Governance Concepts
Assessment run
One execution of the assessment pipeline against one account, identified so its activity can be reconciled in your own audit trail.
What it is
A single execution: assume the role, collect evidence, run control checks, score, render, upload.
Why it is identified
The run identifier appears in the session name GovIntel uses in your account, so every action in your CloudTrail can be traced to the run that made it. It is also recorded with the delivered pack as provenance.
How GovIntel bounds it
One assessment per engagement at a time. A re-dispatch supersedes a run in flight rather than producing two runs carrying the same marker. The job is time-bounded so a pathological account degrades to a recorded failure rather than hanging.
What it does not mean
A run is not an engagement. One engagement may have several runs, including failed ones. A failed run does not destroy the pack a previous successful run produced.
