Skip to content

Reporting & exports

Reporting turns the records in Gamut into outputs people act on, a board view of AI governance maturity, and workpaper-grade exports for audit and assurance. Because reports are generated from the connected records, every conclusion can be traced back to the evidence behind it.

A report draws the lifecycle together into a single, practical view:

  • AI inventory: the systems in scope, their owners and lifecycle status.
  • Risk: the classification picture across systems.
  • Framework scores: per-system conformance, compliance or maturity, rolled up to the workspace using the same coverage-inclusive scoring as the source assessment at generation time.
  • Evidence quality: how well governance claims are supported.
  • Findings: open deficiencies and exceptions.
  • Remediation progress: what is being fixed and how far along it is.
  • Readiness priorities: where to focus next.

Rather than one generic report, Gamut produces purpose-built packs, each composed of a different set of sections for a different audience:

PackBuilt for
Full assessmentThe complete picture: every section, for a deep review.
Framework focusA single framework in depth (for example GTSAF, EU AI Act, ATF).
ExecutiveLeadership: dashboard, estate, framework, evidence, findings, decisions, roadmap.
Board packBoard oversight: adds estate, agentic and gateway posture to the executive view.
Board summaryA concise board-level summary.
Evidence packEvidence-centred: controls, evidence, findings and supporting workflow.
Control testingThe control-testing record for assurance work.
Agentic snapshotThe agentic posture: agents, ATF, gateway decisions and runtime evidence.

Each pack selects only the sections relevant to its purpose, so a board pack is not a 200-page audit file and an evidence pack is not a one-page summary.

  1. Open Reporting in the workspace whose records you want to report on.
  2. Choose a pack type for your audience (full assessment, framework focus, executive, board pack, evidence pack, control testing, or agentic snapshot).
  3. Set the framework scope (all frameworks or a single one) and, optionally, enable the scores-only AI narrative.
  4. Generate the pack. Each run gets a run ID and traceability metadata.
  5. Export it (subject to the export.report / export.workpaper permissions) for boards, clients or audit.

Because reports are built from connected records, regenerate one whenever the underlying assessment, evidence or findings change rather than maintaining a separate document.

Reporting serves two audiences at once, from the same records:

  • Boards and leadership get a concise picture of AI governance maturity, exposure and the decisions required of them, without engineering detail.
  • Auditors and reviewers get traceable, workpaper-grade outputs that connect each conclusion back to its underlying evidence.

Because both views draw on the same connected records, they can be reconciled to the same source state and generation time. Different pack purposes may summarise that state differently, and any pack becomes historical when the source records subsequently change.

Every generated report carries run-level metadata, a run ID, the generation timestamp, the assessment, the framework scope and the pack type, so any export can be located, reproduced and defended. A report is not an anonymous PDF; it is a dated, identified artefact tied to the records it was built from.

A report can optionally include an AI-generated narrative summary. To protect confidentiality, that narrative is generated from assessment statistics only, scores, counts, framework scope and posture figures, and never from free-text governance content. No confidential record text is sent to the model, and the generation is proxied server-side so model-provider keys are never exposed. See AI assistance & data handling.

Reports are produced as governed HTML and can be exported for distribution and record-keeping, for board packs, client assurance, internal audit and external review, subject to the export.report and export.workpaper permissions. Because the underlying records are connected, an export reflects the traceable source state at its recorded generation time. Regenerate it after material assessment, evidence, finding or remediation changes.

Traditional governance produces a report once a year. Because Gamut keeps records connected and current, reporting becomes something you run whenever you need it, supporting the Improve stage with a view of progress over time, not just a single snapshot.