Symmetry Guard
Governance, Risk & Compliance
Audit readiness as a standing condition, not an annual emergency.
The problem
Evidence lives in inboxes and shared drives. Six weeks before the audit, the fire drill starts: what do we have, what has expired, who owns the gap.
What you get
- Compliance frameworks with hierarchical controls, including JSON catalog import and a ready-to-import NIST SP 800-171 structure
- Program profiles: apply a framework to a program, tailor scope per control, and record implementations in SSP vocabulary (implemented, partially implemented, planned, not applicable) with narratives and owners
- First-class evidence: attachments with expiry dates and retention rules, so “current” is computed, not assumed
- A per-program audit-readiness dashboard: implementation status, evidence currency, expiring items, ownership
- Risk registry with a clickable 5×5 heatmap, aging report, escalation flags, and review cadence
- Gates: named checkpoints where submitted items must be validated by someone other than the submitter, and the gate is green only when everything is
- Assessments with findings that convert to POA&M items in one click, with owners, due dates, and burndown derived from the audit trail
- Exports: SSP-style PDF, POA&M CSV and PDF, readiness reports, all with print views
- Auditor access through roles, not workarounds: read-only on profiles and assessments, no access elsewhere
Connected by design
Guard’s gates block Horizon milestones outright. Its policies point to controlled documents in Playbook. Its compliance posture feeds supplier scorecards in Gauge and the executive dashboard in Insight. Compliance training links to Edge.
Proof point
Separation of duties and the append-only audit trail are enforced by the platform, not by policy. In the demo, try to approve your own submission or edit the history. You cannot, and we will show you why.
See it on your program
See the readiness dashboard catch an expired control on realistic program data.