genai
SECURITY LAB
DocsFor teamsCoverage and reporting

Coverage and reporting

See exactly which OWASP categories your team has covered, find the gaps, and export the evidence.

genaisecuritylab.com/team/coverage
Team coverage across the OWASP LLM Top 10, with the biggest gaps called out.
Team coverage across the OWASP LLM Top 10, with the biggest gaps called out.

The coverage view

Coverage maps what your team has actually done against the OWASP LLM Top 10 (2026), plus the MCP and agentic categories, one framework at a time. Switch frameworks to see a completely different map of the same team.

View it for the whole team, or narrow it to one group, one cohort, or a single member — same categories, same bands, a different slice of people. Team Admins and Auditors can open the full view; a regular member only ever sees their own progress.

Reading the numbers

A coverage score is built from bands, not attempts. Attempting a category's labs isn't the same as covering it — only a result counts, and the three bands carry different weight.

BandWhat it does to coverage
objective metCounts the category as covered
partialMoves the needle, but doesn't close the category out
not metNo credit — the gap stays open

See how grading works for exactly what earns each band. Coverage can also go quiet — a category nobody has attempted recently can fall due for refresh even if it was fully covered before, so treat the view as a living picture, not a one-time checkbox.

Find the gaps

The categories with the lowest coverage are your gaps — the ones nobody, or almost nobody, has passed. A gap doesn't always mean nobody has tried; it can equally mean everyone came back with a partial or a not met. Either way, it's the most useful thing on the page, because it tells you exactly what to do next.

Close the loopAssign the learning path behind a gap category straight from the coverage view, instead of hunting for it separately in assignments.

Exports and the evidence trail

Export a coverage report as a PDF for a leadership review, or as a CSV when you need the rows for your own tooling. Both can be scoped to one framework — OWASP LLM, MCP, or agentic — so you hand an auditor exactly the evidence they asked for, not your team's whole history.

Coverage reports are a snapshot of what your team can do right now. For the chronological record of who did what and when — every invite, assignment, and role change — see the audit log, which is where the compliance trail actually lives.

Was this page helpful?
Previous
Assignments