Risk & Scoring

Confidence and INSUFFICIENT EVIDENCE

Confidence is measured over scored governance domains, never over collectors, and below High the overall rating is withheld entirely.

Currentengine 9.0.0Verified 2026-08-30

How confidence is measured

Over scored governance domains. Not over collectors, not over evidence files, not over API calls that returned successfully.

ConfidenceRequirement
High3 scored governance domains, and security must be one of them
Moderate2 scored governance domains
LowFewer than 2

Why not collectors

Counting collectors once let an assessment reach High confidence with account metadata, Security Hub status, control checks and cost telemetry all present, while only two of the governance domains had actually been scored.

Account metadata and Security Hub posture are context. They are useful, and they establish no governance position on their own. Every collector can succeed while the rating is still correctly withheld.

The gate

Below High confidence the overall rating is withheld entirely and reported as INSUFFICIENT EVIDENCE.

The engine will not emit a deliverable pack in that state, so a pack built on partial evidence cannot be shipped by accident.

This is a successful run, not a failure

An assessment that reaches insufficient evidence has worked correctly. It observed the account and reported an honest limit: the environment could not be assessed to a standard that supports board reliance.

That is a different fact from a broken pipeline, and the two are kept apart deliberately at every layer, right down to the name of the artefact the run produces.

What you are told

Plainly, and with what would change it: what was examined, what could not be reached, and what additional access or coverage would be needed to produce a rating a board could rely on.