Metric

Admina Score

The Admina Score is the headline metric on the dashboard — a live-runtime composite (0–100) that answers a single question: right now, how well is this Admina instance actually governing the traffic it sees? It is not a marketing number and not a static checklist — it is recomputed on every read from the proxy's current state.

Live runtime 0–100 GET /api/dashboard/score Recomputed per request

What it measures

The Admina Score is a weighted sum of five independent governance signals. Each signal is a boolean or proportional check against the proxy's current runtime state — not a stored value, and not a promise about future behaviour.

87/100
Example live score
Data Residency +25
Interactions Audited +25
EU AI Act Coverage +25
No Recent Attacks +15
Forensic Chain Valid +10
Total 100

Formula

Implemented in admina/proxy/api/dashboard.py::_compute_governance_score.

# pseudocode
score  = 0
score += 25  # data residency (constant — always awarded)
score += 25  # interactions audited (forensic box has events)
score += round(eu_ai_act_compliance_score / 100 * 25)  # up to +25
score += 15  # no blocked requests on any governed surface (cumulative counter)
score += 10  # forensic chain past GENESIS
# → 0 <= score <= 100

The five components

Data Residency

+25
SignalThe governance proxy is running — this component is a constant, not a measurement
Formula+25 unconditionally, hard-coded in _compute_governance_score
How to improveNothing moves this one — it is a flat +25 for any running proxy. No admina.yaml key feeds it, and the ResidencyEnforcer class is never instantiated by the proxy pipeline. Runtime residency enforcement is an SDK feature instead — GovernedData(connector=..., residency_zone="eu") raises on ingest or query outside the allowed zones — but that enforcement does not feed this component.

Interactions Audited

+25
SignalForensic black box is active with at least one recorded event
Formula+25 when forensic_box.record_count > 0, else 0
How to improveSend at least one request through /mcp, /api/v1/audit, or /v1/chat/completions to seed the chain — traffic is the only thing that moves this component. /api/v1/validate is counted as traffic but writes no forensic record, so it does not move this one. The proxy always has a forensic store (in-memory when no backend is set), so a persistent backend (filesystem or s3) is not what earns the points; it is what keeps the record count from dropping back to 0 on restart. A store that cannot record — a backend that could not be opened at startup in open fail mode, or (since v0.13.0) a chain reported invalid — adds no records; check forensic_writable and forensic_chain on /health.

EU AI Act Coverage

+25
SignalLatest EU AI Act assessment is close to full Article 9–15 coverage
FormulaProportional to the latest assessment: round(compliance_score / 100 × 25)
How to improveRun POST /api/compliance/gap-analysis with risk_category set to high or unacceptable — only a gap analysis records an assessment, and any other risk category returns applicable: false without recording one, so this stays at 0 until you run a qualifying analysis. Assessments are held in memory, so the component drops back to 0 on restart, and the compliance surface must be enabled (with ADMINA_ENABLED_SURFACES leaving it out, /api/compliance/* answers 404). (POST /api/compliance/report counts too, but only when its own risk classification lands on high or unacceptable — it classifies first, then feeds that category to the same gap analysis.) Then close the gaps it surfaces (risk management, data governance, logging, transparency, human oversight, accuracy/robustness).

No Recent Attacks

+15
SignalZero requests blocked on any governed surface since the process started
Formula+15 if metrics.requests_blocked == 0, else 0
How to improveA zero here is good — it means no request has been blocked since the proxy started. The counter is the requests_blocked of /api/stats (admina_requests_blocked_total on /metrics): BLOCK and CIRCUIT_BREAK decisions on /mcp, on the gateway (/v1/chat/completions, since v0.12.2) and on /api/v1/validate (since v0.13.0), plus — since v0.13.0 — /mcp responses blocked by a governance guard, and /mcp requests refused by the rate limiter (429) or the token-size guard (413), in every governance mode. It is cumulative for the process lifetime, so it resets on restart. In observe and dry-run mode a would-be governance block is recorded as allowed, so attacks alone leave this component at +15; only those 429 / 413 refusals still take it to 0. If the score dropped to 0, inspect the blocked-action events in the live feed.

Forensic Chain Valid

+10
SignalThe head of the SHA-256 hash chain has moved past GENESIS — at least one record has been chained
Formula+10 when forensic_box.chain_head != "GENESIS", else 0
How to improveSend real governed traffic through the proxy so the forensic logger appends at least one record past GENESIS. Despite the name, this component does not verify the chain and does not read its status: a chain reported invalid (since v0.13.0) keeps the +10 (and +25 for Interactions Audited) if its restored head is past GENESIS. For an actual integrity check use admina forensic verify or GET /api/v1/forensic/verify, and forensic_chain on /health.

Admina Score vs OISG Score

Admina surfaces two 0–100 scores on the dashboard. The Admina Score (this page) is a live runtime composite. The OISG Score is a static capability assessment. They answer different questions and should be read together.

→ Full side-by-side comparison, a 2×2 interpretation matrix (high/low × high/low), and scenario-based guidance on which score to consult first: Admina Score vs OISG Adequacy.

API response

curl http://localhost:8080/api/dashboard/score \
  -H "X-API-Key: $ADMINA_API_KEY"
{
  "score": 87,
  "max_score": 100,
  "breakdown": {
    "data_residency": 25,
    "interactions_audited": 25,
    "eu_ai_act_coverage": 12,
    "no_recent_attacks": 15,
    "forensic_chain_valid": 10
  },
  "computed_at": "2026-05-21T09:30:00Z"
}

The endpoint belongs to the dashboard surface: with ADMINA_ENABLED_SURFACES (since v0.13.0) leaving dashboard out, it is not mounted and answers 404. See Configuration.