'How many vulnerabilities do we have?' is the most-asked and least-useful question in AppSec. The number moves when the scanner updates its rules, when a big repo is onboarded, when a feed has an outage — none of which say anything about your program. The durable questions are about the machine, not the weather.
Four metrics worth reporting
- Coverage: eligible pipelines and repositories actually enrolled in scanning — with the denominator stated.
- Enforcement: share of enrolled pipelines where policy actively gates builds versus monitor-only.
- Drift: how often intended state diverged from observed state, and time-to-repair.
- Freshness: age of the posture data every decision and dashboard reads from.
Why these survive scrutiny
Each metric has a controllable denominator and an owner. Coverage can be driven to a target; enforcement expresses risk appetite explicitly; drift measures operational integrity; freshness bounds how wrong you can be. An auditor can verify all four from records — if records exist.
Getting them without a spreadsheet farm
These metrics fall directly out of a control plane that already holds the inventory, the enrollment state, the sync results, and the audit history. In Kangl, coverage and enforcement are queries over managed-pipeline state, drift comes from the reconciliation loop, and freshness is tracked per posture sync — no quarterly manual census required.

