Skip to main content
Once Scorecards are incorporated into your regular engineering workflows, they become production-grade tools. Scorecards set the benchmarks for how your organization defines “good,” which impacts everything from security standards to on-call rotations. Because Scorecards are crucial to achieving and maintaining standards, you may want to employ controlled access and version controlling. Turn on GitOps editing for Scorecards to manage your standards the same way you manage the entities in your catalogs. Each Scorecard gets its own YAML file, and every change shows up in your GitOps logs.

Setting up Scorecards as code

Step 1: Configuring GitOps editing for Scorecards

  1. From the main sidebar, click your avatar in the bottom-left corner.
  2. Select Settings.
  3. Locate the Workspace section, then select GitOps.
  4. On the GitOps page, select the Scorecards tab.
  5. Toggle on Enable GitOps for Scorecard editing.
When GitOps for Scorecard editing is enabled:
  • You can’t edit Scorecards in the Cortex UI, including ones you originally created there. Edits happen in the Scorecard’s YAML file in your Git repository.
  • You can still create and delete Scorecards in the UI.
You can also configure an allowlist to control which repositories Cortex imports Scorecards from.

Step 2: Adding Scorecards to your Git repository

You can build a Scorecard in the Cortex UI and convert it to a YAML, or write the YAML from scratch. See the example below. Keep Scorecards in their own repository, separate from your catalog entities, under .cortex/scorecards at the repository root. Avoid putting Scorecard definitions in a service repository. A Scorecard measures many entities, so it doesn’t belong to any single one of them. For example, a simple repository might have the following structure:
Any file found within the .cortex/scorecards directory, including its subdirectories, is automatically picked up and parsed as a Scorecard. When GitOps editing is turned on for Scorecards, you can’t edit any Scorecard in the Cortex UI, including Scorecards you originally created there. You can still create and delete Scorecards in the UI. For more information, refer to Using both the UI and GitOps.

Converting an existing Scorecard to code

You can convert Scorecards created in the Cortex UI to code via GitOps. Keep in mind, though, that once GitOps editing is turned on and your Scorecard lives in a YAML file, you can only edit it via Git. To convert an existing Scorecard into code:
  1. From the main sidebar, expand Scorecards.
  2. Select Scorecards.
  3. On the Scorecards page, select the Scorecard you want to convert.
  4. At the top of the page, click the overflow menu icon, then click Export Scorecard YAML.
  5. Add the Scorecard’s YAML file to your Git repository.

Example Scorecard YAML file

The dora-metrics.yaml descriptor file might look something like this:

Scorecard YAML reference

Scorecard objects

Notifications

Exemptions

Ladder

Level

Rules

Filter

Note: One of types, groups, or query must be present for it to be considered a valid filter.

TypesFilter

Note: Only one of include or exclude can be specified at a time.

GroupsFilter

Evaluation

Last modified on September 9, 2026