Skip to main content
Each project has a Dashboard. Check it first after a scan. It answers three questions:
  • Can we ship?
  • What needs a person to act?
  • Which findings are dangerous?
The Dashboard is made up of cards. Each card is a panel that reports on one part of the project. You can rearrange, add, and remove cards. To open it, select a project, then Dashboard in the sidebar. Dashboard

What the Dashboard is for

The Dashboard reports the project’s posture, meaning its state as of the latest scan, and links to the next action. Every action on the Dashboard applies to the project as a whole. Examples are requesting an exception to a policy (a Policy Approval), generating an SBOM, running a scan, or setting up a policy. You don’t decide individual findings here. You assign, resolve, defer, and reopen findings in the Review Workspace (Review in the sidebar), and every card that points at findings links there.

The header

Above the cards, the header shows:
  • a coverage badge, Full coverage or Partial coverage (see Coverage: Full vs Partial)
  • how the code arrived, for example Repository scan
  • when the project was last scanned, for example Scanned 23 Sept 2026. This is the latest scan that updates posture, so a pull request scan or a Self-check never sets this date.
On the right are New scan and Download.

Tabs, and why you may not have any

Earnie builds the tabs from the scanners your organisation has.
  • If Components and Cryptography are both enabled, you get an Overview tab, a Components tab, and a Cryptography tab. Overview lists what needs doing. The other two tabs each cover one subject in depth.
  • If only one of them is enabled, there’s nothing to switch between, so the Dashboard shows no tab strip. You get a single merged set of cards instead.

The control row

To the right of the tabs is a row of controls: a history period, a card-set dropdown on some tabs, and Customise.

History period

The period dropdown offers Last 30 days, Last 90 days (the default), or All scans. It narrows history only. It changes the Posture trend and Decision throughput cards, not your findings. Posture always reflects the latest scan, whatever period you pick, so changing the period never hides a current problem.

Choosing a card set

The Components and Cryptography tabs have a second dropdown, which starts on All cards. Each option replaces the tab’s cards with a smaller set for one question: Overview has no card-set dropdown. It always lists what needs doing, which doesn’t change by question.

Making the canvas your own

You can change which cards appear on a tab and how Earnie lays them out. Each tab, and each card set on a tab, keeps its own layout.
  1. Select Customise. The cards become editable, and the button changes to Done.
  2. Every card now shows a move handle on the left and a remove button on the right. Make your changes:
    • To reorder, drag a card onto another, or use the keyboard.
    • To resize, drag a card’s right edge. Widths change in whole columns, from a quarter to the full width. Resizing is available only on a wide window. On narrower windows the layout is fixed to halves or full width.
    • To add a card, select Add cards to open the card library. It lists every card this view can hold, each with a one-line description. Cards already on the Dashboard appear greyed out, so the library always shows the full set. Select a card to add it at the end. Hide library closes the library.
    • To remove a card, select the × on it.
  3. Select Done when you’ve finished.
Once a layout differs from its default, Edited · Reset appears in the control row. Reset returns that tab and card set to the default layout and leaves your other layouts alone.
Earnie saves rapid edits in order. If the latest save or reset fails, Earnie reports the error and restores the last layout the server confirmed. This way, you never see an arrangement on screen that would disappear when you reload the page.

What each card tells you

Needs attention

Needs attention sits at the top of the page, and it’s the one card you must read. It lists the things that need someone to act, each with a button that takes you to the next step. A row appears only when its condition is true: When no rows apply, the card reads Clear: “Nothing blocks a merge and no evidence is missing.”

The rest of Overview

The AI provenance tab

The AI provenance tab shows what AI the project uses and which models it ships. It has two cards:
  • AI usage counts the detections Earnie found in your source and manifests by kind: AI SDK, AI dependency, AI agent, AI tool, embedding model, vector store, and dataset. Only kinds Earnie found get a row.
  • Models counts model files by the outcome of identifying them: Identified, Not identified, Matching unavailable, Too large to fingerprint, and Git LFS pointer. Earnie keeps these apart because each outcome needs a different next step.
Both cards show how many findings are Open and how many are Decided, counted the same way as in Review. A decided finding is one that someone resolved or suppressed with a decision, such as approving a model. A decided finding stays in the total, because deciding it doesn’t remove the AI from your code. Open in Review opens Review filtered to AI findings, and Open Models opens the Models page. If AI provenance has never run on the project, the tab says Not scanned and shows no numbers. If it ran and found nothing, the tab says Clean. These cards don’t show policy verdicts on AI findings. Those appear in Merge gate and on the Policies page. See AI provenance.

Cryptography trend lines

The Cryptography summary card includes sparklines for Reachable weak crypto and PQC-vulnerable assets, meaning assets a future quantum computer could attack. The same rows appear in Posture trend.
  • Each sparkline uses the latest twelve completed scans.
  • A scan that didn’t run cryptography leaves a gap in those rows, not a zero. Only a cryptography scan that ran and found nothing plots zero.

Component matrix

On the Components tab, the Component matrix lists the top components by matched files. Each row shows the package identifier, version, origin, licence, and open CVEs (publicly known vulnerabilities).

Export readiness

Some countries control the export of software that uses cryptography. On the Cryptography tab, Export readiness shows whether your export-control evidence is complete. The card never states or implies an ECCN (Export Control Classification Number, the official classification an item receives under export-control rules), and says so on the card: “Evidence only, never a determination; no ECCN is stated or implied.” You still decide how to classify your product. The card shows one of three readings: If only part of the project predates the update, the card keeps its normal reading and adds the number of findings that carry only superseded evidence. A re-scan would change those findings.
Earnie can decide some mass-market reporting-line evidence only over the whole project. An RSA or elliptic-curve finding gets a final answer only after Earnie checks the same scan for symmetric confidentiality algorithms. AES counts. Authentication, integrity, hash, MAC, and signature mechanisms such as HMAC don’t. Earnie resolves this project-level condition before it computes readiness, and keeps the original per-finding evidence unchanged for audit.
Under the disclaimer, the card names the two curated datasets behind it:
  • Risk dataset <id> — last reviewed <date> set the severity of every finding counted here.
  • Export dataset <id> — last reviewed <date> answered every export test.
The export-control report’s header names the same two datasets, so the Dashboard and a filed report always refer to the same version of the data. Below those two lines, What these datasets say opens Settings → Crypto Assessment, which shows the published rules. See Triaging findings.

Post-quantum exposure

A large enough quantum computer could break some of the cryptography in use today. Post-quantum exposure shows how much of your cryptography is at risk.
  • It assesses every type of cryptographic asset (algorithms, protocols, certificates, and key material) by its resolved algorithm family.
  • It counts only cryptography a quantum computer breaks, which is the classical public-key families. A broken hash such as MD5 is a severity problem, never a migration item here.
  • Earnie lists assets it couldn’t judge separately as unassessed. It never counts them as quantum-safe, and never presents a gap in its curated data as migration work.

Reading the numbers

Read this section before you rely on any card. Earnie uses different words for a measurement that came back zero and a measurement that was never taken, and never rolls either into a score or a grade.

Partial coverage changes what the numbers mean

When the header badge reads Partial coverage, Earnie built the posture from declared components only. These come from the manifests and lockfiles that list a project’s dependencies, with no code matching behind them. In that case:
  • Provenance and Origin split show — instead of a percentage.
  • The Component matrix reads Declared, with — for files.
  • Needs attention shows “Posture is declared-only: no files were matched.”
Read it as a list of what the project says it uses, not of what’s in the code.
If the page can’t load. When Earnie can’t fetch the project’s scans, you see “Could not load scans” and a Retry button, and no merge-gate verdict. Earnie hides the verdict because a verdict next to “could not load” would read as a verdict about the failure.

Downloading evidence from the Dashboard

Download in the header gives you every file this project can hand to someone else, such as a customer or an auditor.
  • Downloads come from the snapshot for the exact scan behind the posture on screen. Earnie doesn’t substitute a newer snapshot from another scan.
  • Selecting an item downloads that file immediately. It doesn’t take you to the SBOM ledger.
  • The menu offers only formats already generated on that snapshot, so a snapshot has to exist first. If there isn’t one, Needs attention says so and offers Generate SBOM. See Exporting an SBOM.
The menu can include:
  • SBOM: CycloneDX, the most widely supported inventory format.
  • SBOM: SPDX, the licence-focused format.
  • Notice file (NOTICE.txt), the attribution text you must distribute with your software. See Notice files.
  • Export-control report, available where cryptography is enabled and the scan found something. It’s evidence for your own self-classification and states no ECCN. Its header names the curated datasets behind it and the date each was last reviewed.

What’s next

After the Dashboard shows what needs attention, open the Review Workspace and triage those findings one by one. Once you govern more than one project, All projects answers the same questions for every project in your organisation.