Who it's for
Built for every seat that carries the package.
Roles come from your directory, and there is no limit on them. Each seat sees the systems it is cleared for and the work that is its own. Which seat holds which step of the authorization workflow is set for your agency, not fixed by us.
The seats in our demo environment, and yours
These eight are how the demo environment is configured. Your agency defines its own roles from its own directory; the authorization workflow is being built so you can assign your own people to your own steps.
What this seat gets
-
A short queue of the decisions your agency assigns to this seat, by default authorization, reauthorization and risk acceptance
-
An opening dashboard pinned to the seat, and Ask Alloy for the rest
-
Nothing routine
What this seat gets
-
AVISSAA for what the control requires and what the assessor expects
-
Evidence upload with AI analysis against the control, then a human decision
-
Ask Alloy for what is on your list next, and sprint boards for the rest
What this seat gets
-
Posture across the systems you manage, on a board built from a sentence
-
PolicyForge gap analysis over the policies you own
-
The same evidence and POA&M tools as the ISSO
What this seat gets
-
AVISSAA for control interpretation before you build
-
Evidence upload during implementation, analyzed by the model
-
Technical detail behind every finding
What this seat gets
-
Your package, phase by phase
-
Documents and evidence offered against your own controls
-
Where your system stands, without a status meeting
What this seat gets
-
Validate or override every AI evidence determination
-
Independent by default: the assessor attests, the ISSO acts on it
-
The ledger of what was ratified and why
What this seat gets
-
Dataset Builder, models and site configuration
-
Full scope on the Activity Ledger
-
Demo mode for showcasing every seat
What this seat gets
-
Vulnerability discovery, sprint planning and remediation on the datasets you work
-
Connectors to the ticketing and endpoint tools you already use
-
The fastest route from finding to fix
Three assistants, every seat
An advisor for the control, an answer from the data, a board from a sentence.
AVISSAA tells an ISSO or ISSE what a control requires before they go collect evidence. Ask Alloy and GenAI Dashboards give every seat the picture it needs and the next thing to do.
AVISSAA
Avint ISSO Advisory Assistant
For the ISSO
Ask what a control means at your baseline, what the assessor will expect, and which tasks are mandatory at each RMF step, with the NIST publication cited. Export the session for the package.
At the upload
The same advice sits beside the evidence upload, so what you are about to prove is never a guess. Advisory only: your evidence and system data stay out of it.
ASK ALLOY
Ask Alloy
For leadership
Which vulnerabilities are affecting my systems? Which of my ISSOs is behind? Real figures from the database, ranked in code, phrased by a local model.
For the ISSO
What do I have to work on today? Who owns this CVE? What should I prioritize? One drawer, on every page.
GENAI DASHBOARDS
GenAI Dashboards
For leadership
Type a sentence, get a board of KPI tiles, charts and tables from your data. Pin one as the opening view for a role, share it, save it.
For the ISSO
Ask for exploited findings by system before a stand up, then send a tile's filters straight into the table you will work from.
Separation of duties
Whoever fixes it does not attest that it is fixed.
The evidence chain is enforced by permissions, not by policy documents. By default an ISSO offers proof, the model analyzes it, an independent assessor validates it, and the Authorizing Official accepts the risk. Each hand-off is a ledger entry. Which seat holds each step is being made configurable, because the same people are not involved at every agency.
01
ISSO uploads
Evidence goes in against the control or the whole control family it is meant to satisfy.
Artifact on record
02
AI analyzes
A local model reads the artifact against the requirement and returns a determination with its reasoning.
Determination
03
SCA validates
An independent assessor ratifies or overrides. The override is recorded. The assessor cannot close the item.
Ratified finding
04
Decision
Authorization, reauthorization and risk acceptance are decided by the seat your agency assigns, by default the Authorizing Official.
Decision on the ledger
What every seat shares
Server enforced scope
You see the systems you are cleared for. The restriction is applied before a page renders, not by the page.
Configurable workflow
The ATO workflow is being built to follow your agency's practice: which seats approve, which phases apply. RMF is flexible in the field, and the platform is meant to follow yours rather than dictate it.
NIST SP 800-53 today
Control content, baselines and assessment guidance from the NIST corpus. Further frameworks as they are added.
Federal and commercial
Built around the RMF, usable by any team that has to prove control of a system to someone else.
A record, if you want one
Consequential actions and approvals are written to an activity ledger that exports to the SIEM you already run.
Ask for the demo in your seat.
Tell us your role and we will run the demo from that seat, on synthetic data, so you see exactly what your day looks like.