Operational assurance
One accountable service. Evidence you can act on.
Operational assurance connects the way a managed service is designed and run with the evidence needed to review it: service health, incidents, changes, policy activity, responsibilities, known gaps and agreed actions. It is not a reporting add-on. It is what becomes possible when connectivity, security and observability are operated as one service, by one team, with a single point of accountability.
What is Governance Debt?
Your infrastructure is distributed. Multiple networks, clouds, security controls and suppliers – some chosen deliberately, others inherited through acquisition or stood up quickly to meet an urgent requirement, and most bought as separate point solutions through separate contracts.
Most providers run their own part well. But services rarely fail inside one neat technology silo. They fail where responsibility is fragmented, in the space between suppliers, where no single party owns the end-to-end route, the policy, the telemetry and the operational authority together.
As the estate changes, the gap between how each service is meant to run and how it actually runs keeps widening. That accumulating gap is governance debt, and it comes due every time somebody asks a question the estate cannot answer.
When Governance Debt comes due
Many organisations assemble service and control evidence only when a review, audit or regulatory submission approaches. Teams pull screenshots from tools, reconstruct changes, reconcile supplier reports and chase owners for missing context. The data may exist, but it was not designed to answer the governance question.
That is governance debt being repaid manually, by the people least able to spare the time, against a deadline set by somebody else.
One service, one record
Cloud Gateway runs connectivity, security and observability as one service, integrated through one Unified Control Plane and delivered by one UK-based team. Responsibility sits in one place, as does the record of how it runs.
Three things follow from that operating model:
Orchestration
Services are designed, provisioned and changed as one, not stitched together after the fact, so the change record is a single continuous account rather than four partial ones.
Service intelligence
Telemetry and service context are connected across the services in scope, so signals become understanding rather than another dashboard to interpret.
Assurance
Evidence that proves control and performance, rather than asking anyone to take it on trust.
Cloud Gateway defines which operational records the selected service should create, how they relate to the service boundary, who owns each decision and where limitations are recorded. Observe presents the available service view. Operational assurance is the use of that evidence for service review, governance and audit readiness.
What the evidence covers
Service inventory
and scope
What is in the service, where the boundary sits, and what sits outside it.
Service-level
indicators
How the in-scope services performed against what was agreed.
Incidents and
response history
What happened, what was done, by whom, and how it was resolved.
Change and
approval records
What changed, when, why, and who approved it, recorded automatically.
configuration
evidence
Where included in the service, the security policy actually in force and the exceptions to it.
Access and
responsibility records
Who has access to what, and who owns each decision, on record.
Source coverage
and limitations
Which sources the view depends on, and where the known gaps are.
Improvement
actions
What was agreed, what is outstanding, and what carries forward.
How it helps your team
Service leadership
Review whether the service is operating as agreed, and which risks or actions need attention.
Risk and governance
Assess control and supplier performance using traceable operational evidence rather than unsupported assertions.
Audit readiness
Reduce the manual work needed to locate and reconcile records for an assessment or assurance cycle.
Executive reporting
Translate service operation into a concise account of condition, material events, decisions, risk and action.
The same record for every framework
CAF and DSPT
The Cyber Assessment Framework is the National Cyber Security Centre’s framework for assessing cyber resilience in organisations responsible for essential services. Since September 2024 the NHS Data Security and Protection Toolkit has aligned to it, so NHS trusts, ICBs, ALBs and CSUs now report against CAF objectives, principles and outcomes rather than the previous checklist. That shift moved the burden from ticking boxes to demonstrating outcomes, which requires operational evidence.
ITHC
An IT Health Check is an independent technical security assessment required for connection to public sector networks including HSCN and PSN, and for various other regulated services. It is typically required annually, or after material changes to the system being assessed.
What any of them will ask a managed service for
Change records showing who changed what, when, why and with what approval. Patch and firmware evidence with completion detail. Policy enforcement, including rules, blocks and exceptions. Incident history with actions and resolution times. Service-level delivery against what was contracted. Access governance showing who has access to what, validated and reviewed.
Ensuring responsibility stays clear
Cloud Gateway can provide the operational evidence and reporting expressly included in the managed
service. The customer remains accountable for its regulatory submission, control framework, risk
decisions, legal interpretation and relationship with its auditor or regulator. Operational evidence is not
an audit opinion, certification or guarantee of compliance.
Operational assurance underpins every service
Observe Essentials provides a monthly assurance summary for eligible Cloud Gateway managed services: available service-health evidence, material incidents, completed changes, open issues, data coverage, known limitations and agreed actions. It is an operational service report, built to support a service review rather than to serve as an audit opinion.
More specialised evidence outputs need a defined scope and data model before we will offer them, which is deliberate. We would rather tell you what the service can evidence than promise a pack and reconcile the difference later.
Why Cloud Gateway
Service
discipline
Service definitions, supported patterns, readiness checks, runbooks and lifecycle governance turn capability into repeatable delivery.
Regulated-sector
depth
Experience across health, public sector, policing and other critical environments informs architecture, posture and supplier decisions.
Observability
included
Telemetry, source coverage and service context are treated as design inputs from the first design session, not an afterthought post a go-live date.
Transparent
sovereignty
Customer service management and engineering are UK-based, with any non-UK platform, support or data documented clearly.
Trusted where failure is not an option.
We work with organisations that cannot afford to fail: NHS trusts, central government, local authorities and police forces, plus the tech innovators who serve them. Delivery is fully managed or co-managed with guardrails, backed by a 24/7 UK-based Network Operations Centre.






























Where the evidence comes from
A monthly account of health and activity
The standard service-health view and the monthly assurance summary for eligible managed services in your agreement.
Evidence of security policy and controls
Managed Firewall and the Protect services are where policy, configuration and change evidence originates.
A standing record of your connection
Documented evidence for the connection you are being assessed on, rather than assembling it from scratch.
Define the evidence before the next review cycle.
Bring one critical service that crosses networks, clouds or suppliers. We will map who is accountable for what today, where the gaps sit, and what evidence that service can produce.