The Precedents Lead With A Grade, Scale By Selling The Same Thing Larger, Ship A Documented JSON Output, And The Probe And Finding Vocabulary Already Exists
Summary
Six free assessment services examined on the axes the memo asked about. Their shared shape: one small input, a single legible verdict above the fold with the evidence beneath it, no account for the basic case, and a result the visitor wants to show somebody. The ladder that reaches organisations sells the same thing larger rather than something different. The services that reach engineering publish a documented machine-readable output and run where the thing lives. The finding to act on immediately: the probe and finding vocabulary proposed the same day already exists in OpenSSF Scorecard with definitions close enough to adopt, and that project replaced a score with structured findings for the reason this corpus gave against a levels ladder. Independence is the thing worth charging for. Acted on here: the finding shape adopts probe, message, outcome, remediation and location, and adds reversibility and tier.
Key concepts
- The finding shape — Scorecard's, plus reversibility and tier
- The verdict as a statement — a count, not a grade
- Independence is what costs — the evidence tier as a price list
- The record — what transferred and what did not
Key ideas
- The grade comes first: a visitor who has to read to discover whether they are in trouble leaves first.
- Nothing on the ladder is a feature an individual cannot have; it is a quantity an individual does not need.
- The import and export schema decides whether this reaches teams, and it should exist before the site does.
- Adopt probe and finding with their definitions, cite the source, and diverge only where the subject differs.
- A single number cannot say which of its inputs moved; lead with a verdict, return structured findings.
- A letter grade probably does not transfer: nobody has calibrated a scale, so the verdict is a statement.
On this site
Shapes /probes/schema/ and the verdict on /authorised/; the record is authorised/README.md.