Technical whitepaper
Evidence Semantics and Scanner Orchestration v1.4
The current explanation of the evidence semantics, same-20-family scanner plan and bounded licence-assignment retention model behind Security Observatory.
Architecture & Security
Security Observatory separates experience, orchestration, collection, evidence and governance so each documented trust boundary stays visible.
Diagram 1
Server-side collection and retention, browser-side CSV preparation and local download
Diagram key: Solid arrows show execution or evidence/result relationships, as labelled. Dashed outlines show trust or ownership boundaries.
Licence-assignment retention boundary
At the Everything evidence detail level, retained assignment evidence is bounded to 1,000 rows for each of Package Licences, Permission Set Licences and Salesforce User Licences. The 3,000-row maximum is theoretical; safe capture may be lower than expected or zero when Salesforce transaction/DML headroom is exhausted. Zero captured must not be inferred as zero assignments or shown as Complete; an unknown expected count remains unknown. Incomplete is a separate licence-assignment capture status, not a rendered evidence state, and capped retained counts are not exact organisation totals.
Diagram 2
Subscriber-owned OAuth configuration for the Tooling API self-callout
Diagram 3
Prohibited sensitive categories are removed before retained review evidence
Diagram 4
A successful zero is reached only after usable evidence was obtained and no matching records were observed
Technical whitepaper
The current explanation of the evidence semantics, same-20-family scanner plan and bounded licence-assignment retention model behind Security Observatory.