Coverage and reporting
See exactly which OWASP categories your team has covered, find the gaps, and export the evidence.

The coverage view
Coverage maps what your team has actually done against the OWASP LLM Top 10 (2026), plus the MCP and agentic categories, one framework at a time. Switch frameworks to see a completely different map of the same team.
View it for the whole team, or narrow it to one group, one cohort, or a single member — same categories, same bands, a different slice of people. Team Admins and Auditors can open the full view; a regular member only ever sees their own progress.
Reading the numbers
A coverage score is built from bands, not attempts. Attempting a category's labs isn't the same as covering it — only a result counts, and the three bands carry different weight.
| Band | What it does to coverage |
|---|---|
| objective met | Counts the category as covered |
| partial | Moves the needle, but doesn't close the category out |
| not met | No credit — the gap stays open |
See how grading works for exactly what earns each band. Coverage can also go quiet — a category nobody has attempted recently can fall due for refresh even if it was fully covered before, so treat the view as a living picture, not a one-time checkbox.
Find the gaps
The categories with the lowest coverage are your gaps — the ones nobody, or almost nobody, has passed. A gap doesn't always mean nobody has tried; it can equally mean everyone came back with a partial or a not met. Either way, it's the most useful thing on the page, because it tells you exactly what to do next.
Close the loopAssign the learning path behind a gap category straight from the coverage view, instead of hunting for it separately in assignments.
Exports and the evidence trail
Export a coverage report as a PDF for a leadership review, or as a CSV when you need the rows for your own tooling. Both can be scoped to one framework — OWASP LLM, MCP, or agentic — so you hand an auditor exactly the evidence they asked for, not your team's whole history.
Coverage reports are a snapshot of what your team can do right now. For the chronological record of who did what and when — every invite, assignment, and role change — see the audit log, which is where the compliance trail actually lives.