Skip to main content

Compliance and Authorization

cATO

Continuous ATO Evidence Analyzer

Upload the evidence. Read the determination. Decide.

Inside the ATO workflow, a local model reads each artifact against the control it is meant to satisfy and returns a verdict with its reasoning, the indicators it found, the gaps it did not, and what to do next. An assessor ratifies or overrides. Nothing closes on a model verdict alone.

AC-2 Account Management
Verdict Partial 0.81 confidence
Source Combined verdict over 3 artifacts

Indicators found

  • Account request form with approver signature
  • Quarterly review export dated this quarter
  • Disable on termination in the SOP

Gaps identified

  • policyNo statement of the review frequency for privileged accounts
  • evidence missingNo sample showing a disabled account after separation

Recommended action

Add the privileged review frequency to the policy, then upload one termination sample.

Draft the missing language with PolicyForgeAsk AVISSAA what to collect

Illustrative reading. Control real, findings invented.

The chain

Upload, analyze, combine, ratify

Every step is a separate record. The verdict a control carries is the newest live reading a human has not rejected, and a settled control is never quietly downgraded by a weaker upload that arrives later.

01 Processing queue AC family
Target25 controls
Skipped12 satisfied
Estimate6 min

Queued artifacts

  • account_request_form.pdf analyzing
  • quarterly_review_export.csv queued
  • account_management_sop.docx queued

Illustrative queue. Files and times invented.

01

Upload

Target one control, several, or an entire family. A policy document evidences most of a family at once, so the whole family runs as one batch, already satisfied controls are skipped by default, and the queue shows a time estimate before you commit.

ISSO uploads Queued artifacts
01 Processing queue AC family
Target25 controls
Skipped12 satisfied
Estimate6 min

Queued artifacts

  • account_request_form.pdf analyzing
  • quarterly_review_export.csv queued
  • account_management_sop.docx queued

Illustrative queue. Files and times invented.

02

Analyze

The model reads the artifact against the control statement and returns a verdict of satisfied, partial or not satisfied with a confidence, the compliance indicators it found, the gaps it identified with a type on each, a recommended action and an OSCAL shaped observation.

Local model Determination
02 One reading AC-2

account_request_form.pdf

Partial
Confidence0.78

Indicators found

  • Approver signature on the request form
  • Role requested and justification present

Gaps identified

  • evidence missingNo sample of an account disabled after separation

One artifact, one reading, with an OSCAL shaped observation attached.

03

Combine

When several artifacts speak to one control, a second model call reads them together and produces a single combined verdict. Text is never merged across readings, and the combined verdict is marked stale the moment newer evidence lands.

Local model Control verdict
03 Combined verdict AC-2

Read together

  • account_request_form.pdfPartial
  • quarterly_review_export.csvSatisfied
  • account_management_sop.docxPartial
Partial Confidence 0.81

Marked stale when newer evidence lands

Gaps that survive the set

  • policyNo statement of the review frequency for privileged accounts
  • evidence missingNo sample showing a disabled account after separation

Text is never merged across readings. A second model call reads the set.

04

Ratify

An independent assessor accepts, rejects or overrides each reading, with the override recorded. The control's status follows the ratified reading, and the package documents are generated from it.

SCA decides Ratified status
04 Assessor review SCA
AcceptRejectOverride
Control status Partial, ratified Follows the ratified reading, not the model's
Accepted with a note, on the record

What follows

  • Draft the missing language with PolicyForge
  • Upload one termination sample
  • SAR and POA&M generated from the ratified status

Nothing closes on a model verdict alone.

Two assistants at the upload

It tells you what to collect, and drafts what is missing.

AVISSAA

What should I upload for this control?

One click asks AVISSAA for a short list of the artifacts an assessor will expect: what each one shows and how it is assessed. The question changes with the control's state, decided in code: a baseline list when nothing is uploaded, a gap closing list once a verdict shows gaps. The examine, interview and test methods from SP 800-53A are shown instantly with no model call, and a changed gap list marks the advice as stale instead of serving it again.

About AVISSAA

POLICYFORGE

Draft the missing language

Every gap carries a type. Policy and procedure gaps get a button that hands them to PolicyForge, which drafts the language that closes each one: a section per gap with a placement hint and bracketed parameters your organization fills in. Copy it, or save it to the policy library as an amendment drafted from evidence gaps. The uploaded document is never edited in place.

About PolicyForge
One control, one headline: the verdict, the confidence and how long the model took, with both assistants one click away. Real screen, fabricated evidence on a test system.

Every gap has a type

A label, not a ranking

  • Policy

    The governing document does not say it. PolicyForge can draft it.

  • Procedure

    The document says what, not how. PolicyForge can draft it.

  • Technical

    The system does not do it yet. Remediation, not wording.

  • Evidence missing

    It may be done, but nothing uploaded proves it. AVISSAA says what would.

What the reviewer sees

One reading at a time, not a wall of text

  • Control Status Ledger

    A docked list of every control with its current verdict, searchable by control or family. Click one and its panel opens.

  • Processing Queue

    Every queued artifact with progress and a time estimate, docked beside the upload.

  • Headline first

    The combined verdict is the headline. Each artifact's own reading is one click away in a sidebar, with accept, reject and override right there.

  • History kept, not shown

    Superseded readings and identical re-uploads collapse into a history group instead of crowding the control.

One reading, both halves. What the evidence proved, with the artifact each indicator came from, and what it did not, typed and ready to hand to PolicyForge. Real screen, fabricated evidence on a test system.

Seen in the app

The model reads it. A person still decides.

Every artifact comes back with a reading attached: a verdict, a confidence and the reasoning behind it. The model does the reading so nobody has to work through the document line by line, and none of it counts until a person accepts it.

Submitted, graded, handed back

You upload, the model grades each artifact against the control and hands the reading back with its confidence, and then it waits. Accept it, reject it, or override the verdict yourself; the panel here shows one artifact accepted and one rejected, and the control follows what the human decided, not what the model said. Real screen, fabricated documents.

The decision stays yours

  • Accept the reading as it stands
  • Reject it and it counts for nothing
  • Override the verdict and record why
  • Nothing closes on a model verdict alone

When evidence combines

  • Two documents, each proving part of a control
  • A second pass reads them together into one verdict
  • Every artifact keeps its own reading underneath
  • Superseded readings collapse into history

The combined verdict is marked stale the moment newer evidence lands, so a control is never quietly settled by an older reading.

Straight answers

Does the AI close controls on its own?

No. It produces a determination for a human to ratify or override, and the override is recorded. Nothing closes on a model verdict alone.

What happens when two artifacts only satisfy a control together?

A combined verdict is produced by a second model call over both artifacts. Their analyses are never spliced together, because that would claim each one proved something it did not.

Can a later, weaker upload undo a satisfied control?

No. A satisfied verdict is not overwritten by weaker later evidence, and already satisfied controls are skipped by default when a family is run.

Does the evidence leave our boundary?

No. Analysis runs on a local model inside your own environment with no external inference calls.

Bring a screenshot. Watch it become a determination.

Ask for a demo and we will run a synthetic artifact against a control family, combine it with a second, and hand the result to an assessor in front of you.