Reporting & exports
Reporting turns the records in Gamut into outputs people act on, a board view of AI governance maturity, and workpaper-grade exports for audit and assurance. Because reports are generated from the connected records, every conclusion can be traced back to the evidence behind it.
What reports show
Section titled “What reports show”A report draws the lifecycle together into a single, practical view:
- AI inventory: the systems in scope, their owners and lifecycle status.
- Risk: the classification picture across systems.
- Framework scores: per-system conformance, compliance or maturity, rolled up to the workspace using the same coverage-inclusive scoring as the source assessment at generation time.
- Evidence quality: how well governance claims are supported.
- Findings: open deficiencies and exceptions.
- Remediation progress: what is being fixed and how far along it is.
- Readiness priorities: where to focus next.
Pack types
Section titled “Pack types”Rather than one generic report, Gamut produces purpose-built packs, each composed of a different set of sections for a different audience:
| Pack | Built for |
|---|---|
| Full assessment | The complete picture: every section, for a deep review. |
| Framework focus | A single framework in depth (for example GTSAF, EU AI Act, ATF). |
| Executive | Leadership: dashboard, estate, framework, evidence, findings, decisions, roadmap. |
| Board pack | Board oversight: adds estate, agentic and gateway posture to the executive view. |
| Board summary | A concise board-level summary. |
| Evidence pack | Evidence-centred: controls, evidence, findings and supporting workflow. |
| Control testing | The control-testing record for assurance work. |
| Agentic snapshot | The agentic posture: agents, ATF, gateway decisions and runtime evidence. |
Each pack selects only the sections relevant to its purpose, so a board pack is not a 200-page audit file and an evidence pack is not a one-page summary.
Generating a report
Section titled “Generating a report”- Open Reporting in the workspace whose records you want to report on.
- Choose a pack type for your audience (full assessment, framework focus, executive, board pack, evidence pack, control testing, or agentic snapshot).
- Set the framework scope (all frameworks or a single one) and, optionally, enable the scores-only AI narrative.
- Generate the pack. Each run gets a run ID and traceability metadata.
- Export it (subject to the
export.report/export.workpaperpermissions) for boards, clients or audit.
Because reports are built from connected records, regenerate one whenever the underlying assessment, evidence or findings change rather than maintaining a separate document.
Two audiences, one source
Section titled “Two audiences, one source”Reporting serves two audiences at once, from the same records:
- Boards and leadership get a concise picture of AI governance maturity, exposure and the decisions required of them, without engineering detail.
- Auditors and reviewers get traceable, workpaper-grade outputs that connect each conclusion back to its underlying evidence.
Because both views draw on the same connected records, they can be reconciled to the same source state and generation time. Different pack purposes may summarise that state differently, and any pack becomes historical when the source records subsequently change.
Traceability metadata
Section titled “Traceability metadata”Every generated report carries run-level metadata, a run ID, the generation timestamp, the assessment, the framework scope and the pack type, so any export can be located, reproduced and defended. A report is not an anonymous PDF; it is a dated, identified artefact tied to the records it was built from.
Optional AI narrative
Section titled “Optional AI narrative”A report can optionally include an AI-generated narrative summary. To protect confidentiality, that narrative is generated from assessment statistics only, scores, counts, framework scope and posture figures, and never from free-text governance content. No confidential record text is sent to the model, and the generation is proxied server-side so model-provider keys are never exposed. See AI assistance & data handling.
Exports
Section titled “Exports”Reports are produced as governed HTML and can be exported for distribution and record-keeping, for
board packs, client assurance, internal audit and external review, subject to the
export.report and export.workpaper permissions. Because the
underlying records are connected, an export reflects the traceable source state at its recorded
generation time. Regenerate it after material assessment, evidence, finding or remediation changes.
From point-in-time to continuous
Section titled “From point-in-time to continuous”Traditional governance produces a report once a year. Because Gamut keeps records connected and current, reporting becomes something you run whenever you need it, supporting the Improve stage with a view of progress over time, not just a single snapshot.
- Evidence & findings: the records reports surface.
- Model cards: model-level detail for reports.
- Plans & entitlements: what controls export rights.