How the gate works
This tool grades an escalation path's odds of failing closed instead of proceeding unanswered. It scores 6 weighted controls into a 0–100 number — then a gate that can only make the verdict worse.
The 6 weighted controls
When nobody has defined what happens if the reviewer does not answer in time, the path is forced to FAILS OPEN regardless of its score on the other five controls - an escalation that proceeds unanswered is not a control, it is a delay with a due date.
Why: This path (a refund over threshold) scores 84/100 across the six controls - that reads FAILS CLOSED. But its timeout behavior is undefined (mark 0): nobody decided what happens when the reviewer does not answer in time. The gate forces FAILS OPEN regardless of the score - an unanswered request that proceeds on its own is a delay, not a control. Two more paths in the same portfolio also read FAILS OPEN, so the portfolio verdict is NO BACKSTOP.
A high score didn’t save it. The score is context; the gate is the answer — and it names the one thing to fix first. Grades the escalation paths you describe against six controls, offline. Not a security audit or a guarantee no request will fail open.