Scope, Users, Systems, and Integration
Tracepoint · A&R Strategic Solutions Version 1.0 · August 2026
This document states exactly what Tracepoint covers, who operates it, what it exchanges data with, and what it deliberately does not do.
What Tracepoint is for
Tracepoint supports the remediation work that follows a financial statement audit. The specific work in scope:
- Notice of Findings and Recommendations remediation. Taking an auditor finding through root cause, corrective action plan, milestones, evidence, and closure.
- Corrective action plan management. Planning, owning, advancing, and closing CAPs, including reject and reopen.
- Sustainment testing. Demonstrating that a corrective action held over subsequent periods, with an enforced separation between the person who performed a test and the person who reviewed it.
- Reconciliation and balance support. Recording how a reported balance ties to the records beneath it, rung by rung, and what portion of a difference remains unexplained.
- Population provenance. Recording how a data population was extracted, by what method, with what control totals, so that completeness becomes a stated claim rather than an assumption.
- Evidence assembly and handoff. Producing a package a reviewer can open and evaluate without access to the originating system.
Not in scope. Tracepoint is not an accounting system, a general ledger, a financial reporting system, or a sampling engine. It does not perform audit testing, does not compute materiality, and does not issue opinions. It does not decide whether evidence is sufficient, and it does not close an auditor finding, only an auditor does that.
Regulatory and policy context
Tracepoint is built to support work performed under:
- FIAR Guidance, the Financial Improvement and Audit Remediation guidance issued by the Office of the Under Secretary of Defense (Comptroller), which frames corrective action planning and remediation.
- OMB Circular A-123, management's responsibility for internal control, including Appendix A on internal control over reporting.
- DoD Financial Management Regulation, accounting and reporting policy, and the supporting-documentation expectations that drive evidence retention.
- FISCAM, the framework auditors apply to information system controls, which is what many findings implicate.
- FAR 2.101, the definition of a signature, which is why Tracepoint says "attested" and not "signed."
The product ships reference packs derived from FMR, FISCAM, and A-123 material. These drive the deterministic control linker, which proposes a control a finding may implicate. A proposal is never applied automatically; a person confirms or rejects it, and the confirmation is what lands on the record.
Who uses it
Six roles, each with a defined set of permitted actions:
| Role | Typical title | What the role can do |
|---|---|---|
| Remediation lead | Audit remediation manager, FIAR lead | Everything: confirm links, create and transition CAPs, attach evidence, approve requests |
| CAP owner | Process owner, functional lead | Create and advance the CAPs they own, attach evidence, complete milestones |
| Evidence custodian | Records or documentation specialist | Attach and manage evidence items |
| Reviewer | Internal review, independent reviewer | Confirm, approve, review sustainment cycles |
| Leadership read-only | Comptroller, deputy, senior leadership | View everything, change nothing |
| External liaison | Audit liaison, auditor point of contact | Manage requests and responses |
Role separation is enforced in the guarded action layer: an action attempted by a role that is not permitted is refused, with the reason stated. One rule goes further and is enforced in the data itself, a sustainment cycle whose reviewer is the same person as its preparer is rejected outright, because a self-reviewed cycle is not independent.
Role separation is a workflow control: it governs what the application will do for a given profile, and the trail records which profile did it. The threat model states the boundary in full.
Data coming in
Tracepoint imports findings registers in the formats organizations actually have:
- CSV exported from a findings database, tracker, or spreadsheet.
- Excel workbooks (.xlsx), read directly, including the worksheet name.
- Word documents (.docx) containing a findings table.
Seventeen fields are recognised, and they are kept distinct rather than collapsed: source finding identifier, title, condition, criteria, cause, effect, auditor recommendation, management response, management corrective action, component, fiscal year issued, first year identified, finding classification, status, issuing auditor, report number, and issued date. An auditor's recommendation and management's response are different statements by different parties, and the product never merges them.
Nothing is created from an import until a person confirms it. The import preview shows what will be created, what will be defaulted, what will be refused, and why. The source file's SHA-256 is recorded, and every created finding keeps its original source row and every conversion applied to it.
Hard cases, and what happens
| Case | What Tracepoint does |
|---|---|
| Duplicate source identifier already in the workspace | Flags the row, names the existing finding it matches, offers to skip it |
| Duplicate source identifier repeated inside the same file | Flags the row and names the earlier row it repeats, the workspace check cannot catch these, because nothing has been created yet |
| Conflicting values for the same finding | Not merged and not resolved automatically. Both rows are presented; the person decides. Tracepoint has no basis for choosing between two conflicting statements of fact and does not pretend to |
| Missing fiscal year | Left blank and flagged as not provided. Never inferred, never filled with the current year, and never displayed as though it were real |
| Unrecognised classification | A default is applied and the record says it was defaulted, along with the original value the file contained |
| Missing title but a condition present | A title is derived from the condition and marked as derived |
| No title and no condition | The row is refused and the reason is recorded. There is not enough there to constitute a finding |
| Incomplete records generally | Imported with the gaps visible. Tracepoint's position is that a disclosed gap is more useful to a reviewer than a filled one |
Data going out
Every export is a file on the user's machine. There is no transmission.
The Full Export Package is a single ZIP containing 45 artifacts, organised into folders: cover and summary, records, evidence with embedded bytes, human-readable reports, activity history with full import provenance, the TraceSeal integrity manifest, interoperability exports, the schema, a records handoff section, known limitations, and a validation gate result.
Interoperability exports, also available individually:
| Export | Format | Purpose |
|---|---|---|
| OSCAL POA&M | JSON | The NIST open standard for plans of action and milestones |
| eMASS POA&M | CSV | The 21 columns of the eMASS RMF POA&M import template, in template order |
| ODCFO corrective action plan | CSV | Corrective action reporting layout |
| Canonical workspace | JSON | The complete workspace in open, documented form |
| Reviewer Package | Single HTML file | A self-contained, inert artifact a reviewer can open with nothing installed |
About the eMASS export specifically
The export emits all 21 columns of the eMASS RMF POA&M import template, in template order, using the template's exact header text. eMASS rejects a workbook whose columns have been added, removed, or reordered, so that column list is treated as a contract in the code and carries a comment saying so.
Three things about it are worth stating plainly.
The POA&M Item ID column is deliberately empty. eMASS generates that identifier when a row imports successfully. Writing our own identifier into it would be wrong, so the Tracepoint CAP identifier travels in the Comments column instead, where it stays traceable in both directions.
Eleven columns are deliberately empty, and the package says which. Security Checks, Milestone Changes, Mitigations, Recommendations, and the RMF risk-analysis columns, Raw Severity, Severity, Relevance of Threat, Likelihood, Impact, Impact Description, and Residual Risk Level, are left blank. The risk columns matter most here. A financial statement finding classification and an RMF risk rating are different assessments made by different people for different purposes, and mapping one onto the other would manufacture an analysis nobody performed. The export refuses to do it and reports what it left empty, so the receiving analyst completes those fields in eMASS where they belong.
Bulk import into eMASS is an Excel workbook, not CSV. The documented bulk path uses the .xlsm template through the POA&M Import page; the eMASS REST API is a separate, fully public interface with a different field set and no Excel path, and it requires a PKI client certificate. Tracepoint produces the column set as CSV, which opens directly in the template and is the portable form. An organization should confirm the current column set against its own eMASS instance before relying on it in production, because we have no live instance to test against and the template has been revised before.
The ODCFO export follows the corrective action plan reporting layout and carries the same caution. Warnings raised while generating any of these travel inside the package rather than being dropped. The OSCAL export follows a published open standard and is the most portable of the three.
What Tracepoint does not integrate with
Deliberately, and this is a design position rather than a missing feature.
Tracepoint makes no live connection to any system. There is no API client, no database connector, no single sign-on, no scheduled sync, and no network traffic of any kind. It does not read from a general ledger, does not write to eMASS, and does not push to a findings database.
Data moves the way data moves in this environment already: a person exports a file from the system of record and imports it, and exports a package and files it back. That keeps the product outside every authorization boundary it would otherwise have to cross, which is the difference between deploying in weeks and deploying in quarters.
If an organization later wants a direct connection, that is a different product decision with a different security posture, and we would say so rather than quietly adding it.
Classification
Tracepoint is for unclassified information only.
It does not classify, mark, sanitise, or scan content. Every package it produces is stamped "UNMARKED, apply your organisation's handling marking before distribution." It is not a cross-domain solution and must not be used as one.
What the architecture does contribute is that nothing is transmitted. A package moves only when a person moves it, so the existing marking and handling procedures apply at the same point they always have. An organization that needs to work at a higher classification runs the application on a system already accredited for that level, under its own rules, and the product's lack of network behaviour makes that simpler rather than harder.
Records management
Tracepoint is a working tool that produces artifacts for the systems of record. It is not itself the official agency repository unless an organization formally designates it as one, and its export packages include a records handoff section for that purpose.
Retention, disposition, and recordkeeping remain the organization's, under its own schedule. The workspace is a single file that backs up like any other document.
Deployment
What a workstation needs: a current browser. That is the entire requirement. There is no installer, no runtime, no service, no database, and no administrative rights needed to run it.
What the organization provides: a location for the workspace file with its normal backup and access controls, and its own decision about permitting the software.
On authorization. Tracepoint does not hold an ATO and we do not claim otherwise. It is a set of client-side files that run in a browser with no server component, no listening port, no external connection, and no data leaving the machine. That is a materially smaller assessment than a hosted system, and the published integrity manifest lets an organization verify exactly which files it received. It is not zero, and any organization should apply its own software approval process.
Offline. The application runs identically with the network disabled. This is not a degraded mode; it is the normal mode, and it is verified by running it that way.