The channels
Coverage matrix
Which channel catches which kind of usage:Multi-source corroboration
When several channels detect the same capability, they merge into a single asset carrying multiple evidence trails:discovery_source field is an array — every channel that saw it. That array is what drives confidence scoring.
How assets get merged
The collector does not create a new asset per event. It looks for an existing asset matching a merge key built from vendor, model, use case, business unit, and calling service. Matching events fold into the existing asset and extend its evidence. Two behaviours worth knowing:- Environments stay separate. A
productionasset and astagingasset are distinct, because conflating them would misrepresent your risk surface. - The highest data classification wins. If one event reports
internaland another reportsconfidentialfor the same asset, the asset isconfidential. Classification only ever ratchets upward on merge.
This is why the metadata you set when constructing an SDK client matters so much. Business unit and use case are part of the merge key — get them wrong and one real system fragments into several registry entries. See Python SDK.