect on the person using the device, and carries two pieces of information:
- A disruption type: the kind of change the user experiences, shown as a badge on the rule.
- A severity: High, Medium, or Low, reflecting how much the change affects the user. The badge's color carries the severity: red for High, yellow for Medium, grey for Low.
This means a single badge tells you both things at once. A red Lockout badge and a grey Restriction badge name different kinds of change and different levels of concern.
Alongside these, each rule has an end-user impact description explaining in plain language what will actually change. You see this information in two places: while browsing a benchmark's rules, and again as a warning when you assign the benchmark to a policy.
Monitoring a benchmark's rules does not change anything on a device. A rule only alters a device when its remediation runs.
Reviewing Rules in a Benchmark
- Navigate to Catalog → Compliance.
- Click the benchmark you want to review, then open its details to display the Benchmark Controls dialog.
- The dialog lists every rule in the benchmark with its disruption badge on the right.
- Expand any rule to read its end-user impact description.
From this dialog you can also select Create clone if you need only a subset of the rules, or Assign to policies... when you are ready to deploy.
The End-User Disruption Warning
When you assign a benchmark containing disruptive rules, a Warning: End-User Disruption dialog appears before the assignment completes. It summarizes the impact and asks you to confirm.
Select I understand to proceed with the assignment, or Cancel to back out and adjust the benchmark first.
Disruption Types
| Badge | What the user experiences |
|---|---|
| Lockout | The user can lose access to the device or account entirely. The highest-stakes category. |
| Restriction | A feature stops working, iCloud services, AirDrop, external storage, screen sharing, and similar. Typically the largest category in a benchmark. |
| Notification | New prompts, banners, or permission dialogs appear. Users notice, but keep working. |
| Interruption | The user's work is interrupted, such as being logged out or having the screen lock. |
| Restart | The device must restart for the rule to take effect. |
The same disruption type can appear at different severities depending on the rule. A Restriction that blocks external storage is more disruptive than one that changes an AirDrop default, so the two carry the same badge in different colors.
Severity
| Severity | Badge color | How to treat it |
|---|---|---|
| High | Red | Review individually before assigning. These are the rules most likely to generate support tickets or lock users out. Give each an explicit go / no-go decision. |
| Medium | Yellow | Users will notice and may need to change habits. Announce these to end users ahead of the rollout. |
| Low | Grey | Generally safe to assign, but worth scanning so nothing surprises the help desk. |
A Rollout That Keeps the Help Desk Quiet
- Read the warning, don't dismiss it. The disruption dialog is the fastest inventory of what your users will feel.
- Start in monitor only. Assign with remediation disabled or manual first. You see exactly which devices each rule would touch, with zero end-user impact.
- Pilot on a test policy. Enable remediation for IT's own devices plus a few friendly users, and live with it for at least a week.
- Tell end users what's coming. A two-line heads-up prevents most tickets. Send it before the rollout, not after the first complaint.
- Expand in rings. Roll out policy by policy, reviewing compliance status between rings. A rule that will not remediate on certain hardware is a signal to check its conditions.