Coverage

Which work is governed and which is not — repositories on the host that no workspace watches, merged pull requests that were never judged, and where an integration has stopped protecting anything.

Organization → Coverage, over 7, 30 or 90 days, plus a Coverage card on each workspace's Compliance page.

The compliance verdict says whether one pull request met the rules. Coverage answers what the verdicts leave out: how much of the work was judged at all, and where protection has quietly failed.

Repositories

Everything the organization's connections can see on the host, split into:

Category Meaning
Judged In a workspace, with compliance in monitor or enforce.
Connected but not judged In a workspace, compliance off. The workspace's Compliance page can mark it left off on purpose; until then Coverage shows it as not decided.
Ungoverned On the host, in no workspace at all.

The host list is read per connection, every page, cached for 15 minutes; the page shows how old it is. A host that cannot be listed makes ungoverned not measured, with the reason — never 0.

For each connected repository: its mode, its enforcement reading and when it was read, how current the pull request mirror is, the last webhook, CI and review sync health, and open pull requests with no current verdict.

Merged pull requests

Every merged pull request the mirror holds in the window, judged by the latest verdict on the merged commit:

Category Meaning
Passed Compliant on the merged head.
Passed under an exception Compliant only because an exception waived something.
Failed The verdict on the merged head failed — and it merged anyway.
Never evaluated Compliance was off, only older commits were evaluated, or it was judged with no verdict. The reason is given.
Unreported work Counted separately: merges no supervised session claimed.

Every number opens the list behind it, computed by the same function, so the count and the list cannot disagree.

Integration health

Connection errors and listing failures; what each GitHub App installation actually granted (a permission missing from the installation, not the App); and failing syncs.

In the attention queue

A judged repository whose pull request mirror is failing, or more than three sync intervals behind, raises pull_request_mirror_stale at review. It clears on recovery. The hourly compliance sweep catches staleness that no event announces.