Ask your SCA tool, your SAST tool, and your secrets scanner how many high-severity issues you have, and you will get three answers computed three ways against three inventories. None of them map cleanly to the question leadership is actually asking: which repositories and pipelines are in trouble, and is it getting better?
Posture only becomes comparable when it is normalized — pulled out of vendor presentation and reshaped around your estate.
What normalization actually means
- One severity scale, with explicit mapping from each provider's scheme.
- Findings attached to your entities — repositories, projects, pipelines — not to vendor-side object IDs.
- Freshness tracked per data source, so a stale sync is visible instead of silently wrong.
- Counts precomputed into a read model, so answering posture questions does not mean one vendor API call per table row.
The anti-pattern: dashboard-by-API
Dashboards that call vendor APIs live are slow, rate-limited, and flaky — so teams stop opening them. Exports to spreadsheets freeze a moment in time and rot. Both approaches couple your visibility to each vendor's availability and each vendor's data model.
How Kangl models posture
Kangl synchronizes provider findings asynchronously into a normalized repository-level read model: severity counts, freshness, and provider state, keyed to your Azure DevOps estate. The portal reads the model, not the vendor — posture answers arrive in milliseconds, stay tenant-isolated, and feed the same policy engine that decides whether a build fails.

