Report rate is the proportion of employees who correctly report a suspicious message instead of simply ignoring or clicking it. It is a stronger indicator of security maturity than click rate alone because it measures active detection behaviour, response readiness, and whether training is translating into practical action.
Expanded Definition
Report rate measures the share of users who escalate a suspicious message through the approved reporting path instead of ignoring it or interacting with it. In NHI and agentic AI environments, the same idea applies to how reliably people surface suspicious prompts, token requests, or unusual workflow behaviour before an automated action is taken. It is a behavioural control signal, not a proof of technical control.
Definitions vary across vendors because some programs treat report rate as a phishing metric, while others broaden it to cover all user-reported security alerts. NHI Management Group treats it as a practical indicator of detection readiness and human-to-system feedback quality, which complements controls in the NIST Cybersecurity Framework 2.0. Used well, it reveals whether training, reporting paths, and response culture are functioning together. The most common misapplication is treating a high report rate as evidence of strong security when the reported messages were trivial, expected, or repeatedly flagged without any follow-up workflow.
That distinction matters because report rate should reflect meaningful suspicion, fast escalation, and a usable reporting channel, not just repetitive clicking of a button in a simulation.
Examples and Use Cases
Implementing report rate rigorously often introduces measurement noise, because an organisation must distinguish genuine suspicion from curiosity, habit, or campaign familiarity, so leaders must weigh cleaner metrics against the operational cost of deeper triage.
- A finance team receives a credential-harvesting email and employees use the in-mail report function before any link is opened, showing fast detection behaviour rather than passive avoidance.
- A security awareness program tracks whether staff report unusual OAuth consent prompts or AI-generated invoice requests, using the signal to update both training and detection logic.
- An SOC correlates employee reports with mailbox telemetry and identity logs to see whether suspicious activity was flagged before token theft or account takeover progressed.
- An organisation compares report rate across departments to identify where reporting paths are poorly understood, then adjusts guidance and reinforces escalation procedures.
- After reviewing lessons in the Ultimate Guide to NHIs, a team extends reporting awareness to service account anomalies, secret exposure, and unexpected API use.
These use cases align with the broader reporting and response emphasis in NIST Cybersecurity Framework 2.0, where rapid identification and communication improve containment.
Why It Matters in NHI Security
Report rate matters because many identity incidents start as something a person notices first: a strange login prompt, an unexpected approval request, or an agent behaving outside its normal bounds. In NHI security, the human signal often arrives before automated monitoring catches up. NHI Management Group research shows that 79% of organisations have experienced secrets leaks, and 77% of those incidents caused tangible damage, which makes early reporting a practical defence layer rather than a soft metric.
It is also useful because compromised NHIs often blend into normal operations. A user who reports unusual activity can surface token abuse, misrouted automation, or exposed credentials long before the issue becomes systemic. That is why report rate should be read alongside visibility, incident handling, and response speed, not as a standalone score. The Ultimate Guide to NHIs highlights how weak visibility and poor secret handling magnify exposure, and those conditions usually become obvious only after a suspicious event is finally escalated.
Organisations typically encounter the real cost of low report rate only after a phishing message, token leak, or agent misuse has already spread, at which point reporting becomes operationally unavoidable to contain the incident.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10 and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | RS.AN-1 | Report rate supports timely detection and escalation of suspicious events. |
| OWASP Agentic AI Top 10 | L2 | Human reporting becomes critical when agents receive suspicious prompts or actions. |
| OWASP Non-Human Identity Top 10 | NHI-06 | Security reporting improves visibility into compromised or misused NHI activity. |
| NIST SP 800-63 | Identity events depend on trustworthy user interaction and escalation paths. |
Teach users to report unusual agent behaviour and blocked prompt patterns quickly.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 23, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org