10 pages in this section, in the order they are meant to be read.

Evidence chain

How evidence becomes an assessment.

  1. 01
    What read-only gates prove

    If CI says the collector has no write path, what exactly has been established?

  2. 02
    Run, RunSet, Assessment

    What exactly is the verifiable unit a governance evaluation produces?

  3. 03
    Canonical JSON and digests

    How can the same document hash differently on two machines that both follow the JSON spec?

Provenance

How the engine proves where evidence came from.

  1. 01
    What provenance changes

    What must travel with a finding for it to be worth acting on?

  2. 02
    Fixture vs observation

    When a result is computed from example evidence, what stops it being presented as a real reading?

Coverage

What the engine can and cannot conclude.

  1. 01
    Incomplete evidence and lower bounds

    Can a partial count ever settle a governance question?

  2. 02
    Unknown vs invalid-evidence

    When a governance report says unknown, what exactly failed, and who fixes it?

  3. 03
    Set aside, not excluded

    What should a governance profile do with system lists it did not create?

  4. 04
    Outcome, severity, attention

    A rule failed with severity medium, so how urgent is it?

  5. 05
    The collection manifest

    The evidence folder has ten files. Is that all of them, or all that could be read?

All documentation