Delivery automation
GitHub Actions workflow count, workflow files, and release presence.
The scan does not execute builds or prove that a workflow succeeds.
Point a fine-grained read-only token at a repository. The scan reports what it can see, and says when it cannot.
Repository intake
GitHub does not expose the repository controls needed for a useful review without authentication. Use a fine-grained token restricted to the repository and revoke it after the scan. The disclosure beside the field lists every permission used.
Operator's note
“A score is useful only when every point can be traced back to an observable signal. Unknown data stays unknown.”
Inspection surface
GitHub Actions workflow count, workflow files, and release presence.
The scan does not execute builds or prove that a workflow succeeds.
Dependabot, CodeQL, SECURITY.md, and secret scanning.
A repository signal is not a penetration test or a software-supply-chain certification.
CODEOWNERS and default-branch protection where the supplied token can read it.
Unavailable administration data is reported as missing visibility, not a verified failure.
README depth, CONTRIBUTING, LICENSE, and security-policy presence.
File presence cannot prove that the content is current or followed by the team.
Recent contribution cadence, issue volume, and repository language.
Activity is context, not a proxy for engineering quality on its own.
Evidence model
The model rewards visible repository practices. It also records when GitHub does not expose a control to the supplied token, so lack of access is not dressed up as certainty.
This is a directional repository-surface review. It does not inspect runtime infrastructure, execute code, prove policy enforcement, or replace a security assessment.
The request accepts a GitHub owner/repository path and uses the token only against the fixed GitHub REST API origin.
Metadata, selected policy files, workflow inventory, releases, issues, and available security settings are read server-side.
Every control the token cannot read stays unknown: branch protection, secret scanning, workflow inventory, contribution cadence, and each policy file the API refuses. None of them is treated as a verified pass or a failure.
The scoring rules are versioned and every point traces to an observable signal. The denominator shrinks when GitHub does not expose a control, and the result states how many points it covered.
ITSailor field library
Start with practical, downloadable material. The complete library remains visible below, including every available free pack and diagnostic.
25 free resources in the verified catalog. Reviewed 2026-07-18.
Turn Claude Code into a working member of your IT operations team: 7 specialist agents, 5 guided skills, a project-memory template and the safety rails for regulated EU environments.
7 agents · 5 guided skills · safety contract
Downloadable packTwelve model-neutral system prompts for IT operations and security workflows.
12 model-neutral system prompts · configuration guide
Downloadable packTwo sanitised n8n workflow exports, a broken-flow triage runbook and the operating notes needed to adapt them safely.
2 sanitised n8n exports · triage runbook · operating notes
Discovery, architecture, security baseline, policy and operating-review templates for Azure platform planning.
6 planning templates · policy intent · operating review
Downloadable packAssess AVD requirements, architecture, FSLogix recovery, security, cost and regional outage readiness.
6 planning templates · recovery · cost and outage review
Downloadable packPlan, run and evidence recovery drills without inventing the process during an incident.
6 working templates · drill evidence · recovery validation
Downloadable packThe six-tab Excel model ITSailor uses to surface cloud + SaaS waste and rank the savings backlog. Real formulas, not a static sheet.
6-tab Excel model · formulas · prioritised savings backlog
Downloadable packTrack renewals, audit licence use, assess new vendors and prepare evidence before commitment windows close.
6 working templates · renewal calendar · audit and reclaim procedures
Downloadable packStructure discovery, pilot waves, cutover, rollback and hypercare for cloud and Microsoft 365 migrations.
7 working templates · cutover gates · rollback procedure
Downloadable packStructured decision matrices for mapping regulatory gaps.
Gap analysis · compliance mapping · incident taxonomy
Downloadable packDiscovery, architecture, organisation policy and operating-review templates for a governed Google Cloud foundation.
6 planning templates · policy set · operating review
Downloadable packRead-only PowerShell and KQL examples for Secure Score, inactive licensed users and failed sign-in bursts.
2 read-only Graph scripts · 1 KQL query · permissions guide
Downloadable packVersioned workpapers for reviewing Microsoft 365 controls, evidence, permissions and remediation priorities.
38 source-linked checks · permission audit · gap analysis
Downloadable packOperational templates for triage, device isolation, email purge, identity compromise and detection review.
7 working templates · 4 response procedures · review records
Downloadable packThree KQL detections plus the catalogue, tuning, hunting and review records needed to operate them.
3 KQL samples · 2 runbooks · monthly operating review
Downloadable packAWS Terraform scaffolding, a BCDR SOP and an infrastructure decision matrix.
AWS Terraform baseline · BCDR SOP · decision matrix
Downloadable packRecord ownership, architecture, handover evidence and supplier-exit questions before a dependency becomes lock-in.
4 neutral templates · ownership map · handover and supplier-exit checks
Get an AI deployment verdict, risk register, and 90-day plan from what you declare.
18 declared controls · risk register · unknowns stay unknown
Interactive toolModel one workflow from your own operating numbers and see the range it produces.
Your own baseline · three scenarios · 7 scored questions of 10
Interactive toolInspect one GitHub repository across five evidence families.
5 evidence families · unreadable controls stay unknown · token not stored
Interactive toolEnsure your emails hit the inbox, not the spam folder.
Live DNS checks · 29 DKIM selectors
Interactive toolReview your Microsoft 365 security posture across 38 risk-weighted controls.
38 checks · 6 categories · source-linked assessment
Interactive toolIdentify access leaks and data risks for departing users.
Risk profile · gap matrix · remediation timeline
Interactive toolFind every SaaS you run - and pay for - across users, spend, and SSO.
Three scan paths · browser-local CSV processing