ATO / CONTINUOUS ATO

Keep the authorization record current as the system changes.

When the system changes, see what it touches — then decide what happens next.

FISMA · NIST SP 800-53 · RMF · continuous monitoring
Scope an ATO working session

THE OPERATING MODEL

See which controls and artifacts a change actually hits.

Implementation notes, evidence, findings, owners, and authorization artifacts stay on the same control record. You can see the impact before it disappears into the next package update.

  1. 01

    Map the boundary, assets, identities, and inherited controls.

  2. 02

    Tie implementation to current evidence and an owner.

  3. 03

    Keep SSP and POA&M content tied to the source records.

  4. 04

    Track drift without rebuilding the package from scratch.

CONTINUOUS AUTHORIZATION

See where the authorization basis is current — and where review is due.

Continuous authorization needs current telemetry, explicit risk decisions, and a traceable change. ComplAI organizes those inputs so you can see the basis — not one opaque score.

01

Evidence freshness

Know which assertions have current telemetry and which need a person.

02

Boundary change

See how new assets, identities, and configurations hit affected controls.

03

Decision history

Keep the evidence, reason, owner, and time behind each authorization decision.

AUTHORIZATION WORKSPACE VIEWRELATIONSHIP VIEW · EXAMPLE RECORD

Review what changed before it reaches the decision record.

reviewablesignal → context → owner
REVIEW STATEExample record
  • Current61%
  • Review due25%
  • Action open14%
Latest linked changeConfiguration signal receivedTrace affected context
RELATIONSHIP SIGNALSFive checkpoints

Five checkpoints compare linked context with review attention. Hover, tap, or use the arrow keys to inspect each checkpoint.

86%linked context
+38 pts
HUMAN REVIEW PATHAccountability retained
  • Decision ownerassigned
  • SSP reviewerreview due
  • Boundary stewardcontext needed
CHANGE TIMELINENeeds attention
  1. Configuration signal receivedSource linked
    SR
  2. SSP impact review openedChange traced
    DO
  3. Decision owner requestedAssignment due
    ?

Illustrative values and event history · not a customer result, authorization decision, assessment result, or readiness score.

COMMON QUESTIONS

Asked before scoping.

Short answers that stay true whatever your boundary looks like.

Does ComplAI make the ATO decision?

No. It organizes the boundary, controls, evidence, and change history so the basis is visible. Authorizing officials keep the decision.

What does continuous ATO require?

Current telemetry, explicit risk decisions, and a traceable record of what changed — not a single opaque score.

Do we rebuild the package when something drifts?

No. ComplAI tracks drift against the existing record, so the SSP and POA&M stay tied to their sources instead of being rebuilt from scratch.

Can we start from our current authorization workflow?

Yes. Start with the boundary, artifacts, and decision points you already have, then decide what to connect next.

NEXT DECISION

Start with the authorization workflow you have today.

We’ll map the people, evidence, artifacts, and decision points before proposing a rollout.

Scope an ATO working session