A green status indicator can say more than the underlying system knows. If an API failed or a connector has never been configured, showing zero threats is not a harmless default. It turns missing information into a conclusion.

Absence needs a source

Zero findings means that a successful query returned no findings within a stated scope. It does not mean that every system was checked, or that an organization is safe.

An unavailable result means the query could not establish an answer. A disconnected source means no observation has been established. A stale result means the evidence once existed but may no longer describe the present.

These distinctions influence what a person does next. A disconnected source leads to connection setup. A stale source leads to a freshness investigation. A recorded finding leads to evidence and response.

Keep the interface honest

The number and its explanation should travel together. “No findings returned” becomes more useful when it includes the source, scope and last successful observation. A failure state should include a recovery action without erasing the failure.

Charts need the same discipline. An empty series should not turn into a decorative trend. A percentage should have a denominator. A risk score should explain its method before it influences a decision.

Uncertainty can guide the work

An explicit unknown is actionable. It tells a team where to improve coverage, validate a permission or reconnect a source. Hiding it only defers that work.

This is one of the principles behind Zorro’s workspace: evidence-bearing fields start as unavailable and become specific when a source supports them. The interface should never need to invent confidence to look finished.

A complete picture includes the parts you cannot yet see.