Skip to main content

Continuous ATO — maintaining posture vs. point-in-time audits

ExplanationPublic

The problem this solves

Traditional ATO is a point-in-time event: demonstrate compliance at a moment, get the authorization, and the authorization decays as the system changes. Between audits, drift accumulates. Catching up before the next audit is a project.

Continuous ATO means the platform is always in an auditable state — not by doing more audit prep, but by continuously enforcing the controls that audits check.

How Platform Custodian maintains posture

Platform Custodian is SmoothGlue's automated remediation engine. It runs continuously and:

  1. Scans for drift — compares current platform state against the compliance baseline (FIPS settings, STIG Kyverno policies, network policies, certificate expiry, secret rotation schedules)
  2. Remediates automatically — if a control drifts, Platform Custodian corrects it without operator intervention (re-applies a drifted Kyverno policy, rotates an expiring certificate)
  3. Escalates what it cannot fix — findings requiring human decision surface as alerts in the Console and Ground Control dashboards

What this means for your ATO package

Instead of point-in-time screenshots, you can provide continuous compliance evidence: time-series data from Loki showing that controls were active and enforced over the full authorization period, not just on audit day.

Platform Custodian logs every scan and remediation action. Queryable via Grafana in Ground Control.

What SmoothGlue handles for you

  • Continuous scanning against the compliance baseline
  • Automated remediation of drift
  • Compliance evidence export for ATO packages (Console → Compliance Reports)

What you still own

  • Reviewing and accepting residual risk
  • Findings that require human decision (Platform Custodian escalates these)
  • Agency-specific overlays not covered by the SmoothGlue baseline

Learn more