Tracepoint

Documents

Scope, Users, Systems, and Integration

Tracepoint · A&R Strategic Solutions Version 1.0 · August 2026

This document states exactly what Tracepoint covers, who operates it, what it exchanges data with, and what it deliberately does not do.


What Tracepoint is for

Tracepoint supports the remediation work that follows a financial statement audit. The specific work in scope:

Not in scope. Tracepoint is not an accounting system, a general ledger, a financial reporting system, or a sampling engine. It does not perform audit testing, does not compute materiality, and does not issue opinions. It does not decide whether evidence is sufficient, and it does not close an auditor finding, only an auditor does that.


Regulatory and policy context

Tracepoint is built to support work performed under:

The product ships reference packs derived from FMR, FISCAM, and A-123 material. These drive the deterministic control linker, which proposes a control a finding may implicate. A proposal is never applied automatically; a person confirms or rejects it, and the confirmation is what lands on the record.


Who uses it

Six roles, each with a defined set of permitted actions:

RoleTypical titleWhat the role can do
Remediation leadAudit remediation manager, FIAR leadEverything: confirm links, create and transition CAPs, attach evidence, approve requests
CAP ownerProcess owner, functional leadCreate and advance the CAPs they own, attach evidence, complete milestones
Evidence custodianRecords or documentation specialistAttach and manage evidence items
ReviewerInternal review, independent reviewerConfirm, approve, review sustainment cycles
Leadership read-onlyComptroller, deputy, senior leadershipView everything, change nothing
External liaisonAudit liaison, auditor point of contactManage requests and responses

Role separation is enforced in the guarded action layer: an action attempted by a role that is not permitted is refused, with the reason stated. One rule goes further and is enforced in the data itself, a sustainment cycle whose reviewer is the same person as its preparer is rejected outright, because a self-reviewed cycle is not independent.

Role separation is a workflow control: it governs what the application will do for a given profile, and the trail records which profile did it. The threat model states the boundary in full.


Data coming in

Tracepoint imports findings registers in the formats organizations actually have:

Seventeen fields are recognised, and they are kept distinct rather than collapsed: source finding identifier, title, condition, criteria, cause, effect, auditor recommendation, management response, management corrective action, component, fiscal year issued, first year identified, finding classification, status, issuing auditor, report number, and issued date. An auditor's recommendation and management's response are different statements by different parties, and the product never merges them.

Nothing is created from an import until a person confirms it. The import preview shows what will be created, what will be defaulted, what will be refused, and why. The source file's SHA-256 is recorded, and every created finding keeps its original source row and every conversion applied to it.

Hard cases, and what happens

CaseWhat Tracepoint does
Duplicate source identifier already in the workspaceFlags the row, names the existing finding it matches, offers to skip it
Duplicate source identifier repeated inside the same fileFlags the row and names the earlier row it repeats, the workspace check cannot catch these, because nothing has been created yet
Conflicting values for the same findingNot merged and not resolved automatically. Both rows are presented; the person decides. Tracepoint has no basis for choosing between two conflicting statements of fact and does not pretend to
Missing fiscal yearLeft blank and flagged as not provided. Never inferred, never filled with the current year, and never displayed as though it were real
Unrecognised classificationA default is applied and the record says it was defaulted, along with the original value the file contained
Missing title but a condition presentA title is derived from the condition and marked as derived
No title and no conditionThe row is refused and the reason is recorded. There is not enough there to constitute a finding
Incomplete records generallyImported with the gaps visible. Tracepoint's position is that a disclosed gap is more useful to a reviewer than a filled one

Data going out

Every export is a file on the user's machine. There is no transmission.

The Full Export Package is a single ZIP containing 45 artifacts, organised into folders: cover and summary, records, evidence with embedded bytes, human-readable reports, activity history with full import provenance, the TraceSeal integrity manifest, interoperability exports, the schema, a records handoff section, known limitations, and a validation gate result.

Interoperability exports, also available individually:

ExportFormatPurpose
OSCAL POA&MJSONThe NIST open standard for plans of action and milestones
eMASS POA&MCSVThe 21 columns of the eMASS RMF POA&M import template, in template order
ODCFO corrective action planCSVCorrective action reporting layout
Canonical workspaceJSONThe complete workspace in open, documented form
Reviewer PackageSingle HTML fileA self-contained, inert artifact a reviewer can open with nothing installed

About the eMASS export specifically

The export emits all 21 columns of the eMASS RMF POA&M import template, in template order, using the template's exact header text. eMASS rejects a workbook whose columns have been added, removed, or reordered, so that column list is treated as a contract in the code and carries a comment saying so.

Three things about it are worth stating plainly.

The POA&M Item ID column is deliberately empty. eMASS generates that identifier when a row imports successfully. Writing our own identifier into it would be wrong, so the Tracepoint CAP identifier travels in the Comments column instead, where it stays traceable in both directions.

Eleven columns are deliberately empty, and the package says which. Security Checks, Milestone Changes, Mitigations, Recommendations, and the RMF risk-analysis columns, Raw Severity, Severity, Relevance of Threat, Likelihood, Impact, Impact Description, and Residual Risk Level, are left blank. The risk columns matter most here. A financial statement finding classification and an RMF risk rating are different assessments made by different people for different purposes, and mapping one onto the other would manufacture an analysis nobody performed. The export refuses to do it and reports what it left empty, so the receiving analyst completes those fields in eMASS where they belong.

Bulk import into eMASS is an Excel workbook, not CSV. The documented bulk path uses the .xlsm template through the POA&M Import page; the eMASS REST API is a separate, fully public interface with a different field set and no Excel path, and it requires a PKI client certificate. Tracepoint produces the column set as CSV, which opens directly in the template and is the portable form. An organization should confirm the current column set against its own eMASS instance before relying on it in production, because we have no live instance to test against and the template has been revised before.

The ODCFO export follows the corrective action plan reporting layout and carries the same caution. Warnings raised while generating any of these travel inside the package rather than being dropped. The OSCAL export follows a published open standard and is the most portable of the three.


What Tracepoint does not integrate with

Deliberately, and this is a design position rather than a missing feature.

Tracepoint makes no live connection to any system. There is no API client, no database connector, no single sign-on, no scheduled sync, and no network traffic of any kind. It does not read from a general ledger, does not write to eMASS, and does not push to a findings database.

Data moves the way data moves in this environment already: a person exports a file from the system of record and imports it, and exports a package and files it back. That keeps the product outside every authorization boundary it would otherwise have to cross, which is the difference between deploying in weeks and deploying in quarters.

If an organization later wants a direct connection, that is a different product decision with a different security posture, and we would say so rather than quietly adding it.


Classification

Tracepoint is for unclassified information only.

It does not classify, mark, sanitise, or scan content. Every package it produces is stamped "UNMARKED, apply your organisation's handling marking before distribution." It is not a cross-domain solution and must not be used as one.

What the architecture does contribute is that nothing is transmitted. A package moves only when a person moves it, so the existing marking and handling procedures apply at the same point they always have. An organization that needs to work at a higher classification runs the application on a system already accredited for that level, under its own rules, and the product's lack of network behaviour makes that simpler rather than harder.


Records management

Tracepoint is a working tool that produces artifacts for the systems of record. It is not itself the official agency repository unless an organization formally designates it as one, and its export packages include a records handoff section for that purpose.

Retention, disposition, and recordkeeping remain the organization's, under its own schedule. The workspace is a single file that backs up like any other document.


Deployment

What a workstation needs: a current browser. That is the entire requirement. There is no installer, no runtime, no service, no database, and no administrative rights needed to run it.

What the organization provides: a location for the workspace file with its normal backup and access controls, and its own decision about permitting the software.

On authorization. Tracepoint does not hold an ATO and we do not claim otherwise. It is a set of client-side files that run in a browser with no server component, no listening port, no external connection, and no data leaving the machine. That is a materially smaller assessment than a hosted system, and the published integrity manifest lets an organization verify exactly which files it received. It is not zero, and any organization should apply its own software approval process.

Offline. The application runs identically with the network disabled. This is not a degraded mode; it is the normal mode, and it is verified by running it that way.