Every framework is a projection. Your posture is the source.

Rampart Compliance Engine

Authorization held as live state, event by event. Assessments, readiness scores, and compliance documents are projections of that state, rendered from one defended implementation into any framework an assessor requires. Proof computed, never assembled.

Security is the source. Compliance is the proof.

Rampart is the compliance engine at the center of the Redoubt Forge design. Its architecture holds authorization as live state and renders every framework an assessor requires as a projection of that state. You do not maintain separate evidence sets for separate frameworks. You maintain one defended implementation; Rampart is designed to project it.

Continuous Authorization

The industry treats authorization as an event: a document set assembled for a date, stale the day after. Rampart’s design holds it as state. Compliance state is maintained event by event on an append-only spine, and every point-in-time assessment, readiness score, and compliance document is a projection computed from that state, never a construction. Each control carries a living status from a closed set: unassessed, satisfied, other than satisfied, not applicable, risk accepted, or contested. That last state matters. When two derivations conflict, the design forces a contested status and a resolution instead of letting one answer win silently. The authorization bottleneck exists because proof is rebuilt for every date that matters; a projection has no rebuild.

Never a Bare Verdict

In the Rampart schema, a control status cannot exist without its basis. The satisfaction mappings that justify it are a required field, and a readiness score carries the exact event-log position it was computed at. The answer and its proof travel as one object.

Scoring is data, not code. The design declares a parameter space: an aggregation mode, including a two-tier form that refuses to let strong control families mask weak ones; a decay constant governing how fast past violations are forgiven; normalization scaling; and an explicit weight vector. Each parameter carries a stated default and a sensitivity record, because a weight that does not change the outcome carries no signal. The whole structure is rebuildable by construction: the design’s standing proof drops the entire compliance schema, replays the event stream, and requires the result to arrive byte-equal. Posture computed this way feeds Citadel as the base layer of its command view.

The Mapping Engine

Frameworks share ancestry, and the mapping engine is built on that fact. CMMC Level 2 is defined by the NIST 800-171 control set; the published cross-walk is identity, not interpretation. FedRAMP baselines are catalog artifacts on NIST 800-53 rev5. The design resolves relationships across every active framework through five declared strategies: native mapping, derivation through NIST 800-53, bridging through NIST CSF 2.0, published cross-walks, and AI-suggested mappings. Strategy records how a mapping was derived. A separate fidelity class records how authoritative that derivation is. A third dimension, coverage, records whether the source control satisfies the target requirement entirely or only in part, because those are different claims and the engine refuses to blur them.

The guards are structural. An AI-suggested mapping counts toward posture only after a named human confirms it; until then it is excluded from every posture basis. A partial mapping never carries the weight of a full one, and cannot be recorded without a note naming exactly what is not covered. Every mapping records its full derivation path, requirement to CCI to 800-53 control to target practice, so an assessor walks the chain instead of taking it on faith. Satisfy one control and coverage recompute re-scores every framework that shares it. That is the answer to multi-framework overhead: the work is done once, against the implementation, and projected everywhere it counts.

Evidence Freshness

Rampart is designed to interpret evidence, never to collect it. Discovery, monitoring, and collection are Sentinel’s work, and the estate those observations describe lives in Garrison. What Rampart’s design owns is the interpretation side: the satisfaction mapping that binds an evidence artifact to the controls it satisfies, and the freshness horizon on that mapping, the declared moment past which belief lapses. The default horizon is 365 days, with per-class overrides carried as governed data rather than code.

Expiry is enforced, not advisory. When a load-bearing mapping crosses its horizon, the control’s status demotes from satisfied to other than satisfied and a re-collection demand goes out; stale evidence never silently satisfies, by architecture. This is evidence decay treated as a design problem instead of an audit-week surprise: belief has a half-life, the schema records it, and the posture presented to an assessor is only ever built from mappings there are still grounds to believe.

Findings and POA&Ms

A finding is born from a scan result out of Vanguard, from detected drift, from a manual entry, or from an assessor, and it moves through an explicit lifecycle: ten states from open through triage, confirmation, assignment, remediation, and verification to closed, with false positive and duplicate as honest terminals. AI triage is bounded by design: a suggestion posts only above a declared confidence floor of 0.85, and it suggests. A human confirms. Task delegation rides assignment, so every confirmed finding resolves to a named owner. Remediation execution is deliberately not Rampart’s: the design emits what must change as declared resources, and governed remediation actors execute under their own authority contracts.

POA&M management is built for honesty under slippage. When a scheduled completion passes unmet, the item moves to delayed, and the delay is assessor-visible, never silently re-dated; a re-plan records the new date beside the old, history intact by append-only construction. The human is structural here, not decorative: triage suggests, a named human confirms, and every confirmed finding resolves to a named owner.

Two Rulings No Machine Can Make

Risk acceptance and marking a control not applicable are human-only by architecture. The design admits no automation path, no approval-queue path, and no policy-time pre-approval for either act; without a live step-up by a named human, the act refuses. An acceptance carries a 365-day ceiling: one recorded with no expiry is stored at the ceiling, never as permanence, and when it lapses the unwind runs through posture, finding, and POA&M alike. Nothing is grandfathered.

Assessments as Projections

An assessment in this design is a lens over continuous state, never a data construction. The team works in the live view; when an assessor needs a stable answer, the workspace seals a snapshot anchored to an exact position in the event log and hashed over the frozen view’s canonical bytes. A seal without a resolvable anchor refuses, because a snapshot that cannot cite its log range is not a snapshot. Both views project from the same log, so a fix made during the assessment window is credited by recompute, not by argument.

Live for the Team. Frozen for the Assessor.

The conventional model forces a choice: freeze the program for the audit, or make the assessor chase a moving target. The projection model dissolves the choice. Working view and sealed view compute from one event log, and the sealed view re-projects byte-identical to its recorded digest, so the frozen answer stays checkable for as long as anyone cares to check it.

Snapshots accumulate as history: a re-baseline seals a fresh view and the prior one stands, citable, beside it. Readiness projections and snapshot digests are the designed inputs to attestation exchange through Alliance, where posture crosses organizational boundaries as proof rather than paperwork. The chain an assessor walks is the chain the system keeps: the infrastructure is the evidence.

Threat Model and Baselines

Start at the threat. In Rampart’s design, threats are first-class entities with their own lifecycle: identified, assessed for likelihood and impact, mapped to defenses, retired. Each defense maps to the controls it satisfies with a declared contribution, primary or supporting, and those contributions feed posture basis directly. Retire a threat and its defense mappings retire with it; a dead threat lends no posture. The compliance surface stays honest about why each control matters here, not just that a framework lists it.

Categorization drives scope. The design carries FIPS-199-shaped confidentiality, integrity, and availability levels with a high-water overall, in the discipline RMF formalizes, and an adopted categorization re-resolves the tailored baseline: the exact control set an organization owes, with recomputes queued for exactly the affected frameworks. Posture and assessment operations against an organization with no resolved baseline refuse outright. Computing compliance against an unstated scope is how programs drift, and the design makes that impossible rather than inadvisable.

The Framework Registry

The registry is exhaustive enumeration, not a category list: the 18 frameworks on the public registry are carried as 25 design rows, nothing folded. CMMC levels are separate rows. NIST 800-171 revisions are separate rows. SOC 2 Type I and Type II are separate rows. Beside them, the 18 overlays resolve to 25 design rows: 22 static overlay rows plus three instance families that resolve to hundreds of artifacts, among them 200+ DISA STIGs, six DISA SRGs, and 26 CIS Benchmarks. Any STIG DISA publishes is supported with zero engine change: content and CCI mappings land as data onto NIST 800-53, and the engine stays the engine.

The registry is treated as an integrity surface, because a poisoned row changes what the engine believes a framework requires. Rows are signed reference data held to the rigor of production security configuration: attributed, diffable, promoted only through a signed pipeline. External catalogs enter untrusted and earn authority. Source change is detected by SHA-256 digest comparison, never by trust in a feed’s say-so, and an ingest that fails verification leaves the prior catalog current: fail-closed to the last good version. Tenant-supplied framework content stays organization-scoped forever. It can inform an organization’s own posture; it can never rewrite the reference data every other tenant relies on.

Change Intelligence

Frameworks rev, and most compliance programs learn what changed from a consultant, months later. The design computes the change instead. When a source publishes a new version, the diff engine counts controls added, changed, and withdrawn, and counts renamed labels separately, so a pure renumbering yields zero control deltas instead of a false alarm. Affected controls, evidence, and per-customer deltas are computed on release day, with migration plans generated from the diff itself; the design holds diff propagation to within 24 hours of ingest.

Release Day, Not Renewal Season

The release-day law in the architecture is blunt: when a framework version lands, every affected organization’s deltas are known the same day. Not at the next assessment. Not when an advisory email goes out. The catalog change propagates through the same recompute machinery as any other event, and zero sustained version lag is the stated target.

Propagation is disciplined. Recomputes queue for every affected organization and control, and only those; a coalescing window collapses the storm after a catalog diff into one pass per organization and framework; documents whose inputs changed are marked stale rather than silently serving yesterday’s truth. This is the gap GRC tools cannot close from the checklist side: a filing cabinet does not know which of your controls a revision touched. A projection engine knows, because the mapping is the data it runs on.

Documents as Computation

A hand-written SSP describes a system as of its last edit; everything after that is drift. In Rampart’s design the SSP is a projection. SSPs, POA&M reports, assessment packages, policies, and per-control narratives are managed document kinds regenerated from living data, each versioned with full history. When posture shifts, a framework diff lands, or a narrative input changes, the affected document is marked stale and queued for regeneration, and a stale document never serves as current: its state stays visible until the regenerated version lands. Even a label-only framework change marks dependent documents stale, so no generated document goes on citing a retired control label as current.

Artificer, the intelligence layer, is designed to assist the drafting, and the charter’s line holds here as everywhere: nothing a model infers counts as evidence until a named human confirms it. What lands in front of an assessor is computed from the same event log that holds the compliance state, with the mapping chain intact from requirement to control to defense to artifact. Not assembled. Projected.

One Defended Implementation

The conventional GRC model treats each framework as a separate program with its own binder, its own evidence set, its own annual cycle. Rampart’s design inverts it: hold authorization as live state computed from real defenses, and render every framework as a projection of one defended implementation. That is the engine a compliance control plane runs on. Proof stops being a project and becomes a property: current because it is computed, trusted because every status carries its basis, cheap because no one assembled it.