Compliance and Authorization
cATOContinuous ATO Evidence Analyzer
Upload the evidence. Read the determination. Decide.
Inside the ATO workflow, a local model reads each artifact against the control it is meant to satisfy and returns a verdict with its reasoning, the indicators it found, the gaps it did not, and what to do next. An assessor ratifies or overrides. Nothing closes on a model verdict alone.
Indicators found
- Account request form with approver signature
- Quarterly review export dated this quarter
- Disable on termination in the SOP
Gaps identified
- policyNo statement of the review frequency for privileged accounts
- evidence missingNo sample showing a disabled account after separation
Recommended action
Add the privileged review frequency to the policy, then upload one termination sample.
Illustrative reading. Control real, findings invented.
The chain
Upload, analyze, combine, ratify
Every step is a separate record. The verdict a control carries is the newest live reading a human has not rejected, and a settled control is never quietly downgraded by a weaker upload that arrives later.
Queued artifacts
- account_request_form.pdf analyzing
- quarterly_review_export.csv queued
- account_management_sop.docx queued
Illustrative queue. Files and times invented.
account_request_form.pdf
Indicators found
- Approver signature on the request form
- Role requested and justification present
Gaps identified
- evidence missingNo sample of an account disabled after separation
One artifact, one reading, with an OSCAL shaped observation attached.
Read together
- account_request_form.pdfPartial
- quarterly_review_export.csvSatisfied
- account_management_sop.docxPartial
Marked stale when newer evidence lands
Gaps that survive the set
- policyNo statement of the review frequency for privileged accounts
- evidence missingNo sample showing a disabled account after separation
Text is never merged across readings. A second model call reads the set.
What follows
- Draft the missing language with PolicyForge
- Upload one termination sample
- SAR and POA&M generated from the ratified status
Nothing closes on a model verdict alone.
01
Upload
Target one control, several, or an entire family. A policy document evidences most of a family at once, so the whole family runs as one batch, already satisfied controls are skipped by default, and the queue shows a time estimate before you commit.
Queued artifacts
- account_request_form.pdf analyzing
- quarterly_review_export.csv queued
- account_management_sop.docx queued
Illustrative queue. Files and times invented.
02
Analyze
The model reads the artifact against the control statement and returns a verdict of satisfied, partial or not satisfied with a confidence, the compliance indicators it found, the gaps it identified with a type on each, a recommended action and an OSCAL shaped observation.
account_request_form.pdf
Indicators found
- Approver signature on the request form
- Role requested and justification present
Gaps identified
- evidence missingNo sample of an account disabled after separation
One artifact, one reading, with an OSCAL shaped observation attached.
03
Combine
When several artifacts speak to one control, a second model call reads them together and produces a single combined verdict. Text is never merged across readings, and the combined verdict is marked stale the moment newer evidence lands.
Read together
- account_request_form.pdfPartial
- quarterly_review_export.csvSatisfied
- account_management_sop.docxPartial
Marked stale when newer evidence lands
Gaps that survive the set
- policyNo statement of the review frequency for privileged accounts
- evidence missingNo sample showing a disabled account after separation
Text is never merged across readings. A second model call reads the set.
04
Ratify
An independent assessor accepts, rejects or overrides each reading, with the override recorded. The control's status follows the ratified reading, and the package documents are generated from it.
What follows
- Draft the missing language with PolicyForge
- Upload one termination sample
- SAR and POA&M generated from the ratified status
Nothing closes on a model verdict alone.
Two assistants at the upload
It tells you what to collect, and drafts what is missing.
AVISSAA
What should I upload for this control?
One click asks AVISSAA for a short list of the artifacts an assessor will expect: what each one shows and how it is assessed. The question changes with the control's state, decided in code: a baseline list when nothing is uploaded, a gap closing list once a verdict shows gaps. The examine, interview and test methods from SP 800-53A are shown instantly with no model call, and a changed gap list marks the advice as stale instead of serving it again.
About AVISSAAPOLICYFORGE
Draft the missing language
Every gap carries a type. Policy and procedure gaps get a button that hands them to PolicyForge, which drafts the language that closes each one: a section per gap with a placement hint and bracketed parameters your organization fills in. Copy it, or save it to the policy library as an amendment drafted from evidence gaps. The uploaded document is never edited in place.
About PolicyForgeEvery gap has a type
A label, not a ranking
-
Policy
The governing document does not say it. PolicyForge can draft it.
-
Procedure
The document says what, not how. PolicyForge can draft it.
-
Technical
The system does not do it yet. Remediation, not wording.
-
Evidence missing
It may be done, but nothing uploaded proves it. AVISSAA says what would.
What the reviewer sees
One reading at a time, not a wall of text
-
Control Status Ledger
A docked list of every control with its current verdict, searchable by control or family. Click one and its panel opens.
-
Processing Queue
Every queued artifact with progress and a time estimate, docked beside the upload.
-
Headline first
The combined verdict is the headline. Each artifact's own reading is one click away in a sidebar, with accept, reject and override right there.
-
History kept, not shown
Superseded readings and identical re-uploads collapse into a history group instead of crowding the control.
Seen in the app
The model reads it. A person still decides.
Every artifact comes back with a reading attached: a verdict, a confidence and the reasoning behind it. The model does the reading so nobody has to work through the document line by line, and none of it counts until a person accepts it.
Submitted, graded, handed back
The decision stays yours
- Accept the reading as it stands
- Reject it and it counts for nothing
- Override the verdict and record why
- Nothing closes on a model verdict alone
When evidence combines
- Two documents, each proving part of a control
- A second pass reads them together into one verdict
- Every artifact keeps its own reading underneath
- Superseded readings collapse into history
The combined verdict is marked stale the moment newer evidence lands, so a control is never quietly settled by an older reading.
Straight answers
Does the AI close controls on its own?
No. It produces a determination for a human to ratify or override, and the override is recorded. Nothing closes on a model verdict alone.
What happens when two artifacts only satisfy a control together?
A combined verdict is produced by a second model call over both artifacts. Their analyses are never spliced together, because that would claim each one proved something it did not.
Can a later, weaker upload undo a satisfied control?
No. A satisfied verdict is not overwritten by weaker later evidence, and already satisfied controls are skipped by default when a family is run.
Does the evidence leave our boundary?
No. Analysis runs on a local model inside your own environment with no external inference calls.
Bring a screenshot. Watch it become a determination.
Ask for a demo and we will run a synthetic artifact against a control family, combine it with a second, and hand the result to an assessor in front of you.


