A finding is a fact: this dependency has this CVE at this severity. A decision is a commitment: this build does not ship. Most AppSec programs have industrial-grade machinery for producing facts and folklore for producing decisions — a threshold someone set in a console, an if-statement in a template, a Slack agreement from last spring.

Anatomy of a decision layer

  • Inputs: normalized findings joined to estate context — repository, pipeline, tenant.
  • Policy: explicit thresholds and modes, stored and versioned centrally.
  • Evaluation: deterministic, server-side, producing an explicit verdict per pipeline run.
  • Distribution: the verdict projected to every enforcement point — build gate, PR status, dashboards.
  • Record: verdict, policy version, and inputs retained for later reconstruction.

Why the layer must be separate from the scanner

Scanner-embedded policy fragments across vendors and dies in migration. Pipeline-embedded policy forks per team. A separate decision layer is the only place where multi-provider findings, organizational risk appetite, and estate context can meet — and the only place a consistent audit story can be told.

This is the core of what Kangl is

Everything else in Kangl — inventory, provider operations, posture sync, drift repair — exists to feed and enforce this layer: backend-authoritative policy that turns normalized findings into audited decisions across the Azure DevOps estate.

KEEP READING