Ask for a direction, not a total
Total breaches rises when you add rules and falls when you disable them. It measures the instrument, not the process.
Ask for the measure that reflects whether the process is improving, and stop rewarding the one that improves when enforcement weakens.
Total breaches is what gets reported by default, and it responds to things that have nothing to do with data quality. Adding rules raises it. Disabling a rule lowers it. Tightening a scope lowers it again. Every one of those is a change to how you are measuring, not to what you are measuring.
The incentive that creates is the reason to care as a leader. If total breaches is the number you ask about, the cheapest way for a team to improve it is to enforce less, and that will not be presented as enforcing less. It will be presented as retiring a noisy rule, which is sometimes genuinely correct, and which you have no way to distinguish from quiet retreat if the total is all you see.
Ask instead whether the backlog is trending down, and whether new breaches are arriving more slowly than existing ones are cleared. That is a single sentence. It is easy to answer if the team is measuring properly, and it does not improve when enforcement is weakened, disabling a rule removes items from both sides of the comparison.
Ask for one more thing alongside it: the log of rule changes over the same period. A trend line without the changes that affected it is uninterpretable, and requesting both routinely makes the reporting honest by construction rather than by good intentions. It also tells you something useful about how actively the rule set is being tuned.

The first report says: open exceptions are down from 1,400 to 900, a 36% improvement. It is a good-looking slide and it is almost content-free.
The second report says: open exceptions fell from 1,400 to 900; new breaches arrived at roughly 200 a week and were resolved at roughly 320 a week; two rules were rescoped in week three and one was disabled in week six; the oldest open breach is now 74 days and there are 140 older than 30 days, up from 90.
The second version supports a decision and the first does not. Resolution outpacing arrival means the process is genuinely improving rather than the team having had a clear-out. The disabled rule in week six explains part of the fall and is exactly what a reader needs in order not to over-credit the improvement. And the growing tail of old breaches says that while the overall picture is good, a specific category is not being worked, which is a concrete thing to go and fix next quarter.
None of that costs more to produce than the first version. It is the same data, reported in a way that cannot be improved by enforcing less.
You should be able to answer each of these from memory before opening it. Recalling the answer is what makes it stick; recognizing it when you read it does not.
The cheapest way to improve the number is to enforce less, and that will not be presented as enforcing less. It will be presented as retiring a noisy rule, which is sometimes correct and which you cannot distinguish from retreat if the total is all you see.
The rule-change log for the same period. A trend line without the changes that affected it is uninterpretable, and asking for both routinely makes the reporting honest by construction.
Total breaches rises when you add rules and falls when you disable them. It measures the instrument, not the process.
"Is the backlog trending down, and are new breaches arriving more slowly than we clear them?" That is one sentence and it cannot be gamed by disabling a rule.
A trend without the changes that affected it is not interpretable — and requesting both makes the metric honest by construction.
See agents carry the repeatable work of GTM across sales, marketing, customer success, and RevOps. Every action prepared, reviewed, and recorded. Fictional data, real product.
Explore the demo