Coverage
Which work is governed and which is not — repositories on the host that no workspace watches, merged pull requests that were never judged, and where an integration has stopped protecting anything.
Organization → Coverage, over 7, 30 or 90 days, plus a Coverage card on each workspace's Compliance page.
The compliance verdict says whether one pull request met the rules. Coverage answers what the verdicts leave out: how much of the work was judged at all, and where protection has quietly failed.
Repositories
Everything the organization's connections can see on the host, split into:
| Category | Meaning |
|---|---|
| Judged | In a workspace, with compliance in monitor or enforce. |
| Connected but not judged | In a workspace, compliance off. The workspace's Compliance page can mark it left off on purpose; until then Coverage shows it as not decided. |
| Ungoverned | On the host, in no workspace at all. |
The host list is read per connection, every page, cached for 15 minutes; the page shows how old it is. A host that cannot be listed makes ungoverned not measured, with the reason — never 0.
For each connected repository: its mode, its enforcement reading and when it was read, how current the pull request mirror is, the last webhook, CI and review sync health, and open pull requests with no current verdict.
Merged pull requests
Every merged pull request the mirror holds in the window, judged by the latest verdict on the merged commit:
| Category | Meaning |
|---|---|
| Passed | Compliant on the merged head. |
| Passed under an exception | Compliant only because an exception waived something. |
| Failed | The verdict on the merged head failed — and it merged anyway. |
| Never evaluated | Compliance was off, only older commits were evaluated, or it was judged with no verdict. The reason is given. |
| Unreported work | Counted separately: merges no supervised session claimed. |
Every number opens the list behind it, computed by the same function, so the count and the list cannot disagree.
Integration health
Connection errors and listing failures; what each GitHub App installation actually granted (a permission missing from the installation, not the App); and failing syncs.
In the attention queue
A judged repository whose pull request mirror is failing, or more than three sync intervals behind, raises pull_request_mirror_stale at review. It clears on recovery. The hourly compliance sweep catches staleness that no event announces.