A finding is a fact: this dependency has this CVE at this severity. A decision is a commitment: this build does not ship. Most AppSec programs have industrial-grade machinery for producing facts and folklore for producing decisions — a threshold someone set in a console, an if-statement in a template, a Slack agreement from last spring.
Anatomy of a decision layer
- Inputs: normalized findings joined to estate context — repository, pipeline, tenant.
- Policy: explicit thresholds and modes, stored and versioned centrally.
- Evaluation: deterministic, server-side, producing an explicit verdict per pipeline run.
- Distribution: the verdict projected to every enforcement point — build gate, PR status, dashboards.
- Record: verdict, policy version, and inputs retained for later reconstruction.
Why the layer must be separate from the scanner
Scanner-embedded policy fragments across vendors and dies in migration. Pipeline-embedded policy forks per team. A separate decision layer is the only place where multi-provider findings, organizational risk appetite, and estate context can meet — and the only place a consistent audit story can be told.
This is the core of what Kangl is
Everything else in Kangl — inventory, provider operations, posture sync, drift repair — exists to feed and enforce this layer: backend-authoritative policy that turns normalized findings into audited decisions across the Azure DevOps estate.

