Coverage, investigation, and rollout
Guidance only · no automatic tenant changes · unknown is not clean
One of the most expensive mistakes in assessment software is turning missing evidence into a green box. A collector cannot run, a provider returns a 403, a license does not expose the control, or a permission was not granted—and the report behaves as if nothing is wrong.
That is not a clean result. It is a coverage result.
SCOUTz separates assessed, partially assessed, not assessed, permission-limited, license-limited, provider-error, and unreadable states because each one tells the MSP something different. Assessed means the relevant source was available and the check ran. Permission-limited means the question may be valid but the approved access did not expose the answer. Unreadable means we could not responsibly interpret what came back.
The wording matters. "We did not observe an unmanaged application" sounds reassuring until you learn that application activity was not available from the connected source. The defensible sentence is narrower: "Application inventory was reviewed, but recent activity could not be established from the available evidence."
Unknown is useful. It tells us what to ask, what authorization may be needed, which license changes the answer, and whether another tool or a human validation step belongs in the plan. Unknown is a direction, not a product failure.
If a provider returns a 403, we should not reward ourselves with a passing grade. We should show the boundary, preserve the error, and let the MSP decide whether the missing answer matters. A report earns trust by making its blind spots as visible as its findings.