DECISION QUESTIONCan every privileged account be tied to an approved owner?
AC-2 · OWNER ASSIGNED
Requirement mapped
Implementation owned
Evidence linked
Boundary scoped
AC-2CONTROL
ACCOUNTABLE REVIEW
✓
Basis preserved
Source, scope, and owner stay connected.
PARTNER ECOSYSTEM
Relationships and availability are confirmed per customer.
ONE CONTROL PLANE
Connect once. Map to every framework in scope.
Bring assets, identities, data, telemetry, and evidence into one context graph. ComplAI maps that context across the catalogs in scope while people retain review and decisions.
DATA GOVERNANCE CONTROL PLANEDEPLOYMENT-SCOPED VIEW
Assets & devicesINVENTORY · OWNERS
Identities & accessDIRECTORIES · PRIVILEGES
Data stores & CUIREPOSITORIES · CLASSIFICATION
Telemetry & changeCONFIG · DRIFT · EVENTS
Policies & artifactsSSP · POA&M · PROCEDURES
ComplAIDATA GOVERNANCE CONTROL PLANE
DiscoverASSETS · DATA · IDENTITIES
ClassifySENSITIVITY · CUI · SCOPE
CorrelateONE CONTEXT GRAPH
MapREQUIREMENTS · CROSSWALKS
CONTEXT GRAPHASSETS ↔ IDENTITIES ↔ DATA ↔ CONTROLS
ONE FACT · RELATED REQUIREMENTSMFA enforced — verified once→
NIST 800-53 · IA-2(1)
NIST 800-171 · 03.05.03
CMMC L2 · IA.L2-3.5.3
ISO 27001 · A.8.5
CSF 2.0 · PR.AA-03
SOC 2 · CC6.1
Representative assets, devices, identities, data stores, telemetry, and governed artifacts feed one ComplAI data governance control plane, which discovers, classifies, correlates, and maps that context into a single graph. The plane then relates the same facts to requirements in NIST SP 800-53 Rev. 5, NIST SP 800-171 Rev. 3, CMMC Level 2, ISO/IEC 27001:2022, NIST CSF 2.0, and SOC 2, and those catalogs stay crosswalked to each other. Example: one verified multi-factor authentication fact relates to IA-2(1), 03.05.03, IA.L2-3.5.3, A.8.5, PR.AA-03, and CC6.1. The sequence is illustrative; connectors, catalog availability, and mapping depth are confirmed per deployment, and people retain review.
Representative sources and example requirement relationships. Requirements stay distinct per catalog; mapping depth, availability, and connectors are confirmed for each deployment. People retain review and decisions.
WHY CONTINUOUS ASSURANCE
A status is only useful when the evidence behind it is current.
Compliance work breaks down when the dashboard, evidence folder, asset inventory, and system boundary tell different stories.
ComplAI keeps requirements, implementation, evidence, scope, ownership, and review history connected. When one fact changes, teams can see which conclusions and artifacts need attention.
ASSURANCE WORKSPACE VIEWRELATIONSHIP VIEW · EXAMPLE RECORD
See the program state. Inspect the record behind it.
Illustrative values and event history · not a customer result, authorization decision, assessment result, or readiness score.
01Detect the changeA source signal shifts02Trace the impactLinked context surfaces03Assign the reviewA person retains the decision
CONNECTOR CONTEXTDEPLOYMENT-SCOPED
Source systems in. Governed outputs out.
Representative cloud accounts, identity directories, operating telemetry, repositories, SaaS systems, and data platforms enter through approved connector or custom-ingestion paths. ComplAI's DSPM capabilities can then discover and classify regulated data in scope before the context resolves into governed assurance records.
REPRESENTATIVE SOURCE CONTEXT
Cloud + identity
AWS
Azure
Entra ID
Okta
Security + operations
CrowdStrike
Splunk
ServiceNow
GitHub
Data systems
SharePoint
Box
Databricks
Salesforce
DIRECT CONNECTORSAXONIUS CONTEXTSECURE API / FILECUSTOM ADAPTERS
ComplAI
→
GOVERNED OUTPUTS
EvidenceLinked
PostureMapped
SSP + POA&MPreserved
Findings + driftVisible
CATALOG PORTFOLIO30+
Connect the fact once. See every related requirement.
ComplAI preserves a fact's source, scope, and owner, then shows which requirements it supports across the framework catalogs in your environment.
One fact, multiple relationships
Each requirement keeps its meaning
People review every conclusion
ONE FACT · MANY RELATIONSHIPS6 FEATURED REFERENCES · SELECT ONE
Active lens Registered Portfolio
Controls
Identity
Assets
Evidence
Owner
Scope
ComplAIASSURANCE RECORD
ADDITIONAL CATALOG REFERENCES12 SHOWN · AVAILABILITY VARIES BY DEPLOYMENT
C1CMMC Level 1Active lens
AIRNIST AI Risk Management FrameworkRegistered
SDFNIST Secure Software Development FrameworkRegistered
EAIEU Artificial Intelligence ActRegistered
C3CMMC Level 3Portfolio
172NIST SP 800-172 Rev. 3Portfolio
NPFNIST Privacy FrameworkPortfolio
HIPHIPAA Security RulePortfolio
GDGeneral Data Protection RegulationPortfolio
N2NIS2 DirectivePortfolio
DORDigital Operational Resilience ActPortfolio
CJIFBI CJIS Security PolicyPortfolio
Active lens · Federal controlsNIST SP 800-53 Rev. 5
Follow this federal catalog through shared controls, evidence, scope, and accountable owners. Its requirements and source context stay distinct in the reviewable record.
NIST
Eighteen representative catalog references are shown across active, registered, and portfolio states. Availability, version, mapping depth, and enabled workflows are confirmed per deployment. ComplAI seals are first-party navigation artwork—not official publisher marks, certifications, authorizations, or endorsements, and not assessment results or compliance guarantees.
THE COMPLAI ASSURANCE GRAPH
Trace every conclusion back to the system.
See how each requirement relates to the assets, identities, regulated data, evidence, and accountable review behind its current state.
CONTROLS & EVIDENCE
One relationship model for the facts behind each control.
01
RequirementAC-2 account management
ImplementationLifecycle owner assigned
EvidenceIdentity source linked
Decision recordReview basis preserved
AC-2CONTROL RECORD
NIST SP 800-53 · NIST SP 800-171 · control inheritance
02
SCOPE
Assets & identities
Relate devices, workloads, services, users, and vendors to the boundary they actually influence.
Inventory · access paths · accountable owners
03
DATA
CUI & regulated data
Discover where regulated data lives, understand how it moves, and connect handling expectations to its repositories.
Discovery · classification · lineage · protection
04
OUTPUT
Governed artifacts
Maintain SSP, POA&M, assessment evidence, and authorization context from linked sources and review history.
Source · owner · timestamp · decision trace
TWO HIGH-STAKES WORKFLOWS
Different programs. One connected record.
ATO teams authorize systems. CMMC assessors evaluate implementation. ComplAI keeps those roles distinct while giving both current evidence and a traceable boundary.
Something changes. Your team can see what matters next.
Follow one example from the moment a privileged role changes to the moment a person decides what to do. ComplAI keeps the facts connected so your team can act with context and explain the decision later.
01A change happens
A privileged role changes. Your team sees it clearly.
A privileged role changes in an identity system. ComplAI brings the source and time together in one clear event, so your team begins with what happened—not a spreadsheet hunt.
Where it happened · when it happened · what changed
Entra IDIdentity source
AWSCloud source
CrowdStrikeSecurity source
ServiceNowWorkflow source
ComplAI
What happenedA privileged role changed
The source and time stay attached
Entra IDSeen 2m ago
Illustrative workflow with synthetic records. Source systems and data paths are representative; exact integrations and actions are confirmed for each deployment.
DEPLOYMENT BOUNDARY
Fit the architecture to the data boundary.
ComplAI can be scoped for customer-hosted, commercial-cloud, and government-cloud environments. Before data is connected, the customer and ComplAI document the hosting boundary, approved model provider, ingress and egress, controls, and shared responsibilities. Final architecture and service availability are confirmed for each deployment.
On-premises / customer-hostedCommercial cloudAWS GovCloudAzure Government
ComplAI is available through Carahsoft’s public-sector channel, with direct scoping for deployment and services. Exact vehicle, eligibility, responsibilities, and terms are confirmed for each customer.
The right answer depends on the boundary, decision authority, and deployment constraints. These are the stable starting points.
Is ComplAI only for CMMC?+
No. The platform supports CMMC and ATO / continuous ATO workflows, with a shared model for controls, evidence, assets, identities, regulated data, findings, and artifacts.
Does ComplAI replace the people responsible for authorization or assessment?+
No. ComplAI organizes and automates work, but accountable officials, system owners, security teams, assessors, and authorizing stakeholders retain their respective decisions and responsibilities.
Does regulated data have to be sent to a public AI model?+
That data flow is deployment-specific. Architecture review determines whether a customer-controlled or government-cloud pattern is appropriate; model providers, ingress and egress, and handling rules are confirmed before regulated data is connected.
Can we start with our existing artifacts and tools?+
Yes. A practical rollout starts by inventorying the current boundary, evidence sources, SSP, POA&M, asset records, repositories, and workflows before deciding what to integrate, migrate, or retire.
LET'S TALK
See how ComplAI fits your program.
Tell us what you're working toward. We'll show you how ComplAI can help and where to start.