Authorizing Official
A portfolio of every system under your authority: current state, unmet requirements, waiver exposure, and drift since the last decision. The only role that records a risk decision.
Who it's for
A portfolio of every system under your authority: current state, unmet requirements, waiver exposure, and drift since the last decision. The only role that records a risk decision.
Returns, acceptances, and waivers within delegated limits — maximum expiry, excluded constraint classes — that the server enforces and records.
Composition and publication of requirement sets from versioned framework definitions, system onboarding, rebinding, and reference-binder pinning.
Read access to every binder in scope: evaluation, coverage by framework, drift, and the audit chain.
A template package and an offline validator that reproduce the server's evaluation before submission — plus a submission page with immediate, explained results.
The complete chain of digests behind any binder and its decisions, plus the spillage log. Every question of what was known, by whom, under what authority, when — answered by digests the server already holds.
Tell us which role you sit in.