Running an audit and reading the results
The run itself takes seconds. The value is in what each verdict carries and what history does with the accumulation.
Launch
Pick the scope — full catalog or a baseline — and run. Controls execute in parallel, read-only, against the live APIs; every verdict (compliant, non-compliant, not applicable, error) comes from an actual query, never from a cached assumption. A typical full pass completes in about sixteen seconds.
Read each control, not just the score
Every control in the result cites its source (CIS, NIST, ISO, ANSSI, NIS2, DORA, SCuBA), explains what was checked and, when it fails, ships the remediation steps and the PowerShell to verify the fix. Treat the failed list as the working checklist — triage guidance is in the audit guide.
History, comparison, trend
Every run is kept in history with its date, score, referential coverage and the baseline used. Open any run for the full detail; select two to compare — regressions come first, exactly what a steering committee asks about — and the dashboard trend chart turns successive audits into a posture narrative.
Finish before you fix. Complete the run, get the baseline picture, then remediate and re-run. Fixing mid-audit produces a report that describes neither the before nor the after.