Assessment Methodology
Controls, not findings
Scanner records are collapsed to distinct controls before scoring, so the number a board reads measures governance rather than estate size.
The scanner emits one record per resource per check. A single misconfigured control on forty S3 buckets produces forty records.
Counted raw, that number measures how large the estate is, not how well it is governed — and it moves every time a team adds a bucket.
What GovIntel does instead
Every record is collapsed to its distinct control identifier before scoring and before exposure. A control failing on forty resources counts once.
The forty resources are still reported, in full, against that one control.
| Measure | Meaning | Where it appears |
|---|---|---|
| Controls evaluated | Distinct checks that returned a usable result | Executive View |
| Controls failed | Distinct checks currently failing | Complete Control Index |
| Finding records processed | The underlying per-resource records | Evidence Ledger |
Why the pass rate needs both halves
Security is scored as a weighted control pass rate, so both passing and failing results are required. Without a denominator there is no rate, and the domain is reported as not assessed rather than scored from failures alone.
This is why the scan is run in a mode that returns passes as well as failures — and why a scan that returns only failures is treated as a collection problem, not as a catastrophic result.
Records that cannot be classified
A record whose compliance status is NOT_AVAILABLE, or which carries no classifiable status, is excluded from both the numerator and the denominator. Counting it either way would misstate the result.
The excluded count is reported in the assessment note, so a permission gap is visible rather than quietly flattering the score.
