Ask your SCA tool, your SAST tool, and your secrets scanner how many high-severity issues you have, and you will get three answers computed three ways against three inventories. None of them map cleanly to the question leadership is actually asking: which repositories and pipelines are in trouble, and is it getting better?

Posture only becomes comparable when it is normalized — pulled out of vendor presentation and reshaped around your estate.

What normalization actually means

  • One severity scale, with explicit mapping from each provider's scheme.
  • Findings attached to your entities — repositories, projects, pipelines — not to vendor-side object IDs.
  • Freshness tracked per data source, so a stale sync is visible instead of silently wrong.
  • Counts precomputed into a read model, so answering posture questions does not mean one vendor API call per table row.

The anti-pattern: dashboard-by-API

Dashboards that call vendor APIs live are slow, rate-limited, and flaky — so teams stop opening them. Exports to spreadsheets freeze a moment in time and rot. Both approaches couple your visibility to each vendor's availability and each vendor's data model.

How Kangl models posture

Kangl synchronizes provider findings asynchronously into a normalized repository-level read model: severity counts, freshness, and provider state, keyed to your Azure DevOps estate. The portal reads the model, not the vendor — posture answers arrive in milliseconds, stay tenant-isolated, and feed the same policy engine that decides whether a build fails.

KEEP READING