What exists. What existed.
Garrison Temporal Estate
Garrison is the connected estate with full temporal history. The design holds the present and the past of every component: hardware and software inventory for CM-8, a what's-changed default view, ephemeral entities included, and compliance history retained beyond the life of the entity it describes.
The Temporal Estate
An inventory that remembers.
Garrison is the record of what an organization has. The architecture defines it as the temporal estate: every system and environment, every discovered component, and the full history of each one, ephemeral entities included. Discovery populates the estate; Sentinel executes collection, and Garrison holds the durable entity, its lifecycle, and its compliance touchpoints. What exists now and what existed at time T are the same query against the same record. That is the design's answer to the first question every framework asks.
The Estate Record
Asset inventory is the control every other control quietly depends on. You cannot assess a system you cannot enumerate. You cannot harden the storage you do not know exists. Every framework asks the same first question: what do you have. Most organizations answer it with a spreadsheet, assembled by hand from console exports and institutional memory, accurate on the day it is filed and wrong by the next deploy. The inventory then decays in private, and every control that cites it inherits the decay.
The Redoubt Forge design refuses to make inventory a document anyone maintains. Discovery populates the estate: Sentinel executes collection, and its observation record is the feed the estate projects from, never the estate itself. Garrison holds the durable entity: the component that persists across observations, scoped to its system and environment, carrying its lifecycle and its history. The architecture states the boundary in one sentence with three places: Rampart interprets, Sentinel executes collection, the estate holds custody. Citadel aggregates the estate inventory into its command view. Nothing in Garrison discovers, detects, or monitors; it is the record those activities populate.
What Existed at Time T
The present tense is the easy half of inventory. Audits live in the past. A SOC 2 Type II report covers a review window measured in months. An assessor samples a date and asks what was in place. An incident review asks what the environment looked like on the day of the event, not the day of the meeting. A present-only inventory cannot answer any of these questions, so the answer becomes archaeology: old exports, ticket threads, and whoever was in the room.
Two Clocks on Every Fact
When the world changed and when the platform learned of it are different facts. The bitemporal law keeps both, because an honest history must distinguish what was true from what was believed. Assessments depend on the first. Accountability depends on the second.
The architecture makes time a first-class axis rather than an archive. Under the platform's bitemporal law, every event carries two timestamps: when the world was in that state, and when the platform recorded it. As-of queries resolve either axis, which yields two distinct, answerable questions: what was true of this component at time T, and what did the platform believe at time T. Garrison is the estate rendered against that law. "What existed at time T" sits in its capability definition, not on a wish list: the design holds temporal history as part of the estate itself, so the past is a query, not a restoration project. Alliance extends the same axis outward: the design admits external assessors as scoped, time-boxed actors with as-of evidence lenses.
History Outlives the Entity
Estates stopped being durable years ago. Containers live for minutes. Build runners exist for one job. Functions scale to zero between invocations. AI estates add another layer: models, prompts, and agent tools that change faster than any server ever did. Inventory tools built for racked hardware assume the entity outlives the question, so when a resource is deleted its record usually goes with it. The compliance question does not die with the workload. Was the container that processed regulated data on June 9 hardened? The resource is gone. The obligation is not.
Garrison's capability definition answers this directly: ephemeral and AI-estate entities are included in the estate, and compliance history is retained beyond the entity's lifespan. A terminated component keeps its record. What it was, where it lived, what was observed about it, and which controls it touched remain queryable after the entity itself is gone. That property falls out of the platform's constitution rather than a retention feature: compliance state is event-sourced, with events as the source of truth and entities as projections, so deleting a resource never deletes the history that described it. Evidence from a short-lived entity stays part of the record Rampart reads, long after the workload itself is forgotten; the evidence chain keeps its earliest links.
Terminated Is Not Deleted
In an event-sourced estate, ending an entity is one more event in its history, not the end of its history. The design retains compliance history beyond the entity's lifespan, because assessors ask about workloads that no longer exist and deserve an answer with provenance.
What's Changed, by Default
A complete inventory is a poor place to start the day. At estate scale the full roster runs to thousands of components, and a list that long hides the one thing a reviewer actually needs: what is different since the last look. Teams that open a full-list view learn to stop opening it. Change is where risk enters an estate, and a view that treats change as a filter buries it under everything that stayed the same.
The design makes the delta the default. Garrison's capability row specifies what's-changed as the estate's default view: it opens on what moved, not on the roster. The change signal itself belongs to Sentinel, whose design classifies every detected change by drift class (access, structure, config, or lifecycle) and marks its significance as posture-bearing or informational. The estate view is specified to render that stream against the entity record: which component changed, what facet, the state before and after, and when. The division of labor holds even here. Sentinel detects; the estate displays what detection wrote. And because change events re-evaluate posture, Rampart answers for what the change means while Garrison shows where to look.
CM-8 Without the Spreadsheet
CM-8 in NIST 800-53 requires an inventory of system components that is accurate, current, and complete: hardware and software, at a granularity useful for accountability. It is a modest sentence with a brutal failure mode. In most programs the inventory is a quarterly reconciliation exercise: exports, screenshots, a spreadsheet three people maintain and nobody trusts. It fails quietly, and because so many other controls cite the inventory, its staleness leaks into their evidence too.
The architecture removes the transcription step entirely. In its control mapping, the system component inventory IS the discovery output: enumeration with configuration capture at a derived cadence, where every component is an observation carrying provenance and a freshness horizon rather than a spreadsheet row. The estate projects the CM-8 inventory from those recorded observations, and hardware and software inventory is named in Garrison's own capability definition. Interpretation stays where it belongs: Rampart judges whether the inventory satisfies the control, Garrison holds the record that judgment reads from, and Sentinel supplies the observations beneath both.
Inventory as Output, Not Task
A spreadsheet is an assertion about the estate. A projection is a consequence of it. In this design a component record exists because the component was observed, with provenance and a freshness horizon attached; there is nothing to transcribe and therefore nothing to transcribe wrongly. That is the difference between maintaining an inventory and having one.
Compliance Touchpoints
An inventory that stands apart from the compliance program is trivia with timestamps. The useful questions about any component are relational: which controls lean on it, which evidence came from it, what expires if it changes, who answers for it. In most programs that mapping lives in analysts' heads and in cross-references between tools that were never introduced to each other, and it is rebuilt by hand for every assessment.
Garrison's definition names compliance touchpoints as part of the estate record itself: each entity carries its connections into the compliance program. The architecture goes further and places evidence custody at the estate, alongside the design's evidence fabric: the collection-to-satisfaction pipeline, the expiration workflow, and continuous freshness. When a satisfaction expires, the expiration event itself emits a re-collection task as a declared resource, under an invariant that no consequential act consumes evidence past its horizon. The intended effect is an estate where evidence decay is a scheduled event rather than a discovered emergency, and where Rampart's interpretation reads from custody that knows how fresh its contents are.
Outpost Graduation
Not everything an organization scans belongs to its estate. Teams evaluate a repository before adopting it, test a third-party component before integrating it, probe a proof of concept before it earns a system boundary. Outposts exist for exactly this: saved scan targets, scanned by Vanguard, with their own trend history, deliberately outside any system. The failure mode of evaluation work is that it never formally becomes anything; the proof of concept ships, and the estate never hears about it.
The capability inventory writes the transition as a pipeline with three stations: an Outpost graduates into the Garrison estate, and Sentinel monitoring follows. Graduation makes the target a durable estate entity: scoped to a system and environment, carrying its trend history forward, and subject to the same temporal record as everything else the estate holds. Because the platform is event-sourced, the graduation itself becomes part of the entity's history. The moment "we are evaluating this" became "we own this" is a fact the estate can produce later, at time T, like any other.
The Estate Is a Timeline
Every framework asks first what you have. Every audit eventually asks what you had. A present-only inventory answers one question and improvises the other. Garrison is designed so both are the same query: an estate projected from events, two clocks on every fact, and history that outlives the entity it describes. What exists is in the estate. What existed still is.