Measured on Real Authorizations
Source: Puyenpa operational records, n=14 systems across DoD and Federal engagements, 2021–2025. Manual baseline vs. full automation. Results vary by system and environment.
Decision AuthorityBuilt on Sentinel’s Nine Hardened Layers
ARIA runs as a governed workload on the Sentinel AI Control Plane. Every model is registered and versioned, every artifact carries lineage, and every AI recommendation — and every human override — is logged for audit.
Authorize at the Speed of the Mission
Authorization boundaries are growing faster than assessment teams can absorb. ARIA takes on the highest-volume RMF work — evidence collection, checklist reconciliation, eMASS entry, POA&M upkeep — and returns assessor time to judgment.
Control Template Engine
720 baseline controls pre-mapped to implementation statements, test objectives and expected artifacts, with inheritance, overlays and Rev 4 → Rev 5 migration.
Multi-Scanner Intelligence
One normalized view across Evaluate-STIG, OpenSCAP / Red Hat Satellite and DISA SCC, with AI-maintained Answer Files that shrink the manual-check backlog every quarter.
AI Assessment Engine
IBM watsonx-powered artifact analysis, control satisfaction scoring with cited evidence, CAT I/II/III classification and SCAR-ready narratives.
Human Decision Authority
Decision support, never decision making. Assessors validate every score and the AO alone accepts risk — enforced in the platform and logged for audit.
Every RMF Step, Automated
- Step 0PrepareRole mapping, inventory sync, pre-populated SSP templates
- Step 1CategorizeFIPS 199 / CNSSI 1253 impact suggestions, boundary diagrams
- Step 2SelectBaseline selection, tailoring, overlays, inheritance mapping
- Step 3ImplementSSP generation, STIG evidence collection, CI/CD security gates
- Step 4AssessParallel AI artifact analysis, finding classification, SCAR output
- Step 5AuthorizeRisk posture dashboard, draft risk narrative, AO decision package
- Step 6MonitorContinuous scan feeds, drift alerts, live POA&M tracking
Scan. Harden. Prove.
ARIA works with the scanners and automation already on your network — no forklift replacement — and turns every remediation into authorization evidence.
Ingest
Evaluate-STIG checklists, OpenSCAP results from Red Hat Satellite, DISA SCC XCCDF and Nessus output, linked to one system record.
Resolve
Normalization across tools, format bridging for STIG Viewer and STIG Manager, and Answer File intelligence for recurring manual checks.
Remediate
DISA Cyber.mil Ansible and Chef playbooks matched to each finding, executed through Satellite, Ansible or device APIs behind approval gates.
Prove
Remediation evidence attached automatically, POA&M closure queued for ISSO confirmation, and eMASS-ready packages.
ACAS / Tenable Security Center connector and IAVA lifecycle tracking under DoDI 8531.01; STIG Manager and C-PAT API integration.
The AI Recommends. People Decide.
| Decision | ARIA | Human Authority |
|---|---|---|
| Control satisfaction | Scores Pass / Partial / Fail with confidence and cited evidence | SCA validates or overrides |
| Finding severity | Proposes CAT I / II / III classification | SCA confirms; CAT I requires written sign-off |
| Remediation | Matches playbooks and stages execution | Approval gate before any change; ISSO confirms POA&M closure |
| Authorization | Assembles the decision package and draft risk narrative | AO decides and signs — non-delegable |
Built-In ISSO/ISSM Approval
Every AI-drafted POA&M is reviewed and approved by a named person before it reaches C-PAT or eMASS — never auto-published. Locked scanner data sits beside editable narrative fields, and approval seals a cryptographic fingerprint of the exact content that was approved.


Where ARIA Stands
Built With
IBM
watsonx and watsonx Orchestrate for AI analysis, search and agent orchestration; QRadar for continuous monitoring telemetry.
Dragos
ICS/OT asset visibility and NIST SP 800-82 mapping, so OT and kinetic systems move through the same RMF workflow as IT.