Common limitations
- Blocked or authenticated content
- dynamic and personalized rendering
- geographic or device variation
- third-party outages
- rate limits
- sample-based performance
- undiscovered URLs
- manual testing not performed
Required report context
- Run date and duration
- scope and exclusions
- crawler identity and rate
- authentication state
- methodology version
- failed or incomplete checks
- known uncertainty
Responsible use
Do not present a report beyond the scope it actually covered. High-confidence presentation does not turn incomplete evidence into certainty.
Evidence standard
- State the authorization, scope, exclusions, environment, timing, and methodology version for audit limitations and interpretation.
- An executive explanation and an implementation record generated from the same source data.
- Distinguish direct observation, calculated result, heuristic, inference, and manual judgment.
- Preserve failed, incomplete, blocked, and uncertain checks instead of silently dropping them.
Interpretation and decision record
A methodology should help reviewers reach the same bounded conclusion from the same evidence. It should not imply certainty beyond the assessed scope. Record the finding, limitation, owner, decision, remediation, and the verification required to turn technical evidence into a defensible decision record for both stakeholders and implementers.
Decision and verification record
Scope
Name the website, environment, URLs, entities, templates, or user journeys included in the audit limitations and interpretation decision.
Decision
Record the chosen action, owner, priority, dependencies, approval, and the evidence that justified it.
Verification
Confirm the report matches the current source records, scope, approvals, and verification status before distribution.
Turn audit limitations and interpretation into an accountable record.
A reproducible audit limitations and interpretation assessment record with scope, evidence, limitations, and verification rules.