Every framework. Every system. One view.
Citadel Command Dashboard
The command view of the Redoubt Forge compliance control plane. One world model beneath every capability; Citadel is the lens across all of it: aggregated posture, drift alerts, estate inventory, scan status, and the decisions waiting on a human. Role-prioritized. Never hard-filtered.
The Command View
One model. One view.
Citadel is the command capability in the Redoubt Forge design: the screen that answers what is true, across every system and every framework, at once. It is specified as a lens, not a copy. The architecture holds a single world model beneath every capability, and Citadel is the declared read-view over it: posture from Rampart, alerts and monitoring state from Sentinel, estate inventory from Garrison, scan status from Vanguard. Aggregation is Citadel's whole job. Action belongs to the capabilities that own the work.
One Model, One View
A command dashboard carries a heavy obligation. An executive asks whether the organization is ready. An engineer asks what changed and what broke. An assessor asks where the proof lives. One surface has to answer all three honestly, at the same time, from the same facts. Most of the industry has quietly given up on that: the executive gets a rollup, the engineer gets a console, the assessor gets a binder, and the three disagree with each other by Friday.
The standard failure is the copy. Dashboards are usually fed by exports, sync jobs, and overnight aggregation, and every copy starts aging the moment it lands. The dashboard becomes a second truth that argues with the first, and teams spend real hours reconciling the summary against the systems it claims to summarize. The GRC tool gap is this failure at industrial scale: a product category built on collecting copies of state instead of computing from it.
The Redoubt Forge architecture refuses the copy at the constitutional layer. It holds exactly one causally connected world model: declared resources, observations, evidence, beliefs, and actions as typed, provenanced entries on a single substrate, under a platform law that no capability, service, or agent maintains a private model of the world. In the platform's canonical vocabulary a lens is a capability's declared read-view over that model, and Citadel is the lens built to see all of it. The dashboard is a read, not a reconciliation job: what Citadel shows is what the platform knows, and what the platform knows is computed from the systems themselves.
No Private Models
The law reads plainly: no capability, service, or agent maintains a private model of the world. A dashboard that holds no copy cannot drift from the truth it displays. Staleness is a property of copies, and there are none.
Four Feeds
The capability composition names exactly what converges on the command view. Rampart feeds posture: every control-status change is a typed event addressed to Citadel's feed. Sentinel feeds alerts and monitoring state: a drift alarm is a typed event routed to the command view and to delivery. Garrison feeds estate inventory. Vanguard feeds scan status. The design's own mnemonic is blunt: Garrison is what you have, Vanguard is what you do, Sentinel is what is happening, Rampart is what you are proving. Citadel is SEE.
Aggregation and action are deliberately split. Citadel renders; it performs no action. Every aggregate is a door instead: a control status opens that control's workspace in Rampart, a drift alarm opens the change record in Sentinel, an inventory count opens the estate view scoped to the system in question. The experience layer that owns Citadel also owns the platform's rendering doctrine and design system, so every capability's numbers arrive in one visual language instead of one per capability. And because the Artificer panel is specified as page-aware and scope-aware, the assistant reads the same context as the card beside it.
Posture as a Projection
A posture score compresses thousands of facts into one number, and the compression is where trust is won or lost. What makes a score meaningful is not its precision. It is whether anyone can say what the number was computed from, when, and under which assumptions. A score that cannot answer those questions is decoration.
Two failures repeat across the industry. The propped score: controls marked implemented with thin or aging proof behind them, so the number holds while the evidence underneath decays. And the masked weakness: strong control families averaging away failing ones, so a healthy aggregate hides a family in collapse until an assessor finds it. Both are properties of scoring arithmetic chosen for comfort.
The design makes the arithmetic inspectable. Every control carries a posture record in Rampart, rendered as Control Status, scoped to organization, system, and environment, with the basis it was computed from. The readiness projection aggregates those records under scoring parameters that are declared data rather than buried code: an aggregation mode that can refuse to let strong areas mask weak ones, a decay constant governing how fast past violations are forgiven, normalization scaling, and a weight vector, each declared with a stated default, a rubric, and a sensitivity record. Every projection pins the exact event-stream position it was computed from, upgradeable to a cryptographic receipt on demand. And the tally beneath the score stays honest across every active framework: satisfied, other than satisfied, not applicable, risk-accepted, contested, and unassessed are counted separately, because a contested fact is a first-class state in this architecture, never a silent winner.
A Score That Carries Its Proof
A readiness score in this design is citable: it names the event position it was computed from and can produce a receipt for it. The specification is equally blunt about tuning: weights that do not differ meaningfully carry no signal. The sensitivity record, not the number, is what makes a score worth believing.
Base Layer and Overlay
Compliance runs at two tempos. The continuous tempo never stops: infrastructure changes, evidence ages, deadlines approach. The episodic tempo arrives on a calendar: a formal assessment window, an assessor with questions, an authorization decision at the end. A command view has to serve both without letting either distort the other.
Most platforms pick one. Tools built for the audit go quiet between audits. Tools built for operations bolt the assessment on as a mode switch, and the worst pattern locks the workspace during the assessment window, which punishes exactly the team that keeps fixing things: improvements made mid-audit cannot be credited, work stalls, and the post-audit catch-up burst is where errors breed. The authorization bottleneck owes this pattern a share of the blame.
Citadel's design holds both tempos on one screen. The base layer is permanent: posture trend, drift alerts, evidence freshness, upcoming deadlines. When an assessment is active, overlay cards appear alongside the base layer, shaped to the assessment's stage, and withdraw when authorization is reached. Nothing else changes, because there was never a mode to switch. Underneath sits continuous authorization: the architecture holds authorization as live state maintained event by event, and a point-in-time assessment is a projection computed from that state; the assessment lifecycle assessors already know is preserved as one such projection. The assessor's frame freezes at a chosen position in the event stream, the team keeps working live in Rampart, and the difference between frozen and live renders as a diff from the same event history.
The Assessment Is a Photograph
A formal assessment is a photograph of continuous state, and a camera does not stop its subject. The assessor keeps a frozen frame plus a diff of everything since. The team never stops improving the system the photograph describes.
Cards, Roles, Lenses
A CISO, a platform engineer, and an assessor need different things first. The industry's usual answer is a separate dashboard per role, and it fails quietly: hard filtering decides in advance what each person is allowed to find important, and the fact a role was never shown is reliably the fact that mattered during the incident.
Citadel's rule is role-prioritized, never hard-filtered. Cards are identical components on one route. Role sets the default ordering; a user can reorder, collapse, or hide cards, and nothing is withheld. An engineer's default leads with technical controls and scan state, an analyst's with the action queue and evidence freshness, an assessor's with completeness and the audit trail. The priorities differ. The truth does not.
Some views are lenses in the platform's formal sense: declared read-views over the world model, hosted on the command surface. The freeze-review queue collects what convergence has halted for human review: prediction mismatches, stuck reconciliation, tainted authority. A weekly governance lens reads approval-wait distributions, trust deltas, and budget posture. And the Refusal Lens renders every denied action with the exact gap named: the action attempted, the authority level required, the level actually held. A refusal in this design is an answer, not a dead end.
The Action Queue
A score without direction stalls a team. A seventy-three with seventeen controls open answers nothing about Monday morning. Effort drifts toward whatever is loudest or easiest, low-yield paperwork absorbs the week, and the control that would actually move the defense keeps waiting.
The queue is computed, not curated. The design simulates each incomplete control as implemented, recomputes the readiness projection, and records the difference as that control's predicted score delta; ranking weighs predicted impact against estimated effort and urgency. This rides the platform's constitutional loop, in which every consequential plan is simulated first and every prediction is verified against its outcome. The queue re-ranks as the world changes: a finding born from drift seen by Sentinel or from a Vanguard scan enters posture with its source recorded, and the ordering shifts to match.
Citadel surfaces the queue; it executes nothing. Each item is a door into the capability that owns the work, most often a control workspace in Rampart. The same discipline governs failure across the platform: exhausted retries, exhausted budgets, and frozen convergence all terminate as action items addressed to humans in scope, and the command surface is where those items land. Nothing fails silently into a log.
The Attention Plane
Alert fatigue is a design failure, not a user failure. A dashboard that treats human attention as free will spend all of it: every event becomes a notification, every notification becomes noise, and the one approval that mattered drowns in the ninety-nine that did not. The human is the scarcest component in the loop, and most platforms budget everything except the human.
This design meters attention like the budget it is. Pending approvals of the same class and scope coalesce into one decision card. Approval queues rank by marginal risk reduction, computed from impact, reversibility, and blast radius, never first in, first out. The runtime publishes a predicted approval wait per decision class, and a plan that would exceed its wait budget surfaces that cost before starting, not after.
The decision card itself carries a budget: one screen, a plain-language predicted effect and blast radius, median comprehension in under thirty seconds. And silence has a law. Every escalation class declares how long a consequential item may sit unacknowledged; on breach the pending action halts, the escalation re-routes up the accountability chain, and the item re-offers with full context when a human returns. Tier-3 decisions, risk acceptance and control justification among them, are never delegable by architecture. They arrive as deliberate ceremony surfaces, contracted by Rampart and rendered here, not as one more card in the noise.
An Empty Chair Never Approves
The platform never interprets human silence as consent. An unacknowledged escalation halts the pending action and climbs the accountability chain until it finds a human who answers. Approval is an act, never a timeout.
One View Because One Model
Command dashboards fail two ways: they aggregate copies until the numbers argue with the systems underneath, or they pour everything at the reader until nothing is legible. The Citadel design removes both at the root. No copy exists to drift, because the dashboard is a lens over the same world model every capability writes. Nothing drowns, because cards are prioritized by role and decisions are metered like the budget they are. What remains is what a command view owes you: the state of the defense, the proof behind it, and the next decision that needs a human.