Skip to content

Assurance

One derived reading of what a project has been asked, and what it could answer.

The cockpit is assembled fresh on every view and never stored. It reports the weakest single dimension rather than an average, and it deliberately produces no score: one number would let a well-modelled architecture compensate for a risk posture nobody has assessed.

  • No score, and no opaque model: every reading states its reason
  • The worst dimension is reported, never averaged away
  • UNKNOWN means genuinely undetermined, never a failed read
The OTReady assurance cockpit listing dimensions such as OT architecture, initial cyber risk and NIS2, each with a status band and a written explanation of the reading.
Each dimension carries its band, its reason and a link to the objects behind it.

Five derived states, each rendered as a word.

Colour reinforces the state; it never carries it. Every band is written out, so a reader who cannot separate the hues loses nothing.

UNKNOWN is never a quiet NORMAL. A grey panel over an outage is the most convincing wrong answer a dashboard can give, which is why the next section draws a hard line under it.

Normal
The inputs that could be checked look ordinary. This does not mean compliant, and it is not a pass.
Attention
Something here is worth looking at before it becomes a problem.
Degraded
A dimension is materially weaker than the rest of the project.
Critical
Something needs attention now. Still not a statement that the project is non-compliant.
Unknown
The business state genuinely could not be established, most often because it is not visible to the person looking.

A technical failure is a defect. It is never reported as UNKNOWN.

A missing table, a wrong column, a query that errors: these are statements about the SOFTWARE, not about the plant. They fail loudly, naming the dimension that broke, and they never become a business state. UNKNOWN is reserved for the case where the read succeeded and the answer is honestly undetermined. An empty result is neither: zero zones is a fact, and it reads as zero.

Explainability

Every reading has to say why.

A dimension that only produced a colour would be asking to be trusted. Each one instead states the reason it reads the way it does, names the context it is about, and links through to the objects behind it: the scopes not yet approved, the blockers, the findings that cannot be tiered.

Where the same reason applies many times, it is aggregated rather than repeated. A dimension with fifty-three unapproved objects says so once, groups them by site, and offers the full list one click away: a page that printed fifty-three identical sentences would be technically complete and practically unreadable.

  • A written reason, not a rating
  • A link through to the affected objects
  • Repeated causes summarised, grouped and then drillable

Across projects

The same reading, on a project at a different stage.

A young project and a mature one should not look alike, and the cockpit does not flatten the difference. What stays constant is the method: worst dimension, written reason, no score.

The OTReady assurance cockpit on a second project, showing different dimension bands and their written explanations.
A different estate, the same method, and a visibly different reading.

Connected Assurance

From a source event to a governed Finding, with a person in the middle.

Connectivity is optional enrichment. A project with no connected source is complete; OTReady is assessment-first and stays that way.

  1. Telemetry / source event
  2. Observation
  3. Detected condition
  4. Operational Alert
  5. Governed promotion
  6. Finding

Every step is a distinct object with its own identity. An observation is evidence that a source reported something, never approved architecture, and never a Finding by itself.

The OTReady operational alerts view, listing detected conditions with the basis on which each was raised.
Each alert carries its basis. Promotion is a decision, not a default.

Operational Alerts

An alert states the basis on which it was raised.

A detected condition carries the reason it was detected, and the alert raised from it carries that reason forward. An alert nobody can explain teaches people to ignore the surface.

Promotion to a governed Finding is an explicit human act, one alert at a time, with the severity and exposure judgement made by the person doing it.

An Operational Alert never creates remediation work.

Promotion produces a governed Finding. Whether that Finding becomes tracked work is a separate treatment decision made afterwards. Nothing in the chain from telemetry to a remediation task happens without a person choosing it, and no assessment source creates a remediation task directly either.

Related capabilities

See a reading you can argue with.

Every band, every reason and every link: on a real project rather than a sample dashboard.