GUIDE 2026

PMs & Metrics: North Star Metrics

Because product managers fill in the white space between customers, the business, and the development team, product managers are always flooded with qualitative information – ranging from complaints to quotes to praise to anecdotes.

To successfully manage the chaos, product managers rely on metrics to aggregate information. That way, they can easily digest and diagnose the flood of information that they’re getting.

Yet even then, product managers can still be swamped with too many metrics. Given that product managers must prioritize, how do they make sense of the world around them?

The most successful product managers rely on a single north star metric (NSM) and a counter metric.

A north star metric measures the most critical outcome of success for the product.

A counter metric ensures that this improvement didn’t come at the expense of an equally important outcome.

Below, I’ll discuss how to select a north star metric that makes the most sense for you and your product.

Then, in a later article, I’ll discuss how to select a compelling counter metric, as well as how to pull them both together so that you can enable your stakeholders to strive towards true success.

North Star Metrics

Pioneers of the past used the North Star in the night sky to navigate their way through treacherous, uncharted territory.

Waarom Speeltips e-wallets veiliger acht dan bankoverschrijvingen bij online casino’s

Bij het kiezen van een betaalmethode voor online casino’s gaat het niet alleen om gemak of snelheid. Veiligheid speelt een doorslaggevende rol, zeker wanneer het gaat om financiële transacties in een omgeving waar gevoelige persoonsgegevens en bankgegevens in het spel zijn. De discussie tussen e-wallets en traditionele bankoverschrijvingen is dan ook niet nieuw, maar wordt steeds relevanter naarmate het online goklandschap zich verder ontwikkelt. Wie de twee methoden naast elkaar legt, ziet al snel dat ze fundamenteel van elkaar verschillen in hoe ze omgaan met gegevensbeveiliging, fraudepreventie en gebruikersanonimiteit. Speeltips heeft dit onderwerp uitvoerig onderzocht en concludeert dat e-wallets in de meeste gevallen een aanzienlijk veiliger alternatief bieden voor spelers die regelmatig bij online casino’s actief zijn.

Hoe bankoverschrijvingen werken en waar de kwetsbaarheden liggen

Een bankoverschrijving is in essentie een directe verbinding tussen de bankrekening van de speler en de financiële infrastructuur van het online casino. Wanneer een speler een storting doet via een bankoverschrijving, worden daarbij vrijwel altijd volledige bankgegevens gedeeld: het IBAN-nummer, soms de BIC-code, en in sommige gevallen aanvullende identificatiegegevens. Deze gegevens worden opgeslagen in de systemen van het casino, en dat is precies waar een van de grootste risico’s schuilt.

Online casino’s opereren onder verschillende jurisdicties. Hoewel veel platforms gelicenseerd zijn door erkende autoriteiten zoals de Malta Gaming Authority (MGA) of de UK Gambling Commission, zijn er ook platforms die opereren onder minder strenge regelgevingen, bijvoorbeeld vanuit Curaçao. De beveiligingsnormen voor gegevensopslag variëren aanzienlijk per jurisdictie. Een casino dat gelicenseerd is in Curaçao is niet gebonden aan dezelfde strikte databeschermingsregels als een platform dat onder de Europese AVG (Algemene Verordening Gegevensbescherming) valt. Dit betekent dat bankgegevens die bij zo’n platform worden achtergelaten, mogelijk minder goed beschermd zijn tegen datalekken of ongeautoriseerde toegang.

Daarnaast is er het probleem van chargeback-fraude en ongeautoriseerde transacties. Wanneer iemand toegang krijgt tot de bankgegevens van een speler, kunnen er in theorie transacties worden geïnitieerd die moeilijk te traceren of terug te draaien zijn. Bankoverschrijvingen zijn doorgaans onomkeerbaar zodra ze zijn verwerkt. Dit in tegenstelling tot creditcardbetalingen, die een zekere mate van terugboekingsmogelijkheid bieden. De combinatie van directe bankgegevensoverdracht, variabele beveiligingsnormen en de onomkeerbaarheid van transacties maakt bankoverschrijvingen kwetsbaar in een online casinocontext.

Er is ook een praktisch nadeel: de verwerkingstijd. Bankoverschrijvingen kunnen twee tot vijf werkdagen in beslag nemen, afhankelijk van de betrokken banken en landen. Dit betekent dat spelers langer wachten op uitbetalingen, wat in een snel bewegende omgeving als online gokken als een aanzienlijk ongemak wordt ervaren. Maar los van het gemak, is de vertraagde verwerking ook een beveiligingsrisico: gedurende de verwerkingstijd zijn er meer momenten waarop een transactie kan worden onderschept of gemanipuleerd.

Hoe e-wallets een extra beveiligingslaag toevoegen

E-wallets zoals PayPal, Skrill en Neteller functioneren als een tussenpersoon tussen de bankrekening van de gebruiker en de externe partij, in dit geval het online casino. Dit klinkt misschien als een extra stap, maar die extra stap is precies wat de beveiliging versterkt. Wanneer een speler via een e-wallet een storting doet bij een casino, ziet het casino alleen een transactie afkomstig van het e-walletplatform. De onderliggende bankgegevens van de speler worden nooit gedeeld met het casino. Dit principe van gegevensisolatie is fundamenteel voor de hogere veiligheid die e-wallets bieden.

Skrill en Neteller, beide onderdeel van het Paysafe Group-ecosysteem, zijn gereguleerd door de Financial Conduct Authority (FCA) in het Verenigd Koninkrijk. Dit zijn dezelfde reguleringsstandaarden die van toepassing zijn op traditionele financiële instellingen. PayPal is eveneens gereguleerd als een elektronische geldinstelling in Europa en valt onder de Europese richtlijn voor elektronisch geld (EMD2), die in 2009 werd ingevoerd en in 2011 werd herzien. Deze regelgevingskaders verplichten e-walletproviders tot strikte beveiligingsprotocollen, waaronder tweefactorauthenticatie, encryptie van transactiegegevens en real-time fraudemonitoring.

Tweefactorauthenticatie (2FA) verdient hier bijzondere aandacht. De meeste gerenommeerde e-walletproviders hebben 2FA al jaren als standaardoptie beschikbaar, en sommige verplichten het zelfs. Dit betekent dat zelfs als iemand toegang zou krijgen tot de inloggegevens van een speler, er nog een tweede verificatiestap nodig is — doorgaans via een sms-code of een authenticator-app — voordat er een transactie kan worden uitgevoerd. Bij directe bankoverschrijvingen bestaat deze extra laag van verificatie in de meeste gevallen niet op transactieniveau.

Op speeltips.com wordt regelmatig geanalyseerd welke betaalmethoden door Nederlandse spelers als meest betrouwbaar worden beschouwd, en e-wallets scoren daarin consistent hoog, met name vanwege de combinatie van snelheid en beveiligingsniveau.

Een ander voordeel van e-wallets is de snelheid van uitbetalingen. Terwijl bankoverschrijvingen twee tot vijf werkdagen kunnen duren, worden uitbetalingen via e-wallets bij de meeste online casino’s binnen 24 uur verwerkt, en in veel gevallen zelfs binnen enkele uren. Dit vermindert niet alleen het ongemak voor de speler, maar verkleint ook het tijdsvenster waarin een transactie kwetsbaar is voor manipulatie of onderschepping.

Fraudepreventie en consumentenbescherming in de praktijk

Een van de meest onderschatte aspecten van e-walletveiligheid is de actieve fraudepreventie die deze platforms inbouwen. Bedrijven als PayPal en Skrill investeren jaarlijks tientallen miljoenen euro’s in machine learning-systemen die transactiepatronen in real-time analyseren. Wanneer een transactie afwijkt van het normale gedragspatroon van een gebruiker — bijvoorbeeld een ongewoon hoge storting vanuit een nieuwe locatie — wordt de transactie automatisch gemarkeerd en in sommige gevallen geblokkeerd totdat de gebruiker de transactie heeft bevestigd.

Dit soort proactieve fraudedetectie bestaat niet bij standaard bankoverschrijvingen. Banken hebben weliswaar hun eigen fraudedetectiesystemen, maar deze zijn doorgaans minder gespecialiseerd in de specifieke transactiepatronen van online gokken. Bovendien opereren banken vaak met een vertraging in hun detectiesystemen, wat betekent dat frauduleuze transacties pas worden opgemerkt nadat ze al zijn verwerkt.

Consumentenbescherming is een ander cruciaal punt. E-walletproviders die gereguleerd zijn door de FCA of vergelijkbare Europese autoriteiten zijn verplicht om klantfondsen gescheiden te houden van bedrijfsfondsen. Dit betekent dat het geld van de gebruiker in een afzonderlijke rekening wordt bewaard en niet wordt gebruikt voor de operationele kosten van het e-walletbedrijf. In het geval dat een e-walletprovider failliet zou gaan, zijn de fondsen van de gebruikers beschermd. Bij bankoverschrijvingen naar een online casino is er geen vergelijkbare bescherming: zodra het geld op de casinorekening staat, is het onderhevig aan de financiële gezondheid en het beleid van dat specifieke casino.

De Europese betaaldienstenrichtlijn PSD2, die in 2018 volledig van kracht werd, heeft de beveiligingseisen voor elektronische betalingen verder aangescherpt. PSD2 verplicht alle aanbieders van betaaldiensten, inclusief e-wallets, tot sterke klantauthenticatie (Strong Customer Authentication, of SCA) voor de meeste elektronische transacties. Dit houdt in dat betalingen moeten worden geverifieerd via ten minste twee van de drie factoren: iets wat de gebruiker weet (wachtwoord), iets wat de gebruiker heeft (telefoon of token), of iets wat de gebruiker is (biometrie). Hoewel PSD2 ook van toepassing is op traditionele banken, zijn de implementatie en handhaving bij gespecialiseerde e-walletproviders doorgaans strikter en consistenter.

Anonimiteit, gegevensbescherming en de AVG

Een aspect dat in discussies over betaalveiligheid bij online casino’s regelmatig onderbelicht blijft, is de kwestie van gegevensbescherming en privacy. Wanneer een speler een bankoverschrijving uitvoert, worden er persoonsgegevens gedeeld die verder gaan dan alleen het bankrekeningnummer. In combinatie met de KYC-procedures (Know Your Customer) die online casino’s verplicht zijn uit te voeren, betekent dit dat een aanzienlijke hoeveelheid gevoelige informatie bij het casino terechtkomt: naam, adres, geboortedatum, kopieën van identiteitsdocumenten, en bankgegevens.

E-wallets bieden hier een gedeeltelijke oplossing. De KYC-verificatie vindt in dat geval plaats bij de e-walletprovider, niet bij het casino. Het casino ontvangt alleen de bevestiging dat de e-walletrekening geverifieerd is, maar niet de onderliggende persoonsgegevens die bij die verificatie zijn gebruikt. Dit principe van minimale gegevensdeling is in lijn met de beginselen van de AVG, die in mei 2018 van kracht werd en die verplicht tot dataminimalisatie: er mogen niet meer persoonsgegevens worden verzameld dan strikt noodzakelijk voor het doel van de verwerking.

Speeltips heeft in meerdere analyses aangetoond dat spelers die e-wallets gebruiken, gemiddeld minder gevoelig zijn voor phishingaanvallen die gericht zijn op casinogebruikers. Dit is deels te verklaren door het feit dat hun bankgegevens simpelweg niet in de systemen van het casino aanwezig zijn, waardoor een datalek bij het casino geen directe toegang geeft tot de bankrekening van de speler.

Het is ook de moeite waard om te wijzen op de rol van encryptie. E-walletproviders gebruiken doorgaans 256-bit SSL-encryptie voor alle datatransmissies, wat de industriestandaard is voor financiële instellingen. Maar wat e-wallets onderscheidt, is dat ze ook encryptie toepassen op opgeslagen gegevens (data-at-rest encryption), iets wat niet altijd gegarandeerd is bij kleinere of minder gereguleerde online casino’s die bankgegevens opslaan.

Een interessante ontwikkeling in dit verband is de opkomst van open banking, dat in Europa wordt gestimuleerd door PSD2. Open banking maakt het mogelijk voor derde partijen om met toestemming van de gebruiker toegang te krijgen tot bankgegevens. Hoewel dit nieuwe mogelijkheden biedt voor betaaldiensten, brengt het ook nieuwe risico’s met zich mee als het niet goed wordt geïmplementeerd. E-wallets die al gevestigde beveiligingsprotocollen hebben, zijn beter gepositioneerd om van open banking te profiteren zonder de bijbehorende risico’s te introduceren.

Samengevat bieden e-wallets in de context van online casino’s een structureel hogere mate van beveiliging dan bankoverschrijvingen, niet vanwege een enkel kenmerk, maar vanwege een combinatie van factoren: gegevensisolatie, strikte regulering, actieve fraudepreventie, snelle transactieverwerking en een robuust kader voor consumentenbescherming. Bankoverschrijvingen blijven een legitieme betaalmethode, maar de directe blootstelling van bankgegevens aan de systemen van een online casino, gecombineerd met de trage verwerkingstijden en het ontbreken van een gespecialiseerde beveiligingslaag, maakt ze in dit specifieke gebruiksscenario minder geschikt voor spelers die prioriteit geven aan financiële veiligheid en gegevensbescherming.

Similarly, product managers are pioneers of uncharted territory, and they need to find their way to success by looking for clear signals in a sea full of noise.

That’s where the north star metric comes in.

The north star metric is the most critical, measurable, actionable business outcome for your product. In other words, it’s the one thing you can use to orient yourself towards product success – and therefore, success for your entire company.

Let’s break down each of the adjectives I mentioned.

The North Star Metric Must Be Critical

The north star metric should be critically important to your product’s mission, which then feeds into your company’s business model.

If your product is meant to make it easier for new users to onboard to the rest of your company’s product portfolio, it doesn’t make sense for you to anchor on the number of new users as your north star.

Rather, in this case, it makes far more sense for you to anchor on the total time it takes for new users to onboard, because that aligns with your product’s mission.

In other words, when selecting a north star metric, you need to be comfortable with acting as though it were the only piece of information you had about your product.

Based only on changes to your north star metric, how confident are you that you’re moving in the right direction? If you’re very confident, then you’ve picked a good north star metric. If you’re left with lots of questions and doubt, then you haven’t picked a good one yet.

Why am I purposefully limiting us to only a single metric for success? Couldn’t a product have many different levers to reach success?

It’s true that products have a variety of impacts. The problem is that if you use more than one metric, you’ll wind up getting distracted by noise.

Take it from my own personal experience! When I was an associate product manager for a SaaS B2B product, I used to have a dashboard that had 20 different metrics on it. I tracked metrics like conversion rates, new users, and churn rates.

Every day, I’d see some metrics go up and some metrics go down. And every day, I’d chase the metrics that had performed poorly. Rather than focusing on the one most important thing, I tackled a bunch of things that ultimately didn’t yield impact.

Because I hadn’t selected a single metric as the most important metric, I ran around chasing a bunch of self-inflicted “fires” that didn’t actually move my product towards the success of my customers and towards the success of my business.

I wasted engineering time, design time, product management time, and customer success time in going after random fluctuations rather than focusing on the sustainable growth of a single core metric.

The key is that while a product could have many different levers for success, these levers should all aggregate to the north star metric.

As an example, say that you own the onboarding product, and you’ve decided that your north star metric is “time it takes for a new user to successfully set up their user settings.”

You could measure a variety of things, for example:

  • The time it takes for a new user to move from the landing page to the user settings page.
  • The number of clicks they take within the user settings page.
  • The number of errors that appear when users attempt to save invalid settings.
  • The bounce rate for users on the settings page.
  • The percentage of users who reach the settings page that fails to customize the settings away from the default settings.

Each of these key performance indicators, or KPIs, might be something that you can control from optimizing your product.

But at the end of the day, all of these fold into the broader metric of “time it takes for a new user to successfully set up their user settings.”

So, now we understand why the north star metric needs to be the single most critical metric for your product.

As an aside, one thing to keep in mind is that the north star metric should not be a vanity metric. In other words, it shouldn’t be something that will grow over time no matter what you do.

For example, the total of signups or registrations that you have is not a north star metric, because it will always go upwards – it can’t possibly go down. People can’t “un-sign-up” from your product, so you don’t want to use that as your north star metric.

The North Star Metric Must Be Measurable

You’d be surprised at how many people make the mistake of selecting a north star metric that can’t be measured at all.

For example, let’s say that your product is a mobile app that focuses on increasing spoken English fluency for children. You decide that you want to measure an increase in the total of distinct words that each child can say without assistance.

How, exactly, would you measure this metric?

You can’t just turn on the microphone and record the child’s voice 24/7 without permission.

You can’t send a researcher to every single household that uses your product for a longitudinal spoken word study.

You can’t surface a sentence on the screen for the child to read out loud, because that would be assisting them with visual cues.

You can’t ask either the child or the parent to count out the number of words that the child knows how to speak because it’s highly likely that they’ll self-report incorrectly.

The problem doesn’t lie in the measurement of the metric, but rather in the selection of the metric itself. If you don’t have a good proxy for measurement, you can’t use that metric.

Let’s be absolutely clear – metrics are not reality. Metrics are human inventions that help us to approximate reality.

There are simply some things that you can’t measure because metrics are only tools to help us get close to reality.

So, let’s be less strict about the specific metric here, and loosen some of the requirements. We can use approximations to the ideal metric that we wanted to move.

Here are a couple of alternatives that can move us in the right direction:

  • Measure an increase in percentage of words that a child understands on-screen.
  • Measure an increase in the of distinct words that a child uses to respond to a prompt for a speech recording.

With the first alternative, we now have something that we can actually measure.

As an example, we could design a daily 10-question quiz on our app where the app says a pre-recorded word (e.g. “banana”), and we give the child a multiple choice of 4 words that they can choose from (e.g. “balloon”, “banana”, “pan”, “dog”).

We can measure whether the child is increasingly more successful in selecting the word that matches the recording. It’s not a perfect match with our unmeasurable ideal metric, but it gives us a directional sense that our app is doing what we want it to do.

With the second alternative, we also have something that we can actually measure.

As an example, we could design a weekly prompt on our app where the app asks a pre-recorded question, and asks the child to respond. For example, we could ask “what was your favorite moment today?” or “tell me about one of your friends.”

There, we could parse the child’s recorded response and count the number of distinct words that they used.

Again, it’s not perfectly aligned with the mission of our app, but it moves us in the right direction!

If you can’t measure the metric, you can’t determine whether you’re headed in the right direction.

As a reminder, when pioneers used the North Star in the past to navigate, they didn’t expect the North Star to be as exact as the GPS maps that we use today. Rather, they used it to move directionally towards their desired destination.

The North Star Metric Must Be Actionable

Finally, you need to be able to act on your north star metric. If you can’t take action on it, then it’s not providing you or your product team with value.

After all, if your data can’t inform your decision-making, then your data isn’t actually helping you succeed.

Here’s a real-life example: every B2B product would ideally use “revenue generated” as its north star. After all, revenue is the key goal, and revenue is measurable.

But, problematically, sales cycles in B2B can take a long time. It might take 6 months, 12 months, or even 18 months for a deal to close. How would you know whether your feature actually meaningfully moved revenue upwards if it takes you years to identify whether you made an impact?

Again, metrics are simply approximations for reality. Here, we can swap in our revenue metric with a leading indicator or something that we believe is strongly correlated with our ideal metric.

For example, say that you’re a product manager for Salesforce, which sells B2B products. If you’re in charge of some functionality for their CRM (customer relationship management software), you would ideally like to measure revenue.

But, you’ve noticed that the customers who typically renew their contracts are the ones who have the most active users on your product. Or, you might notice that customers with more records in your product are more likely to buy other features as well.

Now you have two potential leading indicators to use. You can use the number of active users, or you can use the of records. Both can be measured in real-time without needing to wait for a renewal contract to be signed. Say you decide to use “number of active users” as the north star metric for your product.

You now have the capability to run experiments in real-time to see whether you can move your north star metric upwards. You can launch changes in wording, changes in user flows, or even conduct A/B tests for a feature that you’re hoping to roll out broadly across the customer base.

And, you can see in real-time whether the of active users suddenly drops. Say, for example, that there’s an outage on the Salesforce platform, which means that no one has been active on the last day.

North star metrics are actionable because they trigger an immediate investigation – why don’t we have any active users? And how can we get that fixed as quickly as possible?

That’s one reason why user engagement metrics such as daily active users (DAU), weekly active users (WAU), and monthly active users (MAU) are commonly selected as north star metrics. User engagement metrics are leading indicators towards the ultimate goal of “increase revenue”, and these metrics can quickly be acted upon.

Closing Thoughts

Product management is a balance of art and science. While you can be highly scientific in measuring particular metrics, you still need to make subjective decisions on what a good north star metric should be.

A good north star metric helps you focus. Therefore, it needs to be a critical, measurable, and actionable metric that you can align your team on.

Many solid technology companies rely on north star metrics to guide themselves to success. Airbnb, Google, and Dropbox all rely on north star metrics.

In our next article, we’ll discuss how to use counter-metrics to ensure that you’re still talking of what matters and that you’re not taking detrimental shortcuts.

Have thoughts that you’d like to contribute around north star metrics? Chat with other product managers around the world in our PMHQ Community!

Clement Kao
Clement Kao
Clement Kao is Co-Founder of Product Manager HQ. He was previously a Principal Product Manager at Blend, an enterprise technology company that is inventing a simpler and more transparent consumer lending experience while ensuring broader access for all types of borrowers.