Continuous ATO — maintaining posture vs. point-in-time audits
The problem this solves
Traditional ATO is a point-in-time event: demonstrate compliance at a moment, get the authorization, and the authorization decays as the system changes. Between audits, drift accumulates. Catching up before the next audit is a project.
Continuous ATO means the platform is always in an auditable state — not by doing more audit prep, but by continuously enforcing the controls that audits check.
How Platform Custodian maintains posture
Platform Custodian is SmoothGlue's automated remediation engine. It runs continuously and:
- Scans for drift — compares current platform state against the compliance baseline (FIPS settings, STIG Kyverno policies, network policies, certificate expiry, secret rotation schedules)
- Remediates automatically — if a control drifts, Platform Custodian corrects it without operator intervention (re-applies a drifted Kyverno policy, rotates an expiring certificate)
- Escalates what it cannot fix — findings requiring human decision surface as alerts in the Console and Ground Control dashboards
What this means for your ATO package
Instead of point-in-time screenshots, you can provide continuous compliance evidence: time-series data from Loki showing that controls were active and enforced over the full authorization period, not just on audit day.
Platform Custodian logs every scan and remediation action. Queryable via Grafana in Ground Control.
What SmoothGlue handles for you
- Continuous scanning against the compliance baseline
- Automated remediation of drift
- Compliance evidence export for ATO packages (Console → Compliance Reports)
What you still own
- Reviewing and accepting residual risk
- Findings that require human decision (Platform Custodian escalates these)
- Agency-specific overlays not covered by the SmoothGlue baseline