The workflow states an item can occupy. Reordering changes how the pipeline chart is drawn.

StatusColourTypeCounts toward open
DraftGreyInitial
OpenBlueActive
In ProgressVioletActive
Pending ReviewAmberApproval gate
DelayedOrangeActive
ClosedGreenTerminal

Next will be POAM-0192. Tokens: {seq}, {year}, {system}, {control}.
Next will be FND-0319.
Default windows follow FedRAMP guidance: high and critical within 30 days of discovery, moderate within 90 days, low within 180 days. Shortening a window is allowed; lengthening one is not.
Risk ratingSwatchRemediation windowReminder scheduleEscalate to
Critical
days
30 / 14 / 7 / 1 day ISSO + Org Admin
High
days
30 / 14 / 7 / 1 day ISSO
Moderate
days
30 / 14 / 7 day Item owner
Low
days
30 / 7 day Item owner

The platform is framework-agnostic. Anything that produces a finding can feed the same POA&M workflow.

Vulnerability Scan61 findings
3PAO Assessment34 findings
Penetration Test19 findings
Internal Audit17 findings
Customer Audit5 findings
Manual Observation12 findings
FrameworkVersionControlsUsed byStatus
NIST SP 800-53Rev 51,1893 systemsEnabled
FedRAMP Moderate BaselineRev 53232 systemsEnabled
NIST SP 800-171Rev 397Not in useAvailable
CIS Benchmarksv81531 systemEnabled
Control mapping is optional. Findings can be tracked without one, which is what keeps the platform framework-agnostic.
Require MFA for all users
Single sign-on (Azure AD / SAML / OIDC)
Block password sign-in when SSO is available
Allow external auditor accounts
Encryption in transitTLS 1.3
Encryption at restAES-256
Key managementCustomer-managed keys
Evidence retention3 years after closure
Audit log retention7 years, append-only
BackupsNightly, off-site, 35-day PITR
Leave blank to allow access from anywhere. External auditor accounts bypass this list.
Phase 1 supports file-based ingest only. Direct scanner, Microsoft 365 and cloud-provider connectors are planned for Phase 3.

FedRAMP Workbook

Import and export the POA&M template, with column mapping profiles and dry-run validation.

Available now

Scanner CSV Ingest

Upload Nessus, Qualys or generic CSV exports. Findings are de-duplicated against existing records.

Available now

SMTP / Email Delivery

Route notification and scheduled-report email through your own mail relay.

Not configured

Webhooks

Post status changes, closures and overdue events to an external endpoint.

Phase 3

REST API

Programmatic access to findings, POA&M items, milestones and evidence.

Phase 3

Assessment Engine

NIST 800-171 and CMMC questionnaires that generate findings automatically.

Phase 2