AWS Evidence

Evidence capture state

One of eight states describing what happened to a collector, distinguishing a crash from a healthy empty account and a gap from a pass.

Currentengine 9.0.0Verified 2026-08-30

The states

StateMeaning
Assessed, healthyCollected, scored, in good shape
Assessed, issues foundCollected, scored, something is failing
Collected, not ratedEvidence arrived but was too thin to rate
No applicable resourcesNothing of this kind exists. Not a fault
Collector failedIt ran and errored. GovIntel's to fix
Permission deniedA required permission was missing
UnavailableDid not run, or was skipped
CapturedA context collector with no governance position

Why eight and not two

There used to be two: captured, and unavailable. Those could not distinguish a collector that crashed from one never configured, nor an account with four hundred healthy resources from one with a single resource.

Both conflations mislead in the customer's favour, which is the direction that costs trust.

Ordered most specific first

A collector that failed is reported as failed even though its absence also means the domain went unscored. One is GovIntel's to fix; the other may simply be an account with nothing of that kind in it.

What it does not mean

A collector reported as captured has not established a governance position. Account metadata and Security Hub status are context and never count towards evidence confidence.