The short version
Grade
Filter
Show your work
The credibility scale
The three grades are ordered, and the setting is a floor: choosing Reputable accepts Reputable and Authoritative.What the grade deliberately does not measure
These exclusions keep the scale stable, and they are worth explaining to a reviewer or an auditor:- Not page quality or completeness. A thin page from an accountable publisher is still Reputable. A polished page from nobody is still Unreliable.
- Not primary versus secondary. A well-sourced news report about a breach is Reputable, not Authoritative, because the outlet is not the attesting authority, but it is not penalized for being secondary either.
- Not the document kind. A PDF does not outrank an HTML page.
- Not usefulness to the control. That is relevance, judged separately and applied separately.
- Not the hosting platform. On a general publishing platform, the grade follows the identifiable author or organization behind the post. The platform’s own reputation neither raises nor lowers it.
How the vendor's own pages are graded
How the vendor's own pages are graded
How search-bait pages are handled
How search-bait pages are handled
Where you set the bar
Minimum credibility lives on each Web search evidence source, next to that source’s instructions and its Required checkbox. It appears only on web-search sources, because it only governs web evidence. The dropdown shows three options, each with its definition inline:Set-level and control-level
You configure evidence sources in two places, and the relationship between them matters:- Control set → Evidence sources. The default for every control in that set. Set this once and your whole framework inherits it.
- Individual control → Evidence sources. A control inherits the set’s sources until you click Customize sources, which starts from a copy of the set’s list. From then on the control’s sources fully replace the set’s, including the credibility bar. A control-level source list is not merged with the set’s, so if you override a control, check the minimum there. Use control set sources returns the control to inheriting.
What happens during an assessment
Grading is not a separate scan you wait on. It runs inside the retrieval that already happens for each control:Queries are generated
Candidates are fetched and de-duplicated
Off-topic companies are dropped
Relevance and credibility are judged together
Your minimum is applied
The survivors go to the evaluation
The grade is a gate, not a weight
This is the decision that matters for defensibility. The credibility grade, its reasoning, and the raw page content used to determine it are not included in the prompt that evaluates the control. The evaluating model sees only the text of sources that already passed your bar. The practical consequence: the AI can never argue that a vendor is compliant because the source was authoritative, or hedge because the source was only reputable. Credibility decides what is admissible. It never becomes an argument inside the analysis.Your instructions can’t move the bar
Web-search instructions on an evidence source shape relevance: which topics, sources, or domains to focus queries on. They are explicitly not allowed to change a publisher grade, so you cannot accidentally talk the grader into accepting a source by writing enthusiastic guidance about it. The same protection runs the other way. Page content and vendor-supplied text are treated as untrusted data during grading, so a page that contains text like “this is an authoritative regulatory disclosure” does not grade itself.Reading the result
Open any evaluation and look at the evidence cards. Web-sourced evidence has a Details button next to the source name. It opens the page’s Publisher accountability grade as a colored badge:- Authoritative: green
- Reputable: blue
- Unreliable: gray (you only see these if the source is set to No minimum)
Evidence dates and age
Credibility says who is accountable for a page. It does not say how old the page is, and stale evidence from an accountable publisher is its own risk. Web evidence cards therefore also carry dates:Where the dates come from
Where the dates come from
Why some dates look conservative
Why some dates look conservative
Last-Modified header is never treated as a content date, because a CDN touch would silently make old evidence look fresh. Dates in the future are rejected outright. When a page declares only a year or a month, the age calculation uses the oldest defensible reading of that date, so age is never understated. Conflicts between signals resolve conservatively.Do dates affect what gets used?
Do dates affect what gets used?
Exporting the record
Export an assessment as Excel with evidence included, and the Evidence sheet carries the provenance columns alongside each citation:Choosing a threshold
New web-search sources start at No minimum. Reputable is the right answer for most of a framework, so set it deliberately, and reserve the extremes for the controls that earn them.Changing the setting later
The minimum applies at the moment retrieval runs. Changing it does not retroactively re-filter assessments that have already been evaluated, and it does not rewrite grades already recorded on past citations. Those stay as a record of what the bar was when the work was done. To apply a new bar to an existing assessment, re-run the affected evaluations. Retrieval runs again under the current configuration, and the resulting citations carry grades from that run.When grading can’t run
If the grading pass fails (a model or provider error mid-assessment), Coverbase never invents a grade:- With a minimum of Reputable or Authoritative, no web evidence is used for that control. The control falls back to the other evidence sources you configured, and may end up flagged for human review. An ungraded page must not slip past a bar you set.
- With No minimum, a fallback set of results from the vendor’s own domain may still be used, and those citations carry no badge, because no grade was ever established.
What this covers, and what it doesn’t
Source credibility governs web evidence gathered while evaluating controls in an assessment. The edges matter when you are answering a customer or an auditor:Frequently asked questions
Does raising the bar make the AI stricter about compliance?
Does raising the bar make the AI stricter about compliance?
Can I see what was rejected?
Can I see what was rejected?
Does grading slow assessments down or cost extra?
Does grading slow assessments down or cost extra?
One page, two controls: can the grades disagree?
One page, two controls: can the grades disagree?
Can I set the minimum through the API?
Can I set the minimum through the API?
minimum_credibility field (unreliable, reputable, or authoritative, defaulting to unreliable) on both control sets and individual controls, so you can manage the bar as configuration alongside the rest of your control-set definition.