Sample report

What lands on the board's desk.
A real score, and how it is built.

Real output from a Govern360 tenant. One number, five dimensions, every point traceable to a finding, the points lost to stale sources, and an explicit statement of what the model does not claim.

A governance score is only worth reading if you can take it apart. This one decomposes into five weighted dimensions, each into measured domains, each into findings that name the configuration behind them. Nothing is scored that was not measured - where a signal is unavailable the dimension is excluded and said so, rather than quietly scored zero.

The headline

68
Moderate exposure

100% measured - the whole score rests on real signal, with 87% of configured sources connected. Model v1.1. No movement over the last 90 days, which for a governance score is itself a finding.

37AI tools discovered
5shadow AI tools, high risk
0 of 8agents acting alone - 8 not measured
3autonomous decisions in 30 days

Read the third tile carefully. It says 0 of 8 agents are acting alone, and then says 8 were not measured. That is not a contradiction - it is the product refusing to report zero as a clean result when the underlying signal has not been established. A tool that showed a green zero there would be reporting an absence of measurement as an absence of risk.

Five dimensions

AI Discovery 25%79Room to strengthen
AI Protection 25%73Room to strengthen
AI Governance 20%55Needs attention
AI Control 15%54Needs attention
AI Compliance 15%80Room to strengthen

What to fix

Ordered by severity, then by recoverable points. Each finding names the measurement behind it, so a reviewer can disagree with the conclusion rather than take it on trust.

Critical - Accountability gap: 8 of 8 agents have no signed purpose Agents with no signed purpose, so no behaviour can be judged out of scope.Measured from the tenant
High - Losing about 9 of 20 available points in AI Governance Assign a named owner and approval record to every AI system and agent.Evidence: policy coverage, approval records, architecture reviews · Effort: Medium · +5 points
High - Losing about 7 of 15 available points in AI Control Attribute token spend to cost centres, set budgets, and instrument agent oversight.Evidence: token attribution, budgets, agent-oversight signals · Effort: Medium · +3 points
High - Token waste: 612.00 unallocated of 3,879.85 allocated Share of AI cost with no named owner after the allocation rules run.Measured from the tenant
High - Shadow AI: 5 unsanctioned tools Unsanctioned tools seen in use.Measured from the tenant
Medium - Losing about 7 of 25 available points in AI Protection Extend DLP at point of use, scope non-human identities to least privilege, and review behavioural risk.Evidence: DLP coverage, behavioural risk, NHI least-privilege signals · Effort: Low · +3 points

Two of those findings carry no effort estimate. Nobody has estimated the cost of assigning a purpose to every agent, so the field is empty rather than filled with a plausible guess. The findings that do carry an estimate earned one.

What is working

A report that only lists failures gets discounted. These are the dimensions carrying the score.

AI Compliance is strong at 80/100 +12
AI Discovery is strong at 79/100 +20

Freshness - stale sources cost points

A connected source that stopped reporting is not the same as a source that reports nothing. The score treats them differently, and says which is which.

3 cloud accounts stale  -6 points Re-test cloud connections and refresh expiring credentials to restore Control freshness.
2 endpoints without a recent heartbeat  -4 points Coverage is decaying. Ensure the browser extension is active on managed endpoints to restore it.

Those ten points are deducted for measurement decay, not for anything the organisation did wrong. It is the same discipline in the other direction: if we cannot currently see a source we said we were watching, the score should reflect that rather than coasting on a reading from six weeks ago.

What the model does not claim

Runtime behaviour

Govern360 reads management APIs and does not sit in the execution path. Memory poisoning, unexpected code execution and cascading multi-agent failures are not observable from that position, and the published coverage matrix says so rather than scoring them green.

Semantic duplication

Two agents doing the same job under different names are not detected. That needs instruction text the platform management APIs do not return.

Validation against outcomes

The score measures governance state. It is not validated against incident outcomes, because no incident corpus exists to validate it against. That is stated on the methodology page rather than left for a customer to discover.

This is real output from a Govern360 demonstration tenant, shown to illustrate the shape of the report rather than to describe any customer's estate. Model v1.1: weighted geometric aggregation, band capped by the weakest measured dimension, and dimension inputs floored inside the aggregation - a scoring artefact disclosed on the methodology page rather than hidden in it.

See your own score.

Book a free 30-minute session

One read-only administrator consent. Nothing installed, no traffic proxied. First findings inside 24 hours.