Verification
Verify what actually ran
Reconcile the assessment against your own CloudTrail, and against the evidence ledger the pack publishes about its own coverage.
In your CloudTrail
Filter on the assumed-role session name, which begins govintel- and carries the engagement reference and the run identifier.
| Expect to see | Do not expect to see |
|---|---|
| One federated assume-role event | Any console sign-in |
| Describe, list and get-configuration calls | Any create, update, delete or put |
| Calls confined to the assessment window | Any access key usage |
| Nothing after your engagement expiry | Any data-plane read |
The session name is required by the role's own trust policy, so this reconciliation is available by construction rather than by GovIntel's cooperation.
In the pack
The Evidence Ledger states which collectors ran and which did not, in one of eight states. Cross-check it against what you see in CloudTrail.
A collector reported as permission denied should correspond to a denied call in your trail. One reported as no applicable resources should correspond to a successful call that returned nothing.
The assessment note
Check three figures:
- The control population. Far outside the typical range is a signal that the scan did not do what it usually does
- Records excluded as unclassifiable. A non-zero count usually indicates a missing permission
- Evidence files ignored. Should normally be zero
What confirms the scope
The pack prints the account and the regions covered. If regions were narrowed for your engagement, the pack says so, and the narrowing is visible in the trail as calls confined to those regions.
