AWS Evidence
Scan scope
The account and the regions an assessment actually covered, printed in the pack so a reader can see what was in scope without asking.
What it is
One account, and by default every enabled region in it.
Why the default is everything
A governance assessment scoped to a convenient subset of regions reports on a convenient subset of the estate. The regions input exists to restrict scope where an engagement explicitly requires it, not to enable it.
How GovIntel applies it
Collectors that enumerate resources discover enabled regions and fan out. The scope is printed in the pack, including any narrowing.
Why the population matters
A control population far outside the typical range is a signal that the scan did not do what it normally does: a permission gap, a region filter, or a scanner change. The pack reports the count so this is visible rather than absorbed.
What it does not mean
Scope is not coverage. Scanning every region does not mean every resource type is observed. See Coverage limits, domain by domain.
