Scorecards
Write the standard. Score every service.
A standard nobody measures is a preference. Scorecards check your resources against rules you define and give each a maturity level you can argue about with evidence.
Levels and rules
Gold means everything below it passed too
A scorecard turns your standards into rules, sits each rule at a level, and hands a resource a level only when every rule at that level and below it passes. There’s no numeric score, on purpose. A level is a rank, so a service failing basic hygiene can’t flash Gold on a couple of advanced passes. The rules themselves read from three places.
Resource properties
Anything on the resource, whatever put it there: a form input, a deployment output, an API call. Has a code owner. Deployed in the last thirty days.
Plugin records
A computed aggregation over a plugin’s data, or a direct query when a rule needs one: open critical PRs over thirty days old, or whether every Datadog SLO is green.
Inventory metrics
Coverage from your asset inventory, so a rule can demand a team’s IaC coverage stays above a line, or that nothing in it is left unmanaged.
Cycloid for your team
What a measured standard changes for each reader
Name the twelve, not
the document
The problem
You publish standards and have no idea which services meet them, so enforcement turns into nagging.
With Cycloid
Rules over properties, plugin records and inventory coverage, re-checked when a property changes, on a daily pass, and on demand.
The outcome
You can name the twelve services below Bronze instead of resending the document.
A list, in the order that helps
The problem
You are told your service is non-compliant and left to work out which part, and by when.
With Cycloid
The scorecard on your resource page shows every rule with its outcome and the level it belongs to, skipped and exempted ones included.
The outcome
You fix the two rules that move you a level, not the twenty that do not.
Is it actually getting better
The problem
Maturity is anecdotal, so the readiness conversation goes to whoever is most persuasive in the room.
With Cycloid
A distribution across levels, a trend over twelve months with definition changes marked, and a breakdown by team.
The outcome
You can see whether the standard is met, and whether that is improving.
How it works
From a checklist to a measured standard
01 · Write the rules
Property comparisons, boolean logic, aggregation. Rules are parsed on save, so a typo is caught then, not six weeks later.
02 · Put each at a level
Basic, Bronze, Silver, Gold by default, and you can rename them. The ladder is cumulative, so a level means what it says.
03 · Cycloid evaluates
On every relevant change, on a daily baseline pass, and on demand. You don’t schedule anything.
04 · Read the result
Each resource shows its level and the exact rules it failed. You fix the two that move you up.
05 · Exempt where it's fair
A legacy box gets an exemption with a reason and an optional expiry, shown as exempted, never as a pass.
Two honest notes ride along with that. Scorecards evaluate, they don’t fix: a failing rule surfaces the gap and tells the people who should care, but it won’t fire a day-2 action to close it. And a Gold built on last week’s data isn’t Gold, so you decide whether stale data warns, fails the rule, or drops out of the maths.
The short version
The ladder in numbers
4
levels by default. Rename them
4
outcomes a rule can have, exemptions too
2
re-checks: on every change, once a day
12mo
of history, so you can see progress
Which services are below Silver?

Eleven, and nine of them fail the same rule. Two more are held at Bronze for different reasons.
Scorecard · Production readiness
Read as you
Common failure
No runbook URL, 9 services
Other
1 exempted, 1 skipped on stale data
Working with your assistant
Which services are below the line, and what is missing
Does the assistant get its own permissions?
No. There’s no service account and no elevated assistant role. If you can’t deploy to production, neither can the assistant you’re talking to, in Cycloid’s own assistant or any compliant MCP host.
Ask which services sit below Silver and the assistant reads the scorecard results as you, under your permissions, and hands back the resources and the rules they failed. It’s a read, so there’s nothing to approve. It’s the report you’d have built from the dashboard yourself.
And it stops where the product stops. The assistant can tell you eleven services are missing a runbook URL. It can’t set that property on all eleven, because that’s remediation, and remediation isn’t a v1 move for a person or an assistant.
Frequently asked questions
Level by level. A resource reaches a level when every rule at that level and below it passes. Exemptions count as passes, and a skipped rule simply drops out of the maths. It’s a rank, not a score.
You choose, rule by rule. Warn uses the cached figure and flags how old it is. Fail treats stale data as a failing rule. Skip drops the rule for now and shows you the reason it was skipped.
No. In v1 they compute levels, surface gaps and raise events, and people fix things. Auto-remediation waits until we’ve settled whose authority a fix runs under and what happens when it fails.
Bring the standard nobody follows
Twenty minutes, the readiness checklist from your last incident review, and the rules it becomes. Then we run it across your resources and show you the distribution, which is usually a more interesting conversation than the checklist ever was.



