Sample report
What lands on the board's desk.
A real score, and how it is built.
Real output from a Govern360 tenant. One number, five dimensions, every point traceable to a finding, the points lost to stale sources, and an explicit statement of what the model does not claim.
A governance score is only worth reading if you can take it apart. This one decomposes into five weighted dimensions, each into measured domains, each into findings that name the configuration behind them. Nothing is scored that was not measured - where a signal is unavailable the dimension is excluded and said so, rather than quietly scored zero.
The headline
100% measured - the whole score rests on real signal, with 87% of configured sources connected. Model v1.1. No movement over the last 90 days, which for a governance score is itself a finding.
Read the third tile carefully. It says 0 of 8 agents are acting alone, and then says 8 were not measured. That is not a contradiction - it is the product refusing to report zero as a clean result when the underlying signal has not been established. A tool that showed a green zero there would be reporting an absence of measurement as an absence of risk.
Five dimensions
What to fix
Ordered by severity, then by recoverable points. Each finding names the measurement behind it, so a reviewer can disagree with the conclusion rather than take it on trust.
Two of those findings carry no effort estimate. Nobody has estimated the cost of assigning a purpose to every agent, so the field is empty rather than filled with a plausible guess. The findings that do carry an estimate earned one.
What is working
A report that only lists failures gets discounted. These are the dimensions carrying the score.
Freshness - stale sources cost points
A connected source that stopped reporting is not the same as a source that reports nothing. The score treats them differently, and says which is which.
Those ten points are deducted for measurement decay, not for anything the organisation did wrong. It is the same discipline in the other direction: if we cannot currently see a source we said we were watching, the score should reflect that rather than coasting on a reading from six weeks ago.
What the model does not claim
Runtime behaviour
Govern360 reads management APIs and does not sit in the execution path. Memory poisoning, unexpected code execution and cascading multi-agent failures are not observable from that position, and the published coverage matrix says so rather than scoring them green.
Semantic duplication
Two agents doing the same job under different names are not detected. That needs instruction text the platform management APIs do not return.
Validation against outcomes
The score measures governance state. It is not validated against incident outcomes, because no incident corpus exists to validate it against. That is stated on the methodology page rather than left for a customer to discover.
This is real output from a Govern360 demonstration tenant, shown to illustrate the shape of the report rather than to describe any customer's estate. Model v1.1: weighted geometric aggregation, band capped by the weakest measured dimension, and dimension inputs floored inside the aggregation - a scoring artefact disclosed on the methodology page rather than hidden in it.
See your own score.
Book a free 30-minute sessionOne read-only administrator consent. Nothing installed, no traffic proxied. First findings inside 24 hours.