Assessment Methodology

Controls, not findings

Scanner records are collapsed to distinct controls before scoring, so the number a board reads measures governance rather than estate size.

Currentengine 9.0.0Verified 2026-08-30

The scanner emits one record per resource per check. A single misconfigured control on forty S3 buckets produces forty records.

Counted raw, that number measures how large the estate is, not how well it is governed — and it moves every time a team adds a bucket.

What GovIntel does instead

Every record is collapsed to its distinct control identifier before scoring and before exposure. A control failing on forty resources counts once.

The forty resources are still reported, in full, against that one control.

MeasureMeaningWhere it appears
Controls evaluatedDistinct checks that returned a usable resultExecutive View
Controls failedDistinct checks currently failingComplete Control Index
Finding records processedThe underlying per-resource recordsEvidence Ledger

Why the pass rate needs both halves

Security is scored as a weighted control pass rate, so both passing and failing results are required. Without a denominator there is no rate, and the domain is reported as not assessed rather than scored from failures alone.

This is why the scan is run in a mode that returns passes as well as failures — and why a scan that returns only failures is treated as a collection problem, not as a catastrophic result.

Records that cannot be classified

A record whose compliance status is NOT_AVAILABLE, or which carries no classifiable status, is excluded from both the numerator and the denominator. Counting it either way would misstate the result.

The excluded count is reported in the assessment note, so a permission gap is visible rather than quietly flattering the score.