Ratify: Policy Assessment Engine (Sample Output)

Access Control Family Assessment

Select an Access Control control and review the system context to see recorded sample output from a Ratify assessment: gap analysis, SSP narrative draft, and POA&M triage.

Select Control
System Implementation Context
The system is a classified C2 (Command and Control) application hosted on a hardened RHEL 9 server within a SCIF at a DoD facility. It uses Active Directory for identity management, PKI/CAC authentication, and role-based access controls managed through a custom authorization service. The system has 45 authorized users across 4 role types. Remote access is provided via an Aruba VPN concentrator with MFA enforcement. The system connects to SIPRNet and processes data up to SECRET//NOFORN.
Sample system context for demonstration. In production, Ratify assesses against your own system documentation and exported records.
RATIFY ASSESSMENT ENGINE
CONFIDENCE
HOW THIS WORKS IN PRODUCTION

This page shows recorded sample output. In production, Ratify runs on a single workstation inside your enclave with a local open-weight model and no external network egress, verified on every run. It assesses your control set continuously on the schedule you set, cites the evidence behind every finding, and the operator, not the software, makes the decision.