Evidence & Findings

Evidence capture states

Eight states describing what happened to each collector, because captured and unavailable could not tell a crash from a healthy empty account.

Currentengine 9.0.0Verified 2026-08-30

Every collector's outcome is reported in the pack as one of these.

StateMeaning
Assessed, healthyCollected, scored, and in good shape
Assessed, issues foundCollected, scored, and something is failing
Collected, not ratedEvidence arrived but was too thin to support a rating
No applicable resourcesThe account holds nothing of this kind. Not a fault
Collector failedThe collector ran and errored. Ours to fix
Permission deniedA required permission was missing
UnavailableThe collector did not run, or was skipped
CapturedA context collector that has no governance position to report

Why there are eight and not two

There used to be two: captured, and unavailable.

Those could not distinguish a collector that crashed from one that was never configured, nor an account with four hundred healthy resources from an account with one. Both conflations mislead in the customer's favour, which is the direction that costs trust.

Ordered most specific first

A collector that failed is reported as failed even though its absence also means the domain was not scored. The two call for different responses: one is GovIntel's to fix, the other may simply be an account with nothing of that kind in it.

Context versus governance

Account metadata and Security Hub posture are context. They establish no governance position on their own and never count towards evidence confidence.

Conflating the two is what once let an assessment reach High confidence on half an environment. See Confidence and INSUFFICIENT EVIDENCE.