DECISION QUESTIONCan every privileged account be tied to an approved owner?
AC-2 · OWNER ASSIGNED
Requirement mapped
Implementation owned
Evidence linked
Boundary scoped
AC-2CONTROL
ACCOUNTABLE REVIEW
✓
Basis preserved
Source, scope, and owner stay connected.
PARTNER ECOSYSTEM
Relationships and availability are confirmed per customer.
ONE CONTROL PLANE
Connect once. Map to every framework in scope.
Bring assets, identities, data, telemetry, and evidence into one context graph. ComplAI maps that context across the catalogs in scope while people retain review and decisions.
DATA GOVERNANCE CONTROL PLANEILLUSTRATIVE · DEPLOYMENT-SCOPED
Assets & devicesINVENTORY · OWNERS
Identities & accessDIRECTORIES · PRIVILEGES
Data stores & CUIREPOSITORIES · CLASSIFICATION
Telemetry & changeCONFIG · DRIFT · EVENTS
Policies & artifactsSSP · POA&M · PROCEDURES
ComplAIDATA GOVERNANCE CONTROL PLANE
DiscoverASSETS · DATA · IDENTITIES
ClassifySENSITIVITY · CUI · SCOPE
CorrelateONE CONTEXT GRAPH
MapREQUIREMENTS · CROSSWALKS
CONTEXT GRAPHASSETS ↔ IDENTITIES ↔ DATA ↔ CONTROLS
ONE FACT · RELATED REQUIREMENTSMFA enforced — verified once→
NIST 800-53 · IA-2(1)
NIST 800-171 · 03.05.03
CMMC L2 · IA.L2-3.5.3
ISO 27001 · A.8.5
CSF 2.0 · PR.AA-03
SOC 2 · CC6.1
Representative assets, devices, identities, data stores, telemetry, and governed artifacts feed one ComplAI data governance control plane, which discovers, classifies, correlates, and maps that context into a single graph. The plane then relates the same facts to requirements in NIST SP 800-53 Rev. 5, NIST SP 800-171 Rev. 3, CMMC Level 2, ISO/IEC 27001:2022, NIST CSF 2.0, and SOC 2, and those catalogs stay crosswalked to each other. Example: one verified multi-factor authentication fact relates to IA-2(1), 03.05.03, IA.L2-3.5.3, A.8.5, PR.AA-03, and CC6.1. The sequence is illustrative; connectors, catalog availability, and mapping depth are confirmed per deployment, and people retain review.
Illustrative sequence with representative sources and related requirements. Requirements stay distinct per catalog; mapping depth, availability, and connectors are confirmed for each deployment. People retain review and decisions.
WHY CONTINUOUS ASSURANCE
A status is only useful when the evidence behind it is current.
Compliance work breaks down when the dashboard, evidence folder, asset inventory, and system boundary tell different stories.
ComplAI keeps requirements, implementation, evidence, scope, ownership, and review history connected. When one fact changes, teams can see which conclusions and artifacts need attention.
ILLUSTRATIVE ASSURANCE WORKSPACERELATIONSHIP VIEW · EXAMPLE RECORD
See the program state. Inspect the record behind it.
Illustrative values and event history · not a customer result, authorization decision, assessment result, or readiness score.
01Detect the changeA source signal shifts02Trace the impactLinked context surfaces03Assign the reviewA person retains the decision
CONNECTOR CONTEXTDEPLOYMENT-SCOPED
Source systems in. Governed outputs out.
Representative cloud accounts, identity directories, operating telemetry, repositories, SaaS systems, and data platforms enter through approved connector or custom-ingestion paths. ComplAI's DSPM capabilities can then discover and classify regulated data in scope before the context resolves into governed assurance records.
REPRESENTATIVE SOURCE CONTEXT
Cloud + identity
AWS
Azure
Entra ID
Okta
Security + operations
CrowdStrike
Splunk
ServiceNow
GitHub
Data systems
SharePoint
Box
Databricks
Salesforce
DIRECT CONNECTORSAXONIUS CONTEXTSECURE API / FILECUSTOM ADAPTERS
ComplAI
→
GOVERNED OUTPUTS
EvidenceLinked
PostureMapped
SSP + POA&MPreserved
Findings + driftVisible
CATALOG PORTFOLIO30+
One assurance graph. A 30+ catalog portfolio.
Relate applicable requirements to the same controls, evidence, systems, identities, and owners while keeping each catalog's maturity and deployment scope visible.
Requirements stay distinct
Evidence can be reused with context
Catalog maturity stays visible
CATALOG RELATIONSHIP VIEW6 FEATURED REFERENCES
Active lens Registered Portfolio
ComplAICONTROL GRAPH
ADDITIONAL CATALOG REFERENCES12 SHOWN · AVAILABILITY VARIES BY DEPLOYMENT
C1CMMC Level 1Active lens
AIRNIST AI Risk Management FrameworkRegistered
SDFNIST Secure Software Development FrameworkRegistered
EAIEU Artificial Intelligence ActRegistered
C3CMMC Level 3Portfolio
172NIST SP 800-172 Rev. 3Portfolio
NPFNIST Privacy FrameworkPortfolio
HIPHIPAA Security RulePortfolio
GDGeneral Data Protection RegulationPortfolio
N2NIS2 DirectivePortfolio
DORDigital Operational Resilience ActPortfolio
CJIFBI CJIS Security PolicyPortfolio
Active lens · Federal controlsNIST SP 800-53 Rev. 5
Requirements in this federal catalog stay related to shared controls, evidence, scope, and accountable owners. Availability and mapping depth remain deployment-scoped.
NIST
Eighteen representative catalog references are shown across active, registered, and portfolio states. Availability, version, mapping depth, and enabled workflows are confirmed per deployment. ComplAI seals are first-party navigation artwork—not official publisher marks, certifications, authorizations, or endorsements, and not assessment results or compliance guarantees.
THE COMPLAI ASSURANCE GRAPH
Trace every conclusion back to the system.
See how each requirement relates to the assets, identities, regulated data, evidence, and accountable review behind its current state.
CONTROLS & EVIDENCE
One relationship model for the facts behind each control.
01
RequirementAC-2 account management
ImplementationLifecycle owner assigned
EvidenceIdentity source linked
Decision recordReview basis preserved
AC-2CONTROL RECORD
NIST SP 800-53 · NIST SP 800-171 · control inheritance
02
SCOPE
Assets & identities
Relate devices, workloads, services, users, and vendors to the boundary they actually influence.
Inventory · access paths · accountable owners
03
DATA
CUI & regulated data
Discover where regulated data lives, understand how it moves, and connect handling expectations to its repositories.
Discovery · classification · lineage · protection
04
OUTPUT
Governed artifacts
Maintain SSP, POA&M, assessment evidence, and authorization context from linked sources and review history.
Source · owner · timestamp · decision trace
TWO HIGH-STAKES WORKFLOWS
Different programs. One connected record.
ATO teams authorize systems. CMMC assessors evaluate implementation. ComplAI keeps those roles distinct while giving both current evidence and a traceable boundary.
Follow one synthetic account change from question to evidence, human review, and a durable decision record.
01Ask the environment
Questions run against the live boundary.
Ask in plain language. ComplAI investigates connected sources and returns an answer with the evidence attached — never a bare status.
Ask the environmentSynthetic records
Question · asked in ComplAI
Which privileged accounts changed in the last 7 days?Which privileged accounts changed in the last 7 days?
Investigating connected sources
3 sources in scope
Identity directoryaccounts · roles
Change logapprovals · tickets
Access reviewsrecurring cycles
Answer · evidence cited
Three privileged accounts changed. Two match approved requests. svc-build-04 has no linked owner approval.Three privileged accounts changed. Two match approved requests. svc-build-04 has no linked owner approval.
identity-export.json · 2m ago
change ticket #4821
access review · Q3 cycle
CORouted to the control owner for review — question, answer, and sources stay together.
Scoped questions
Which systems hold CUI without a linked handling rule?
Whose evidence goes stale in the next 30 days?
Which findings still have no accountable owner?
The boundary shapes the answer.
Questions resolve against the systems, identities, and data actually in scope — not a generic index.
Answer anatomy
svc-build-04 has no linked owner approval.
source · identity exportcollected · 2m agoowner · CO
Every answer keeps its basis.
Source, collection time, and accountable owner ride along with the response.
02Trace live evidence
Every fact keeps its source.
Evidence stays connected to where it came from, when it was collected, and the requirement it supports — freshness and provenance resolve in view.
Trace live evidenceSynthetic records · AC-2
Identity directoryexport · signed
Cloud configurationsnapshot · current
Document storepolicy · v14
Evidence record · EV-2041Privileged account export
Proposal · prepared for reviewOpen an account review for svc-build-04 and update the SSP §9.2 narrative.Review required — waiting on the decision owner
Impact scope
3relationships affected
14unchanged
Only what changed demands attention.
The relationship graph bounds the blast radius, so review effort follows actual impact.
Every prepared review lands with an accountable owner and a due date.
04Authorize the action
A person approves. The record shows why.
Scope, impact, and rollback sit in front of the decision owner before anything proceeds. Authority stays human; context stays complete.
Authorize the actionSynthetic records · human review
Proposal · account review for svc-build-04Review required
Scope1 service account · 2 systems
ImpactAC-2 narrative · 1 POA&M entry
RollbackRevert grant or document the exception
DO
Decision ownerReviewed scope, impact, and rollback
Approved
Decision recordApproved · basis preservedsource · owner · time
Authority stayed with a person. ComplAI kept the context.
Decision record
WhoDecision owner · DO
WhenRecorded with the change
BasisScope · impact · rollback
Approval is an artifact.
Who decided, when, and on what basis — preserved in the same graph as the evidence.
Rollback visible
Revert the privileged grant
Or document the exception with an owner
Every approval knows its exit.
The reverse path is part of the proposal, not an afterthought.
05Preserve the decision
Approved once. Precedent afterward.
Each decision joins a chronological trace. The next time a similar change appears, the prior decision is already there.
Preserve the decisionSynthetic records · trace
MAYAccess recertificationapproved
JUNBoundary changeapproved
AUGsvc-build-04 account reviewapproved · decision recorded
Next cycle · new signalPrivileged grant detected · svc-data-02Precedent available · 1 prior decision
The next review starts from the last decision, not from zero.
Continuity
linked context across review checkpoints
The record outlasts the moment.
Decisions, evidence, and ownership stay reviewable across cycles, staff changes, and assessments.
Precedent recall
AUG · decision recordsvc-build-04 account reviewcited in 2 later reviews
Institutional memory, on demand.
Prior decisions resurface beside similar changes instead of living in someone's inbox.
Illustrative product choreography with synthetic records · not a customer result, authorization decision, assessment result, or readiness score.
DEPLOYMENT BOUNDARY
Fit the architecture to the data boundary.
ComplAI can be scoped for customer-hosted, commercial-cloud, and government-cloud environments. Before data is connected, the customer and ComplAI document the hosting boundary, approved model provider, ingress and egress, controls, and shared responsibilities. Final architecture and service availability are confirmed for each deployment.
On-premises / customer-hostedCommercial cloudAWS GovCloudAzure Government
ComplAI is available through Carahsoft’s public-sector channel, with direct scoping for deployment and services. Exact vehicle, eligibility, responsibilities, and terms are confirmed for each customer.
The right answer depends on the boundary, decision authority, and deployment constraints. These are the stable starting points.
Is ComplAI only for CMMC?+
No. The platform supports CMMC and ATO / continuous ATO workflows, with a shared model for controls, evidence, assets, identities, regulated data, findings, and artifacts.
Does ComplAI replace the people responsible for authorization or assessment?+
No. ComplAI organizes and automates work, but accountable officials, system owners, security teams, assessors, and authorizing stakeholders retain their respective decisions and responsibilities.
Does regulated data have to be sent to a public AI model?+
That data flow is deployment-specific. Architecture review determines whether a customer-controlled or government-cloud pattern is appropriate; model providers, ingress and egress, and handling rules are confirmed before regulated data is connected.
Can we start with our existing artifacts and tools?+
Yes. A practical rollout starts by inventorying the current boundary, evidence sources, SSP, POA&M, asset records, repositories, and workflows before deciding what to integrate, migrate, or retire.
LET'S TALK
See how ComplAI fits your program.
Tell us what you're working toward. We'll show you how ComplAI can help and where to start.