Browse documentation

Repository executive summary

Understand how the latest completed audits become a clear repository-level health summary.

What the summary uses

The repository executive summary is generated from published audits that have already completed at least once for the selected repository. It uses the latest eligible source run for each audit, allowed report artifacts, score and severity when available, completion times, commit identifiers, and project activity counts.

It does not run missing audits or silently substitute recon, Autofix, or pentest results for audit scores. If no completed audit reports are available, create the relevant audits first.

What the summary contains

The output includes a headline, overall status, optional score, narrative, confidence, commit-coverage statement, presentation sections, prioritized recommendations, source-run list, and limitations. Activity statistics can show audit, Autofix, issue, PR/MR, merged-review-request when observable, and Auto-pentest counts, but those counts do not become health scores.

Recommendations name their source audits so the reader can trace the synthesis back to detailed evidence.

Commit coverage and confidence

Latest audits may not all describe the same commit. The summary records whether sources cover a single commit, multiple commits, partial commit data, or unknown revisions, along with audit counts per known commit and missing-commit count. Multiple-commit coverage is useful but should not be presented as one atomic snapshot.

Confidence can be high, medium, or limited. Missing scores, unavailable report artifacts, mixed revisions, or audit limitations remain visible rather than being averaged away.

Generate a summary

  1. Open the repository’s Summary reports controls.
  2. Confirm that the audits you need have completed.
  3. Choose the output language.
  4. Choose private or public access.
  5. Start generation.
  6. Wait for the ready state or completion email, then open the report.

Private summaries are available to project members in Guard. Public summaries produce a link that anyone with the URL can open until access changes.

Review before sharing

Check the generated date, repository, audit count, source commits, score availability, top priorities, and limitations. Follow important claims back to the source audit reports. A summary is an executive navigation layer, not a replacement for the detailed evidence or a compliance certificate.

If newer audits finish later, create a new summary to capture them. Existing finished summaries remain tied to the source pack used when they were generated.