Evidence & Findings
Evidence capture states
Eight states describing what happened to each collector, because captured and unavailable could not tell a crash from a healthy empty account.
Every collector's outcome is reported in the pack as one of these.
| State | Meaning |
|---|---|
| Assessed, healthy | Collected, scored, and in good shape |
| Assessed, issues found | Collected, scored, and something is failing |
| Collected, not rated | Evidence arrived but was too thin to support a rating |
| No applicable resources | The account holds nothing of this kind. Not a fault |
| Collector failed | The collector ran and errored. Ours to fix |
| Permission denied | A required permission was missing |
| Unavailable | The collector did not run, or was skipped |
| Captured | A context collector that has no governance position to report |
Why there are eight and not two
There used to be two: captured, and unavailable.
Those could not distinguish a collector that crashed from one that was never configured, nor an account with four hundred healthy resources from an account with one. Both conflations mislead in the customer's favour, which is the direction that costs trust.
Ordered most specific first
A collector that failed is reported as failed even though its absence also means the domain was not scored. The two call for different responses: one is GovIntel's to fix, the other may simply be an account with nothing of that kind in it.
Context versus governance
Account metadata and Security Hub posture are context. They establish no governance position on their own and never count towards evidence confidence.
Conflating the two is what once let an assessment reach High confidence on half an environment. See Confidence and INSUFFICIENT EVIDENCE.
