Glossary

Glossary

Every term this documentation uses, with the canonical page that defines it. Each definition lives in exactly one place and is linked from everywhere else.

Currentengine 9.0.0Verified 2026-08-30

Each term is defined once, on its own page. Everything else links here rather than restating it.

A to C

TermDefinition
Account metadataWhich account was assessed, and its organisation context
Artifact separationDeliverable, evidence and snapshot uploaded separately
Assessment runOne execution of the pipeline against one account
Assessment snapshotThe fingerprinted record used for the next comparison
Attributable session nameHow your CloudTrail tells one engagement's access from another
Board attention itemsWhat the pack raises for directors, derived not curated
Board decision lensWhere governance attention converts into risk reduction
Board packThe deliverable
Board pack structureThe order of the pack, and why
CloudFormation authorizationHow the access grant is presented
Closure evidenceWhat would demonstrate a finding is closed
Comparability gatingWhen a comparison is withheld, and why
Comparison and movementWhat changed since the previous assessment
Complete control indexEvery failed control, at every severity
Confidence gateThe rule that withholds a rating below High confidence
ControlA single governance check
Control checksThe scanner's results, and why both outcomes are needed
Control evidence formatThe record format control results arrive in
Control identifierThe scanner's stable name for a check
Control pass rateThe proportion that passed, weighted by severity
Control populationHow many distinct controls were evaluated
Control severityThe scanner's judgement of a check in the abstract
Control vs findingThe distinction the whole methodology rests on
Cost telemetrySpend and evidenced waste, from your own billing
Coverage ratioThe resilience unit of measure

D to M

TermDefinition
Data-plane denyThe denials that override every permission
Delivery repository evidenceOptional, collected, and not scored
Determinism and pinningWhy every score-affecting input is pinned
Domain weightingHow the three scored domains combine
EngagementOne customer, one account, one lifecycle
Evidence capture stateThe eight states a collector can end in
Evidence collectorOne script reading one class of evidence
Evidence confidenceHow many governance domains were scored
Evidence manifestWhat every collector actually did
Evidence retentionHow long each artefact survives
Executive summaryThe opening statement of position
Exposure banding and provenanceWhere the bands come from, and what they are not
Exposure rangeAn indicative magnitude, not a loss estimate
Failed controlA control evaluated and not satisfied
Failing resourceA specific resource a control failed on
Finding lifecycleThe five states between two assessments
First actionThe single next step for a failed control
GitHub OIDC federationShort-lived credentials with no stored secret
Governance assessmentThe category this product belongs to
Governance domainAn area scored independently, then weighted
Governance implicationWhat a failed control means, from the mapping
Indeterminate recordA result that cannot be classified either way
MaterialityHow far a failure reaches in this account
Materiality bandEstate-wide, broad, contained, not determinable
Materiality rules M0 to M6The seven rules that assign a band
Methodology pageThe page that makes the score checkable

N to Z

TermDefinition
90-day action matrixWhat management should do next
No silent renormalisationWhy a missing domain withholds the overall score
OIDC subject and audienceThe two claims your trust policy pins
OfferingThe product an engagement is recorded against
Overall RAG floorWhy the overall band cannot beat security
Overall scoreThe weighted mean of the three domains
Population minimumsThe floors below which no rating is issued
Preventive vs detectiveWhether a control stops or notices
Private link deliveryHow a pack reaches you without being public
RAG bandRed, amber, green, and what constrains them
Read-only assuranceObservation without alteration, enforced by IAM
ReassessmentRunning it again, and the comparison window
Resilience postureFive coverage ratios, and what is not observed
Resource identity and fingerprintingNamed for action, fingerprinted for comparison
Resource reachHow much of an account a failure touches
Risk levelThe words used in place of a colour
Risk register rowOne line of the register a board reads
Scan scopeThe account and regions actually covered
ScannerThe external tool producing control results
Scanner contractThe pinned version and severity scope
Scope and reproducibility pageWhat it would take to reproduce the result
Scoring fingerprintWhich constants a result was produced under
Security Hub postureWhether the account observes its own security
Severity vs materialityTwo measures that are routinely conflated
The assessment IAM roleThe single role created in your account
Unclassified controlReported in full, and given no interpretation
Waste ratioThe cost unit of measure
Weighted pass rateThe security domain calculation