Verification

Verify what actually ran

Reconcile the assessment against your own CloudTrail, and against the evidence ledger the pack publishes about its own coverage.

Currentengine 9.0.0Verified 2026-08-30

In your CloudTrail

Filter on the assumed-role session name, which begins govintel- and carries the engagement reference and the run identifier.

Expect to seeDo not expect to see
One federated assume-role eventAny console sign-in
Describe, list and get-configuration callsAny create, update, delete or put
Calls confined to the assessment windowAny access key usage
Nothing after your engagement expiryAny data-plane read

The session name is required by the role's own trust policy, so this reconciliation is available by construction rather than by GovIntel's cooperation.

In the pack

The Evidence Ledger states which collectors ran and which did not, in one of eight states. Cross-check it against what you see in CloudTrail.

A collector reported as permission denied should correspond to a denied call in your trail. One reported as no applicable resources should correspond to a successful call that returned nothing.

The assessment note

Check three figures:

  • The control population. Far outside the typical range is a signal that the scan did not do what it usually does
  • Records excluded as unclassifiable. A non-zero count usually indicates a missing permission
  • Evidence files ignored. Should normally be zero

What confirms the scope

The pack prints the account and the regions covered. If regions were narrowed for your engagement, the pack says so, and the narrowing is visible in the trail as calls confined to those regions.