10 pages in this section, in the order they are meant to be read.
Evidence chain
How evidence becomes an assessment.
- 01What read-only gates prove
If CI says the collector has no write path, what exactly has been established?
- 02Run, RunSet, Assessment
What exactly is the verifiable unit a governance evaluation produces?
- 03Canonical JSON and digests
How can the same document hash differently on two machines that both follow the JSON spec?
Provenance
How the engine proves where evidence came from.
- 01What provenance changes
What must travel with a finding for it to be worth acting on?
- 02Fixture vs observation
When a result is computed from example evidence, what stops it being presented as a real reading?
Coverage
What the engine can and cannot conclude.
- 01Incomplete evidence and lower bounds
Can a partial count ever settle a governance question?
- 02Unknown vs invalid-evidence
When a governance report says unknown, what exactly failed, and who fixes it?
- 03Set aside, not excluded
What should a governance profile do with system lists it did not create?
- 04Outcome, severity, attention
A rule failed with severity medium, so how urgent is it?
- 05The collection manifest
The evidence folder has ten files. Is that all of them, or all that could be read?