Tracepoint

P.00 Product

One workspace for the part of remediation that nobody's system of record covers.

The NFR Database holds the plan and eMASS holds the POA&M. Tracepoint is where the evidence behind a closure is assembled, attested, and packaged before it goes there.

Formats inCSV, Excel, Word, Nessus, CKL, CKLB, XCCDF, ARFRead with their structure intact
Formats outOSCAL, eMASS, ODCFO, Reviewer PackageChecked against the template before they save
RolesSix, each with permitted actionsA refused action states its reason
NetworkNo network calls, by designNo server, no account, no telemetry
The Deliver surface: the Full Export Package, the Reviewer Package, and the interoperability exports, each with its status
Fig 01 Deliver, exports, with the worked example loaded Synthetic data

P.01 In and out

Fifteen doors in. Eleven artifacts out. One workspace between them.

What comes in and what goes out 15 input formats converge on one workspace, and 11 exports leave it, one of them the TraceSeal manifest. In Out Findings list: CSV, Excel, Word ODCFO CAP tracker eMASS POA&M Scanner file: .nessus, .ckl, .cklb, .xml Property book Count file DD Form 577 appointment register DA Form 2062 hand receipts Demand history and purchase log Auditor's sample selection Component listing and shortage annex Balance population: FBWT listing PBC request list Full Export Package, restore Workspace file OSCAL POA&M eMASS POA&M CSV ODCFO CAP tracker CSV Full Export Package Reviewer Package Closure Package Submission print package Outcome Ledger Business case Workspace file TraceSeal root digest Workspace
Fig 00 Drawn from the product's own import and export lists Every name is a real format

P.02 What comes in

The formats organizations actually have, read with their structure intact.

The first screen asks what you received and offers three doors: Bring in files, Practice with a small example, or Practice with the full example. Nothing is created from any of them until a person confirms the preview.

Findings lists

CSV, Excel workbooks read directly with the worksheet name, Word documents containing a findings table, the ODCFO CAP tracker, and the eMASS POA&M export, which both round-trip. More than fifty fields are recognised, among them identifier, title, condition, criteria, cause, effect, auditor recommendation, management response, corrective action, component, fiscal years, classification, status, issuing auditor, report number, and issued date.

Scanner files

.nessus from ACAS, STIG checklists in .ckl and .cklb, and XCCDF results in .xml including an ARF wrapper. A rescan sorts into four buckets: new, unchanged, reappeared, absent. Absent proposes a closure and never performs one.

Property records

GCSS-Army property books, count files, DD Form 577 appointment registers, DA Form 2062 hand receipts, demand history, purchase logs, the auditor's sample selection, component listings, and shortage annexes, each through its own door, for the quarterly floor-to-book sample under AR 710-4. Property is an evidence layer inside the same product rather than a counting application.

Every file, read by its bytes first

Every file is read by its byte signature before its name: a workbook named .csv is read as a workbook, and Office binaries, PDFs, archives, and other non-text files are refused with the reason. A bad row is refused, never the whole file, and every refused row is listed with a CSV download and recorded on the trail.

Balances and requests

A financial population file, such as an FBWT transaction listing in xlsx or csv, comes in with a support walk and leaves as a population-support package. A PBC request list becomes requests with a response walk and leaves as a PBC response package.

Workspace files, packages, and checkpoints

The complete workspace in open, documented JSON. The product's own Full Export Package re-imports and restores a workspace, checked against its TraceSeal manifest. Named checkpoints in the browser's own storage, and a blocking checkpoint before every one of the twelve irreversible actions.

The import preview: counts of rows to create, default, and refuse, with the file's SHA-256
Fig 02 Workspace, import preview FY2026 NFR register, xlsx SHA-256 7f945ec6c076… Synthetic data

P.03 What happens to it

Four mechanisms, each one leaving a row on the trail.

01Link

Deterministic control linking

A rule-based linker proposes the control a finding implicates from reference packs derived from the FMR, FISCAM, and A-123 material. It is a lexicon rather than a model. It proposes, a named person confirms, and the confirmation is the record. The same file produces the same proposals every time.

A finding with its proposed control link
Fig 03 Case record fnd_appr0001 Proposed control link, unconfirmed Synthetic data
02Act

A role-guarded corrective action lifecycle

Root cause, plan, milestones, evidence, review, closure, sustainment, reject, reopen. Six roles, each with a defined set of permitted actions. An action a role is not permitted to take is refused with the reason stated. A sustainment cycle whose reviewer is its own preparer is rejected outright.

A closed corrective action with its root cause, its state, and its closure package
Fig 04 Corrective action cap_wk000001, monthly bank reconciliations Closed, with its root cause and closure package Synthetic data
03Prove

Challenges, sustainment tests, risk acceptances, repeat findings

A closed finding has to stay closed. Sustainment cycles test that the fix held. Risk acceptances carry an expiry and lapse visibly. Repeat findings are counted, because a reduction in repeats is the measure the Department is being taught to ask for.

The Prove group: challenges, sustainment tests, risk acceptances, and repeat findings
Fig 05 Prove, sustainment Cycles passed against the policy requirement Synthetic data
04Reconcile

Balances tied to their support

A five-rung ladder from source records to the reported total. A difference that is not explained is displayed as unexplained. Nothing is ever forced to zero to make a screen look finished, and the Explain it button opens the form that records a reconciling item under your name and writes it to the trail.

The reconciliation ladder from source records to the reported balance, with an unexplained difference shown as unexplained
Fig 06 Balances, checking account Unexplained difference shown as unexplained Synthetic data

P.04 What goes out

Every export is a file on the user's machine.

There is no transmission. Exports are checked against the government's own formats before they are allowed to save.

ExportFormatWhat it is for
Full Export PackageZIPRecords, embedded evidence bytes, reports, the activity history with import provenance, the TraceSeal manifest, every interoperability file, the schema, and the stated limitations. The same workspace produces the same package on the same day on a device in the same time zone.
Reviewer PackageSingle HTML fileAn inert, self-contained artifact a reviewer opens with nothing installed and no account
OSCAL POA&MJSONThe NIST open standard, validated against the schema before it saves
eMASS POA&MCSV, 21 columnsThe eMASS RMF POA&M import template, in template order with exact header text; columns that must not be derived are left empty and disclosed
ODCFO corrective action planCSVCorrective action reporting layout
Closure PackageHTML, per corrective actionThe evidence behind one closure, in one file
Submission print packageHTMLThe human-readable submission, with its limitations on its face
Outcome LedgerFileEvery outcome the workspace recorded, in order
Business caseFileThe case for the deployment, with published comparables
Canonical workspaceJSONThe complete workspace in open, documented form
The exports page
Fig 07 Deliver, exports Synthetic data

A staleness indicator shows when a package no longer matches the workspace it came from. It discloses and never blocks. Changes since last export are listed by record.

The activity trail: every action with its person, role, statement, and time
Fig 08 Activity trail, newest first Synthetic data

P.05 The trail

The trail underneath all of it.

Every guarded action appends a row with the person, the role, the statement they made, and the time on their clock. Rows are never edited. Evidence is hashed with SHA-256 the moment it arrives. The TraceSeal manifest fixes the records, the trail in order, and the evidence digests under one root digest, and prints the canonicalization rules so anyone can recompute it.

The words are exact on purpose. The product says attested rather than signed, and append-only rather than immutable. The seal is a fixed point rather than an authentication: it shows whether bytes changed, and it cannot show who wrote them or when. Making it evidence of authorship means signing the manifest with the agency's own PKI, outside this application, and the manifest says so on its face.

What the seal covers and what it does not

P.06 What sets it apart

It discloses, and it never decides.

Five behaviours that hold across every screen and every package.

It discloses and never decides

When a file cannot be read, a count cannot be recorded, or a difference is unexplained, the product says exactly why and where the item belongs. Nothing is blocked silently and nothing is quietly adjusted.

It shows where the support stops

A balance is reconciled step by step toward the reported amount, and the record states what tied, what did not, and what remains unexplained, with the evidence for each step.

It reads the government's own files and writes them back

The ODCFO CAP tracker, the eMASS POA&M, scanner files in .nessus, .ckl, .cklb, and .xml, GCSS-Army property books, DD Form 577 appointment registers, and DA Form 2062 hand receipts import as they arrive. An ODCFO tracker exported and re-imported reports zero differences, and a scan re-imported reconciles as unchanged.

The property module enforces the regulation by paragraph

AR 710-4's bars on who may count, who may sample, and consecutive-period inventories are enforced when the workspace knows the people involved, and disclosed on the trail when it does not. Sensitive lines past their inventory cadence, monthly for weapons under 16-24b and quarterly for other sensitive items under 16-23a, are raised as observations, and the cadence can be set in the property policy.

Everything is reproducible

The same workspace produces the same package on the same day on a device in the same time zone, and the Deliver page says so on its face. 2,213 automated checks run before every commit, and the date handling is exercised in four time zones.

P.07 Requirements

What a workstation needs.

A current browser

That is the entire requirement, on Windows, macOS, or Linux. No installer, no runtime, no service, no database, and no administrator rights. It does not run on a machine with no browser.

A place for the workspace file

With the organization's normal backup and access controls. Evidence bytes travel inside the workspace file, so the file is the record.

Your own software approval

Tracepoint runs under your organization's own software approval. It is client-side files with no server, no listening port, and no external connection, which makes the assessment small, and the published integrity manifest makes it precise.

P.08 Next step

Every behaviour on this page can be exercised in the demo.

Load the worked example, take a finding through to closure, and read the package it produces.