> ## Documentation Index
> Fetch the complete documentation index at: https://docs.onefirewall.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Passed vs Denied

> The same enforcement split as a radial chart, with severity broken out inside both the passed and denied branches

<img style={{ borderRadius: '0.5rem' }} src="https://mintcdn.com/onefirewall/XtQuNxdDTqAwCnod/images/case20.png?fit=max&auto=format&n=XtQuNxdDTqAwCnod&q=85&s=04c229a48ddaa8066baeeef8c529ffad" width="1026" height="778" data-path="images/case20.png" />

This radial chart lays out the same two branches covered elsewhere in this report — traffic passed by Demo Org and traffic denied by Demo Org — but keeps the severity bands visible inside both, rather than only inside the passed branch.

***

## Two branches, same severity scale

The outer green band on the right is traffic passed by Demo Org's firewall. The segmented band on the left is traffic denied by Demo Org, broken into the same Low, Medium, High, and Critical bands used throughout this analysis, with **425** Critical and **245** High events called out specifically. Both branches are scored using the same Crime Score thresholds, which is what makes it possible to compare severity across an enforcement boundary instead of only within one side of it.

## The thin green segment

A narrow green slice sits at the boundary between the two branches — a small amount of already-denied traffic that OneFirewall's scoring also assessed as clean. It's a minor share of the total, and it functions as a cross-check on the existing rule set rather than a finding that needs action: traffic the firewall blocked and OneFirewall independently agrees was not malicious.

## Why the same data appears twice in this report

This chart and the enforcement-split donut cover the same underlying numbers from different angles. The donut answers "how much was passed versus denied." This one answers "how severe was the traffic on each side of that decision," which is the detail a flat pass/deny ratio doesn't carry on its own.

***

Proof of Value engagements produce this same breakdown against a client's own firewall decisions. [Start a Proof of Value](https://onefirewall.com/proof-of-value).
