The workflow states an item can occupy. Reordering changes how the pipeline chart is drawn.
| Status | Colour | Type | Counts toward open | ||
|---|---|---|---|---|---|
| ⠿ | Draft | Grey | Initial | ||
| ⠿ | Open | Blue | Active | ||
| ⠿ | In Progress | Violet | Active | ||
| ⠿ | Pending Review | Amber | Approval gate | ||
| ⠿ | Delayed | Orange | Active | ||
| ⠿ | Closed | Green | Terminal |
| Risk rating | Swatch | Remediation window | Reminder schedule | Escalate to | |
|---|---|---|---|---|---|
| Critical | days |
30 / 14 / 7 / 1 day | ISSO + Org Admin | ||
| High | days |
30 / 14 / 7 / 1 day | ISSO | ||
| Moderate | days |
30 / 14 / 7 day | Item owner | ||
| Low | days |
30 / 7 day | Item owner |
The platform is framework-agnostic. Anything that produces a finding can feed the same POA&M workflow.
| Framework | Version | Controls | Used by | Status | |
|---|---|---|---|---|---|
| NIST SP 800-53 | Rev 5 | 1,189 | 3 systems | Enabled | |
| FedRAMP Moderate Baseline | Rev 5 | 323 | 2 systems | Enabled | |
| NIST SP 800-171 | Rev 3 | 97 | Not in use | Available | |
| CIS Benchmarks | v8 | 153 | 1 system | Enabled |
Import and export the POA&M template, with column mapping profiles and dry-run validation.
Upload Nessus, Qualys or generic CSV exports. Findings are de-duplicated against existing records.
Route notification and scheduled-report email through your own mail relay.
Post status changes, closures and overdue events to an external endpoint.
Programmatic access to findings, POA&M items, milestones and evidence.
NIST 800-171 and CMMC questionnaires that generate findings automatically.