What PipelineSpend reads
The current product uses a least-privilege GitHub App with metadata, contents, and Actions read access. It can discover authorized repositories, inspect workflow configuration and bounded run/job history, and retain evidence references needed to reproduce the Audit result.
The Audit path does not require GitHub write access and does not edit workflow files, dispatch jobs, cancel runs, or suppress checks.
What the report means
An observed finding means the detector found evidence matching a defined condition. It does not automatically mean the repository should change. Eligibility requires sufficient evidence and policy authority; actionability requires a safe eligible next step; a verified outcome requires post-change evidence.
- Observed evidence: what the repository/provider data shows.
- Estimated opportunity: modeled or calculated upside when a defensible basis exists.
- Actual prevented work: jobs/runtime demonstrably avoided after an intervention.
- Verified savings: receipt-backed economic outcome with authoritative pricing/accounting.
Durable evidence instead of repeated collection
When a completed Audit already has sufficient retained evidence, PipelineSpend can serve a durable reread without recollecting provider history or rerunning the Audit engine. This reduces repeated agent and operator work while preserving the original evidence lineage.