End to end, or not at all
The synthetic card-authorisation service in our payments extension reports Effective Coverage of exactly 0%. Not one path in the service operates at target state from end to end, and the zero is published as a headline figure beside the concentration index, because the two metrics answer different questions and a service needs both answers.
The index reads how concentrated the estate is. Coverage reads how much of it is protected in the only sense that counts.
The definition, and its three rules
Effective Coverage is the share of a service’s cryptographic assets where every party and every hop on the path operates at target state. Three rules make the definition strict rather than aspirational. The denominator is assets, the same inventory the index uses, so an asset mapped to no path becomes a discovery finding rather than a definitional escape.
An asset traversing multiple paths takes the minimum state across all of them. And counterparty state counts, not only the institution’s own, because a path protected at your endpoint and exposed at the counterparty’s is not a protected path. It is a protected half.
Target state is defined per service, up front, and applied uniformly to the institution’s own negotiated outcomes and to counterparties alike. Where no definition was set, coverage reports as not computable rather than computed against an implicit one, on the principle that an undefined term is never a favourable value.
Why the minimum, never the average
Averaging coverage across paths has its own row in the reviewer error catalogue, and the effect recorded there is protection not held. A service with nine hardened paths and one exposed one is not 90% safe on the traffic crossing the tenth. The exposed path is the one an adversary chooses on purpose, and the choosing is the whole business model.
Vaccine logistics learned this arithmetic the expensive way. Potency depends on an unbroken cold chain from the factory dock to the clinic, and a certified refrigerator at each end does not make one. The audit that matters walks the whole route, because the cargo takes the temperature of its worst segment, not the average of its best ones. Cryptographic protection travels the same way, hop by hop, and inherits the state of the weakest one it crosses.
Counterparties, sorted by who can move them
A low coverage figure usually means the shortfall belongs to other parties, so the metric ships with a classification, one field per counterparty.
- Blocking counterparties cannot be compelled, and must migrate before the institution can. On the signature track, the certificate authorities a service’s accepted chains terminate in are blocking in their own right.
- Contractual counterparties are movable through contract terms, certification or onboarding requirements.
- Peer counterparties move only by bilateral coordination between equals.
- Population counterparties form a homogeneous estate the institution cannot address individually, handled by campaign and reported as a percentage.
The single field prevents the failure that does the most planning damage. A count of 358 counterparties conceals the six blocking ones that gate the other 352, and 340 contractual counterparties are far easier to move than six blocking ones. The classified count is also the only one a supervisor can deduplicate into a sector view, which is what makes the figure aggregable at all.
The actionable metric
Concentration is largely inherited and slow to move. Coverage responds to sequencing decisions the institution controls, which turns the assessment into a planning input rather than a verdict.
A 0% with a classified counterparty table is a route map. It names which six organisations gate the service, which 340 a contract cycle can move, and what the first quarter of real progress looks like. The index tells a board where the risk concentrates. Coverage tells a programme what to do next, and the programme is the audience this framework was written for.