Skip to content
Assay
Sign inTalk to us

Assay · System documentation

How a decision report works

What a buyer sets up

How a bar decides

A bar is an organisation's written-down definition of "good enough". Assay does not supply one: the buyer authors it, publishes it, and binds it to what it applies to.

Bars

A bar states the standard a piece of software must meet. It is authored as a draft, and published when it is ready. Once published, a bar version is immutable — changing a standard means publishing a new version, never editing one that reports already refer to.

This is the same discipline that governs measurement itself. A requirement that could be edited after the fact would make every past verdict unverifiable, because nobody could tell what was actually being asked at the time.

Bindings — where a bar applies

A bar on its own decides nothing. A binding attaches a specific published version of a bar to a specific scope, and that is what brings it into force.

Bindings exist at different altitudes, because organisations do not have one standard for everything:

  • Organisation-wide — a regulatory or internal baseline that reaches everything unconditionally.
  • Customer-scoped — applies through a particular engagement or relationship.
  • Product-scoped — applies to the repositories that make up a product.

Where several bindings reach the same target, the resolution is deterministic — the same target and the same set of bindings always produce the same applicable standard. A binding can be revoked, at which point it stops applying to future reports; reports already issued under it are untouched.

The verdict is derived, never stored

No view holds a score. Verdicts are derived when a report is built, from the signed evidence and the bound bar. Nothing in the governance surface caches a number, so a bar change cannot silently rewrite what an earlier report said, and no stale score can leak into a new one.

What this means in practice

Two buyers can assess the same supplier evidence and reach different verdicts, correctly, because they require different things. The evidence is a fact about the software; the bar is a decision by the buyer. Keeping them separate is what allows one measurement to serve many buyers without anyone's standard being imposed on anyone else.