This is the template we would use, section by section, with example wording you can paste and adapt. It takes about fifteen minutes a month per site once the data collection is automated, and it is built to survive the moment a finance director asks what the retainer is for.
Download the template (.docx) — no email required. Copy it into Google Docs or Word and fill in the blanks.
The Eight Sections Clients Actually Read
| Section | What it answers | Keep it to |
|---|---|---|
| 1. Headline summary | Is my site fine? | 3 bullets |
| 2. Availability | Was it there when customers looked? | 1 line + a number |
| 3. Business flows | Could people buy, sign up, or contact us? | 1 line per flow |
| 4. Updates applied | What changed, and did anything break? | A short table |
| 5. Backups & security | Am I protected? | 2 lines |
| 6. Speed & experience | Is it getting slower? | 1 number + direction |
| 7. What we did this month | Where the hours went | 3–6 bullets |
| 8. Recommendations | What should we do next? | 1–3 items, priced |
If a client only reads the first section, they should still know whether to worry. Everything below it is evidence.
1. Headline Summary
Three bullets, written last, in the client's language.
September 2026 — everything is healthy. The site was available 99.98% of the month, checkout and the contact form were tested throughout and worked, and 14 updates were applied with no issues. One recommendation this month: the checkout page has slowed by 0.4s since the July theme update — we suggest 2 hours of image work to fix it.
Avoid "no issues to report". It reads like nothing happened, which makes the invoice look expensive.
2. Availability
One number and one sentence of context. Clients do not know whether 99.9% is good.
Uptime: 99.98% (about 9 minutes unavailable across the month, in one incident on 12 September at 03:14, resolved automatically in 9 minutes. No visitors reported problems.)
If you had a real outage, say so plainly, with what you did. A report that only ever says everything is fine is one bad month away from being disbelieved.
3. Business Flows
This is the section that justifies the retainer, and the one most reports skip. Uptime says the server answered; this says customers could act.
Checkout: tested every 15 minutes, 2,976 runs, all successful. Contact form: tested hourly, all successful — one failure on 3 September was a temporary mail-server timeout that cleared on the next run. Customer login: tested hourly, all successful.
If you do not monitor flows yet, this is the single highest-value thing to add to a care plan: it turns a report about maintenance into a report about revenue.
4. Updates Applied
A table, not a list of version numbers. Group by what the client might notice.
| What was updated | Count | Result |
|---|---|---|
| WordPress core | 1 | No issues |
| Plugins | 11 | No issues |
| Theme | 1 | Layout checked after update, no visual changes |
| Skipped deliberately | 1 | WooCommerce Stripe 8.2 held back — known conflict, scheduled for next month |
The "skipped deliberately" row is worth more than the rest of the table. It shows judgment rather than button-pressing.
5. Backups and Security
Two lines. No security theatre.
Backups: daily, retained 30 days, last restore test 4 September (successful). Security: 0 malware detections, 412 blocked login attempts, SSL valid until 14 December 2026 (auto-renewing).
Restore tests matter far more than backup counts. A backup nobody has restored is a hypothesis.
6. Speed and Experience
One number, its direction, and what you plan to do about it.
Homepage load: 1.9s (was 1.8s in August). Checkout: 3.1s (was 2.7s in July — see recommendation below).
Trends beat absolutes. A client cannot judge 1.9 seconds, but "slower than last month, here is why" is a conversation.
7. What We Did This Month
Where the hours went, in plain language. Bullets, no jargon.
- Applied and verified 14 updates across core, plugins and theme
- Investigated and fixed the 3 September contact form failure
- Added two new product pages and updated the autumn banner
- Replaced 18 oversized images on the blog
- Reviewed monitoring alerts daily
8. Recommendations
One to three items, each with a reason, an effort estimate and a price. This is where next month's work is sold, and it is the part clients skip if it reads as upsell.
- Fix checkout image sizes — 2 hours. Checkout has slowed 0.4s since July; oversized hero images are the cause. Faster checkout, fewer abandoned carts.
- Add monitoring for the newsletter signup — included in the current plan. It is currently unmonitored, so a failure would go unnoticed until signups dried up.
- Plan the PHP 8.4 upgrade — 4 hours, next quarter. The host retires PHP 8.1 in March.
What to Automate
The report should be assembly, not research. Most agencies lose an hour per site because they are gathering numbers by hand on the last Friday of the month.
- Uptime and incidents: from your monitoring tool, not from memory.
- Flow results: from scheduled journey checks on checkout, forms and login.
- SSL and domain expiry: pulled automatically; never a manual diary entry.
- Updates applied: exported from your management tool.
- Speed numbers: the same measurement, same page, same time of day, every month — otherwise the trend is noise.
- Screenshots: a before-and-after of the homepage or a key page after a big update, which is the one visual clients always respond to.
NorthDuty can produce the availability, flow, SSL and visual-change parts on a schedule — scheduled reports are built for exactly this handover — so the only writing left is sections 1, 7 and 8, the parts that need a human.
How Often, and Who Reads It
Monthly suits most care plans. Quarterly works for small brochure sites, and weekly is usually a sign the client does not trust the arrangement yet — in which case fix the trust, not the frequency.
Send it to the person who signs the invoice, not only to the marketing contact. The whole point of the report is that the person deciding whether to renew sees what they are getting.
A Note on Length
Two pages. If it runs longer, it is being written to justify the price rather than to inform, which has the opposite effect. Put the detail in an appendix or a dashboard link, and keep the report itself something that can be read on a phone between meetings.