Risk & Scoring
Confidence and INSUFFICIENT EVIDENCE
Confidence is measured over scored governance domains, never over collectors, and below High the overall rating is withheld entirely.
How confidence is measured
Over scored governance domains. Not over collectors, not over evidence files, not over API calls that returned successfully.
| Confidence | Requirement |
|---|---|
| High | 3 scored governance domains, and security must be one of them |
| Moderate | 2 scored governance domains |
| Low | Fewer than 2 |
Why not collectors
Counting collectors once let an assessment reach High confidence with account metadata, Security Hub status, control checks and cost telemetry all present, while only two of the governance domains had actually been scored.
Account metadata and Security Hub posture are context. They are useful, and they establish no governance position on their own. Every collector can succeed while the rating is still correctly withheld.
The gate
Below High confidence the overall rating is withheld entirely and reported as INSUFFICIENT EVIDENCE.
The engine will not emit a deliverable pack in that state, so a pack built on partial evidence cannot be shipped by accident.
This is a successful run, not a failure
An assessment that reaches insufficient evidence has worked correctly. It observed the account and reported an honest limit: the environment could not be assessed to a standard that supports board reliance.
That is a different fact from a broken pipeline, and the two are kept apart deliberately at every layer, right down to the name of the artefact the run produces.
What you are told
Plainly, and with what would change it: what was examined, what could not be reached, and what additional access or coverage would be needed to produce a rating a board could rely on.
