What a good monthly report from your web partner looks like

One page, five minutes, written for the owner. The six sections a monthly report should contain, what each proves, and the reports that are theatre.

3 minread 588words last updated

The short answer

A monthly report has two jobs: to prove that the routine that keeps your site healthy actually happened, and to make one recommendation for what to do next. It should be one page, written for the owner rather than for a developer, and readable in five minutes. Anything longer is either padding or a different document.

If you have never received one, the routine is probably not happening either.

The six sections

SectionWhat it containsWhat it proves
1. What was doneUpdates applied, changes shipped, fixes made, in plain languageThe routine ran; the change budget was used
2. What monitoring foundAlerts, outages, form failures, certificate or DNS events, and what was done about eachSomeone is watching, and reacting
3. Security and recoveryScan result and what was fixed; the recovery route and when it was last proven, by restore test or by rollbackThe site is secure and recoverable, with evidence
4. The numbersVisits and sources, conversions or submissions, mobile Core Web Vitals, search impressions and clicks, uptime, each with last month beside itThe site is doing its job, and the direction
5. Change budgetUsed, remaining, what is queuedYou know what you are getting and what is next
6. RecommendationOne thing worth doing next, with the reasonThe partner is thinking about your business, not just maintaining it

Reports that are theatre

  1. The analytics dump. Forty pages of screenshots from the analytics tool. Proves the tool exists. Says nothing about whether anyone maintained the site.
  2. The vanity number. Visits went up. Without sources, conversions and a trend, it is a number, not information.
  3. The green dashboard. A status page showing uptime. Uptime is one line; the routine is the rest.
  4. The invoice with prose. A list of hours by task. That is billing, not reporting.
  5. The absent report. Nothing arrives, and everything is “fine”. Fine is not evidence.

Why one page changes decisions

A page that arrives on the first working day of the month, that the owner reads with coffee, that ends with one recommendation, gets acted on. Decisions about the site get made monthly instead of yearly, small problems are caught while small, and the change budget goes to things that matter because the numbers are in front of the person deciding.

What this means for you

Ask your current partner for last month’s report. If it is one page with the six sections, you are well served. If it is long, empty of evidence, or does not exist, that is your answer about whether the routine is happening, and the first thing to change.

Written by the CivSec S.M.A.R.T team

We build and run websites, software and AI systems for businesses. We write about what we see in that work, in plain language, and we update articles when things change.

Last checked . Spotted something outdated? Tell us.

Frequently asked questions

Why one page? Our previous agency sent detailed reports.

Detail is useful when someone reads it. A report the owner actually reads, every month, changes decisions. A long report full of charts gets skimmed once and filed. The detail can exist behind the page for anyone who wants it; the page is what gets read.

What numbers should be in it?

The few that reflect the site doing its job: visits and where they came from, form submissions or conversions, mobile Core Web Vitals, search impressions and clicks, uptime. Each with last month next to it, so the direction is visible. Not every metric the tools can export.

What if nothing happened this month?

Then the report says so, and lists the routine that ran: updates applied, scans clean, backups tested, monitoring quiet. A quiet month is the routine working. It should still produce a page, because the page is the evidence.