Register:Mechanism/Monitor5 recordsSHA3-256 chainedSealed head sha3:e8f3df8547131ce5ba39c5f874d8546b7fa1329e1e9108e358d078212ef7c26cIntact

Register / Mechanism / Monitoring

Monitoring that leaves a record, not a green light.

PolicyCortex monitors your cloud against NIST 800-53, NIST 800-171 and CMMC Level 2, and CIS benchmarks, and writes every observation as evidence: content hashed with SHA3-256, timestamped, appended to the chain in your tenant, retained seven years. The control mapping is stored on the record. A control that stopped being observed produces a declared gap, not a stale green.

Exhibit G-2readiness, five honest states
The PolicyCortex readiness view: every control in one of five states, with permitted automatic fixes flagged per control

Exhibit G-2 · every control in one of five states, with permitted automatic fixes flagged per control. Illustrative demo data; the interface is real.

REC 0000THE OBSERVATIONsha3-256d20f97ae9ea8a2e42a0d092933bc80264b8ba52e78d56935a696050f1daa4e6aprev:7e2b4914b287

One observation, one record.

One record per resource, per capture, whether the capture ran on schedule or a change triggered it. The claim is not a sentence about the resource; it is the raw provider response underneath, hashed. The fields that make an observation file as compliance evidence are these.

resource.id
The full provider path of the resource this record is about: the identifier the cloud API resolves, not a friendly name someone typed into a spreadsheet.
control.mapping
The control statements this state bears on, stored on the record. One encryption setting can evidence NIST 800-171 3.13.16 and 800-53 SC-28 at once, and the mapping is written down, not implied.
asset.scope
The declared boundary the resource sits in: CUI enclave, environment, production class. Scoping arguments get settled by this field instead of by the meeting.
state.proof
The raw cloud API response that grounds the claim, stored verbatim. If a narrative and this payload ever disagree, the payload wins.
content.hash
SHA3-256 digest of the record content. Anyone holding the record can recompute it; a matching digest means unaltered content.
captured.at
UTC timestamp of the capture. Every claim in the evidence base reads as of this field, not as of whenever someone last looked.
Exhibit G-1control rows, as shipped
The PolicyCortex control implementation table: CMMC Level 2 controls by family with implementation status and evidence counts

Exhibit G-1 · the 110-requirement table where observations file, control by control. Illustrative demo data; the interface is real.

See alsoProof of state, the full recordWhere the collectors run

REC 0001DRIFTsha3-256a086572fd780a19a4f4aaaee4d2686add7de6e9a9174068f1b19e1a5d9795d23prev:d20f97ae9ea8

Drift is a finding, not a dashboard color.

Changes made around the system, in the portal, through a direct API call, from a pipeline that never met a gate, surface at the next state capture as drift records with no authority attached. A change with no authority is not a blind spot. It is a finding, and it is recorded as one.

Configuration tampering becomes detectable for the same reason: expected state is on record, so an unexplained delta from the last capture anchors the detection. Every control sits in one of five honest states, and permitted automatic fixes are flagged per control; a fix, when one runs, is approval gated and arrives with its own record.

See alsoProof of change, where drift is recordedProof of agency, how a fix is gated

REC 0002DECLARED GAPSsha3-25645143d6b2e8eb61a5cd2315090e348576c07c4be4cad37e12d5c9d496a808820prev:a086572fd780

What is written when nothing was watching.

A collector down for six hours does not produce six hours of silence. It produces a gap record: which stream, from when to when, why, and when the gap was declared. Evidence with fewer rows and no explanation is indistinguishable from evidence that was trimmed, so the register declares the gap and lets you hold us to it.

declared_gap recordappend-only JSONL, one record per line
{
  "record_type": "declared_gap",
  "stream": "aws.iam.role_state",
  "from": "2026-07-03T09:12:44Z",
  "to": "2026-07-03T15:12:44Z",
  "reason": "collector_unreachable: credential rotation failed, retries exhausted",
  "declared_at": "2026-07-03T15:13:02Z"
}
# hashed and chained like any other record

Why absence is a record and not a smaller number is argued in full in the architecture.

REC 0003FRAMEWORK MAPsha3-2562bc01802ea50adc88444109c44c1a5f1a8d4714b948238743057ced3f03f83b2prev:45143d6b2e8e

Where the observations file.

Monitoring files under continuous monitoring, with the audit family governing how the records themselves are protected. The mapping is quiet on purpose: the record is the product, and the rows below are where monitoring evidence files. The full list of supported frameworks follows them.

NIST 800-53
CA-7 continuous monitoring grounded in point-in-time records, with the AU family covering how those records are protected, retained, and reviewed.
NIST 800-171 / CMMC Level 2
One evidence base for the 110 requirements: state records handed to your assessor as generated evidence with the raw payload attached.
CIS Benchmarks
Benchmark observations written as evidence on the same chain, hashed and timestamped like every other record.
FedRAMP 20x
Machine-readable by construction. State and control mappings export as OSCAL 1.1.2.
MITRE ATT&CK
Configuration tampering becomes detectable because expected state is on record: an unexplained delta from the last capture anchors the detection.

Supported frameworksCMMC Levels 1 to 3NIST SP 800-171 Rev 2/3NIST SP 800-53 Rev 5DFARS 252.204-7012FedRAMP Low, Moderate, HighFISMAITAR/EARHIPAASOXPCI DSSCIS Benchmarks for AWS, Azure, and GCPSOC 2 Type IINIST AI RMFMITRE ATT&CK and ATLAS

See alsoThe federal recordHow the record becomes a package

REC 0004STATED LIMITsha3-256e8f3df8547131ce5ba39c5f874d8546b7fa1329e1e9108e358d078212ef7c26cprev:2bc01802ea50

What this layer does not do.

See your controls as records, not as a score.

Request verification
Register colophonRecomputable by a second party
SeqLabelSHA3-256Prev
REC 0000THE OBSERVATIONd20f97ae9ea87e2b4914b287
REC 0001DRIFTa086572fd780d20f97ae9ea8
REC 0002DECLARED GAPS45143d6b2e8ea086572fd780
REC 0003FRAMEWORK MAP2bc01802ea5045143d6b2e8e
REC 0004STATED LIMITe8f3df8547132bc01802ea50

The record headers on this page are SHA3-256 digests of this page's own copy, chained in sequence from a fixed genesis value. Edit one word of any record's copy above and every digest after it changes. Head of chain: sha3:e8f3df854713. The product does the same thing to your evidence.

Photograph: U.S. Department of Energy, Public domain (U.S. Department of Energy, 17 U.S.C. 105). Source