Skip to content
SAUTERASAUTERA
← Blog
Field Notes··7 min read

Unknown Is an Answer: Honest Infrastructure Trust

A trust model that always returns a confident number is easy to build and impossible to trust. The honest move is to say when coverage isn't there yet.

By Joe Augustine

Listen to this post

There is a quiet decision buried inside every scoring system, and almost everyone makes it the wrong way.

A false green is worse than no green

A score is a claim. When you hand someone a high score for a device you can barely see, you are making a claim you have no basis for — and worse, you are hiding the fact that you can't see it.

The reader has no way to tell a genuine "this is healthy" from a manufactured "we didn't look closely and decided to assume the best." Both come back as the same comforting number. That is the core failure: the number erases the difference between knowledge and assumption.

That is how estates end up with confident coverage over their best-understood systems and silent blind spots over everything else — and no signal anywhere that the blind spots exist. The parts of your infrastructure you already manage well get watched closely. The parts you don't understand get a shrug dressed up as a verdict.

This matters because the cost of a wrong green is not symmetric. A device flagged as risky gets attention it may not need — annoying, but cheap. A device marked safe when it is unseen gets no attention at all, right up until it becomes the incident. Security research has long held that most breaches trace back to known, unaddressed exposure — not exotic attacks, but the ordinary gaps nobody was looking at. A false green is a machine for manufacturing exactly those gaps.

Any model of infrastructure trust that cannot distinguish "observed and healthy" from "unobserved and assumed" is not measuring trust. It is laundering ignorance into confidence.

What the score is actually claiming

It helps to be precise about what a trust score asserts. A score is not a mood or a vibe. It is a defensible statement about a device, backed by evidence, that someone downstream will act on.

We've written before about what the trust score measures and the trust assertion it stands behind. The short version: every score is a promise that you looked, you saw enough, and this is what the evidence says.

The problem is that traditional scoring systems collapse two very different situations into one output:

  • Observed and good — you have current, sufficient signal, and it says the device is healthy.
  • Observed and bad — you have current, sufficient signal, and it says the device is not.
  • Not observed at all — you have no meaningful signal, so the model guesses, usually optimistically.

The first two are legitimate verdicts. The third is not a verdict; it is a default. And when the default renders as the same green as a real pass, the score stops being a claim you can defend. It becomes a claim you merely hope holds up.

This is the difference between a trust decision and a trust guess. A trust decision has a chain of evidence behind it. A guess has a placeholder.

The measurement model abstains on purpose

SAUTERA's measurement model handles this differently, and it is one of the design choices I am most deliberate about. When coverage is too thin to support a verdict, the device does not get an optimistic default. It reads Unknown.

Unknown is not a failure state and it is not a low score. It is a precise, honest statement: we have not observed enough to conclude, and we are not going to pretend otherwise.

It sits alongside the real verdicts — trusted, uncertain, untrusted — as a first-class outcome. Not-yet-knowing is a real condition of the world, and a model that cannot express it is lying by omission. Confidence, in this framing, is not how good the number looks. It is how much evidence stands behind it.

This is why we separate the verdict from the confidence attached to it. A device can be provisionally healthy with low confidence, or clearly untrusted with high confidence. Folding those two axes into a single number is where most scoring systems go wrong — the output implies certainty the model never earned. Keeping them separate is closer to how careful practitioners already reason: calibrated uncertainty is a feature, not a weakness.

Unknown is the most actionable state you have

Here is the part people miss: Unknown is actionable in the cleanest possible way. It tells you exactly where to point attention.

A red verdict says something is wrong but rarely says what to do first. An Unknown is unambiguous. The fix is always the same shape: raise coverage until the model can conclude.

Concretely, an Unknown resolves through one of a few moves:

  • Install or reconnect the sensor that should be reporting on the device.
  • Add agentless credentials so the platform can query it directly.
  • Close the network path or permission gap that is blocking collection.
  • Confirm the asset still exists and is in scope at all.

The moment there is enough signal, the Unknown resolves into a real answer — trusted, uncertain, or untrusted. You are never guessing. You are either concluding from evidence or being told, plainly, that the evidence isn't there yet.

This is what makes Unknown a coverage instrument, not just a scoring nicety. The count of Unknowns in an estate is a direct readout of your observability debt. Drive that number down and you are not gaming a metric — you are literally seeing more of your infrastructure. This is the operating loop behind continuous, observed, enforced trust: you cannot enforce what you have not observed, and you should not assert what you cannot enforce.

Contrast this with a scenario every operator recognizes. A medical device or an OT controller shows up on the network. It cannot host a sensor. Legacy scanning barely touches it. A naive model marks it green by default and moves on. Six months later it is the pivot point in an incident review, and the after-action question is brutal: why did the dashboard say this was fine? The honest answer is that the dashboard never knew. It just refused to say so.

Why this is the whole game

Trust is a claim you have to be able to defend. The fastest way to make it indefensible is to assert it where you have no grounds.

A model that knows the boundary of its own knowledge — that says "I don't know" out loud instead of smoothing it into a number — is not a weaker model. It is the only kind strong enough to put in front of someone who will be hurt if it's wrong.

This is also where ITCM (IT continuous management) earns its keep over point-in-time posture checks. A one-time scan can afford to guess, because nobody expects it to be current. A continuous model cannot, because it is standing behind a live claim every minute of every day. A device that was right at design time can be wrong by Tuesday, and a system that never admits Unknown will keep asserting the design-time answer long after it stopped being true.

Honesty about coverage is also what makes the output audit-ready. When compliance evidence is not a fire drill, it is because your trust claims already carry their own provenance — including an explicit record of what you could not see. An auditor trusts a system that says "unknown, here's why" far more than one that is uniformly, suspiciously green.

Unknown is an answer. Often it is the most honest one available, and honesty is the only foundation a trust system is allowed to be built on.

The takeaway

  • A trust score is a claim you must be able to defend. A confident number over an unobserved device is not a claim — it is a guess wearing a verdict's clothes.
  • Unknown is a first-class outcome, not a failure. It means we have not observed enough to conclude, and we will not pretend otherwise.
  • Separate the verdict from its confidence. A model that expresses calibrated uncertainty is stronger, not weaker.
  • Unknown is the most actionable state you have: it points straight at a coverage gap you can close with a sensor, credentials, or a network path.
  • The count of Unknowns is your observability debt made visible. Drive it down and you are seeing more of your real infrastructure — not gaming a metric.
  • For continuous infrastructure trust and ITCM, admitting Unknown is what keeps a live claim honest and audit-ready.

Audit your estate for false greens: count the devices scoring high on thin coverage, and see how many should read Unknown. Start with what the trust score actually measures.

#infrastructure trust#confidence#coverage#measurement
SAUTERA mark

Written by

Joe Augustine

Author of the Infrastructure Trust Architecture (ITA) and the Infrastructure Trust Conveyance Mechanism (ITCM) — the standard organizations use to decide whether infrastructure can be trusted.

About the author

Follow the work

Read the next one

New perspectives on infrastructure trust and updates to the ITA / ITCM framework, by email.

Occasional. No spam. Unsubscribe anytime.

← All perspectives