Profile
Manage account access.
Evidence detailsChecking
Not assignedData Date sourceLoading the accepted schedule date.Checking effective role and scopeBounded evidence only · original schedule source remains protectedProfile content
Role composition changes priority and disclosure only. API tokens remain read-only and visible once.
Not authority
Your hosted account identity and current presentation composition.
Permissions grant access. Composition only changes priority and initial disclosure.
Change password
Create read-only API/MCP token
Readiness contract definitions
Defined-only pending provider evidence and review dates.
Eight evidence gates; no packet is marked ready.
No operating ConMon claim.
No recurring KRI result; missing is not zero.
No per-control statements; evidence is required.
Defined-only; hosted components await boundary approval.
Quarterly access-review records are not populated; no production IAM/MFA or revocation claim is made.
MFA, reauthentication, lockout, revocation, and privileged access are gated; no production authentication or authorization claim.
Incident records are not populated; the response runbook and metadata-only contract remain readiness design.
Key records are metadata-only and not populated; no KMS, rotation, revocation, or hosted encryption operation claim is made.
Certificate records are bounded metadata-only design; no hosted TLS, renewal monitoring, or boundary approval claim is made.
Secret records are reference-only and not populated; no secret-manager, rotation automation, or production credential review claim is made.
Machine identity records are scoped design only; no production IAM, workload identity, rotation, or break-glass operation claim is made.
Vulnerability records are bounded design only; no scanning, remediation operation, or assessment-result claim is made.
Baseline and drift records are metadata-only design; no approved hosted baseline or drift-monitoring operation claim is made.
Change records are readiness design; no production change board, FedRAMP process, or release-gate operation claim is made.
Boundary decisions are metadata-only readiness design; the current CUI boundary remains local-only and hosted components are not approved.
Retention records are design-only; no approved duration, legal-hold tooling, WORM operation, or disposal cadence claim is made.
Recovery records are design-only; no backup, restore, failover, or disaster-recovery operation claim is made.
Classification decisions are metadata-only design; no CUI determination, external sharing approval, or boundary expansion claim is made.
Egress approvals are readiness design; no DLP, transfer enforcement, or operating export workflow claim is made.
Log access records are metadata-only design; no hosted access control, reviewer segregation, or privileged-operation enforcement claim is made.
Endpoint attestations are design-only; no MDM, EDR, encryption, or endpoint-attestation tooling operation claim is made.
Exceptions are time-bound design records; no risk acceptance or boundary-expansion approval claim is made.
Lifecycle records are metadata-only readiness design; no production IAM, MFA, screening, training, or revocation operation claim is made.
Privacy inventory is defined-only; no PII processing, FedRAMP PT-family applicability, or privacy-program operation claim is made.
Training records are metadata-only readiness design; no learning system, completion population, or recurring awareness operation claim is made.
Component and SBOM records are defined-only; no package registry, scanner, supplier assurance, or dependency approval operation claim is made.
Maintenance records are metadata-only readiness design; no support portal, privileged-access workflow, or hosted maintenance operation claim is made.
Privileged access records are metadata-only readiness design; no MFA, session recording, revocation, or break-glass operation claim is made.
Data-flow records are defined-only; hosted Kafka, remote S3 WORM, CLP, and other external movement remain unapproved candidates.
Media records are defined-only; no sanitization, disposal, encrypted workspace, or WORM disposal operation claim is made.
Auditor-view receipts are defined-only and read-only; no hosted auditor view or raw-log access operation claim is made.
CI evidence records are defined-only; no scanner, SBOM, secret-scan, or release-enforcement operation claim is made.
Responsibility rows are draft readiness design; no customer commitment, provider inheritance, or hosted service operation claim is made.
Control-test results are defined-only; no assessor workpaper, operating-control, hosted-approval, or authorization claim is made.
Cadence records are defined; no recurring review/operating evidence claim.
Workpaper records are defined-only; no assessor, CMMC, FedRAMP, or operating-control claim is made.
Package dispositions are defined-only; no readiness, sampling, or authorization claim is made.
POA&M records are defined-only; no FedRAMP POA&M, assessment result, weakness closure, or authorization claim is made.
Evidence-request records are defined-only; no assessor response, operating-control result, or authorization claim is made.
Assessment periods are defined-only; no CMMC, FedRAMP, SOC 2, or hosted-boundary approval claim is made.
No path selected; Rev5/20x planning only; no certification or authorization claim.
20x package inventory; required_elements load below.
Owner API loading; no assessment result or certification claim (no assessment or certification claim).
Coverage loading; not an assessment.
Integrity loading.
CMMC: not evaluated · affirmation not evaluated
Loading.
Browser render readiness; not conformance.
Outbox health; does not prove Kafka, WORM, or CLP operation.
Owner API loading; no validation or certification claim.
Owner API loading; no certification or authorization claim.
KSI posture loading; no certification or authorization claim.
Security decision posture loading; no certification or authorization claim.
Ongoing certification posture loading; no certification or authorization claim.
Secure configuration posture loading; no certification or authorization claim.
Package overview posture loading; no certification or authorization claim.
Loading.
-
Nine; no authorization claim.
Index; artifacts stay outside.
Kafka offsets are permitted only after a verified receipt; failures remain replayable.
Not run is not success.
CMMC Level 2 basis; FedRAMP Rev. 5 and FedRAMP 20x are future planning overlays.
Review status and evidence steps
Steps update from visible page evidence. Blocked and withheld states name the boundary; no completion percentage is inferred.
Discussion questions and talking points
Observed → derived → withheld remains explicit. These talking points stay tied to the selected evidence; they are not an unrestricted database question box.
Unavailable context remains explicitly not supplied.
This talking point preserves the page’s evidence and authority boundary.
