Choose what you see
Connected, but no results
A working connection is the first step in a longer path: Find the first step you cannot confirm:- Check connection health and source access in Integrations.
- Confirm the source record’s identifier maps to the intended Organization.
- Check whether collection completed and produced observations for that client.
- Review the standard and control settings. A copied library template starts disabled.
- Use Standards → Run checks, review the selected clients and settings, and inspect the completed evaluation.
Not covered
Read the detailed reason and identify the missing predicate: the kind of observation the control needs.- Look up its meaning in the predicate reference.
- Confirm that an available source can supply it in this deployment and client context.
- Check the relevant integration and client mapping.
- Review existing evidence as well: existing observations can affect coverage reconciliation, while freshness still matters.
No data
Use the result’s detailed reason to narrow the investigation.The selected population is empty
The selected population is empty
Check that the population predicate has observations for this client. Compare any exact population value with the actual value, including type and spelling. Review filters for unintended exclusions.Recovery check: the expected subjects appear, or the reason they are outside this population is understood. An empty observed population is not proof that no relevant accounts or devices exist.
A selected subject is missing a required observation
A selected subject is missing a required observation
Confirm that the population observation and expected observation refer to the same account, device or workload. Inspect source permissions, completed collection and the source’s ability to provide that property.Recovery check: a fresh, eligible observation answers the question, or the remaining gap has a specific cause and owner. Missing is not false, zero or an observed null value.
Evidence exists but is too old or unusable
Evidence exists but is too old or unusable
Inspect observation times and the detailed status reason. If the source has stopped collecting, restore collection and confirm new evidence arrived before running checks again.Recovery check: both the observation time and the subsequent evaluation show that new evidence was considered. Re-running a check alone does not refresh the source evidence.
A filter needs evidence that is missing
A filter needs evidence that is missing
A filter decides which subjects are assessed. Missing filter evidence can prevent a complete pass. Check the filter’s required observation and whether the filter expresses your intended scope.Recovery check: the scope can be established from evidence. Do not remove a meaningful filter merely to obtain a different badge.
An unexpected pass or failure
Reconstruct the question before changing the answer:
A known failure can coexist with missing evidence for another subject. Likewise, a pass only establishes the selected expectation against the assessed evidence.
Recovery check: you can state the actual value, effective expectation and evidence that explain the result. If you intentionally changed the definition or threshold, record that the question changed.
For worked examples, follow the administrator assessment, vulnerability limit or backup recipe.