Verification standard · observed-controls/3
What we observed.
What we can claim.
An assessment concerns a named set of provider controls. It does not prove that software is safe or that every release authority has been identified. A paid plan cannot change a check's outcome.
Pass
The observed setting meets this control's criterion.
Fail
The observed setting does not meet that criterion.
Unknown
Evidence is missing, inaccessible, incomplete or from an older incompatible evaluation.
Not applicable
The control does not apply to this assessment's stated scope.
Scope and freshness
All required controls for every represented provider must be present and pass before the assessment says “Observed controls passed.” No score averages away a failure. Evidence expires eight days after a completed assessment. Provider reports may describe an earlier reporting date; enrollment counts do not establish which factor is required at authentication. An incomplete assessment cannot establish end-to-end publisher protection.
Current control inventory
| Provider | Control |
|---|---|
| Active super-administrator 2SV enforcement | |
| Active-user 2SV enforcement | |
| Reported password policy compliance | |
| Super-administrator count | |
| Reported legacy app access | |
| github | Organization 2FA requirement |
| github | Default workflow token permissions |
| github | Secret scanning coverage |
| github | Push protection coverage |
| github | Default-branch required reviews |
| github | Actions SHA-pinning policy |
| github | Actions allowlist policy |
| github | Workflow review-approval policy |
| github | Fork workflow approval policy |
| github | Organization runner public-repository access |
| github | Release immutability coverage |
| registry | Registry-reported publishing evidence |
| registry | Artifact origin matches connected GitHub account |
| registry | Declared npm install hooks |
Important boundaries
- Google Directory and usage reports establish reported 2SV enforcement, enrollment and account counts. Security-key enrollment does not establish phishing-resistant-only authentication. Personal Gmail accounts are outside the Workspace connector's scope.
- GitHub checks inspect repositories accessible to the installed app and organization policies where applicable. Personal account connections require proof of account ownership; organization-only policies are not applicable to them. Default-branch reviews are not a complete analysis of rulesets, bypass identities, workflow content or all possible release paths. Limited repository visibility is incomplete coverage.
- Registry metadata alone is an observation. For supported npm GitHub Actions provenance, package lookup checks Sigstore signatures, certificate identity, transparency evidence and the signed statement’s binding to the exact package, version and registry-reported digest. A publisher assessment is linked only when signed repository and owner IDs match its connected scope. This does not prove every alternative credential or recovery path is protected.
- Repository URLs and maintainer names in registry metadata are hints. They do not establish ownership or connect a human to a protected email account.
- Matching lockfile and registry integrity metadata is a metadata comparison. We do not download or execute the artifact during a dependency review.
- No declared npm lifecycle hook does not mean a package cannot execute code, or that its dependencies are harmless.
Public and private evidence
Publishers explicitly choose publication. Public assessments expose scope, aggregate outcomes and dates. Private findings, dependency inventories and review notes remain in the signed-in workspace. JSON assessments identify their schema and policy version; unsigned assessments explicitly report a null signature.