Findings

Triage first. Detail on demand.

Findings group retained risk evidence by security question, with source, limitation, verification guidance and advisory review state.

One canonical rendered vocabulary

Severity, rendered evidence state and Coverage remain separate. Partial is a completeness qualifier, not a separate rendered state. A failed or unavailable source never becomes None found. Not assessed means work was not performed or the question was outside the assessed scope; intentional detail omission is Not retained at this evidence level or Not captured.

Severity

  • Critical
  • High
  • Moderate

Rendered evidence state

  • Contextual metric or finding label
  • None found
  • Unavailable
  • Not assessed
  • Not retained at this evidence level
  • Not captured
  • Not applicable

Coverage

  • Automated
  • Partial Evidence
  • Manual Required
  • Not Covered
  • Extended Check
  • Partial Evidence is Coverage, never an outcome or evidence state

Completeness boundaries

  • Partial: shown beside a usable count
  • Not assessed: work not performed or outside assessed scope
  • Unavailable: required attempted source inaccessible or unusable
  • Not retained at this evidence level: detail intentionally not retained
  • Not captured: product intentionally does not capture that detail
  • Incomplete: separate licence-assignment capture status for bounded or truncated capture

Filter, inspect and record review

Prioritise

Filter by severity, review area, rendered evidence state and Coverage.

Inspect safe detail

Open retained evidence, affected context and verification guidance. Top Issues contains no licence-assignment rows or assignment-summary rows; licence-assignment identities are Everything-only.

Record advisory review

Track follow-up without changing permissions, sessions, applications or endpoints.