Changelog
What's shipping in Affirmark.
A reverse-chronological log of capability changes — what's new, what changed, what's now defensible to your assessor. Month-level cadence, customer-language entries; the commit history lives on GitHub for anyone who wants it.
-
April 2026
Continuous control monitoring
Affirmark now pulls evidence directly from your existing tooling — IdP exports, EDR attestations, vulnerability scans, configuration drift — so drift surfaces in near real time instead of at cycle close. Supported for several Tier-A providers today, with more wiring in continuously.
- Mailbox ingestion: Microsoft 365, Google Workspace, Proton.
- Direct API ingestion where the provider exposes one.
- Manual upload remains the always-available fallback.
-
April 2026
In-product audit-chain viewer
Your assessor can now inspect the verifiable audit chain directly inside Affirmark — integrity banner, per-entry inspector, filters by actor / entity / date range. Raw JSONL bundle still exports for offline review, and the signed CLI tool still ships for fully-offline verification.
- Filter by actor (system / user), entity type (narratives, evidence, findings, …), or date.
- Integrity banner reads OK / FAIL with the head hash and entry count.
- Download the raw JSONL bundle from the same screen for assessor handoff.
-
April 2026
Sign in with your IdP
OIDC sign-in via Cognito hosted UI. SSO from Microsoft Entra ID, Okta, or Google Workspace. Every action recorded against the user account that signed in — no more shared service-account credentials.
-
April 2026
Role-gated access
Backend and frontend now enforce role-based access. Operators see and edit; reviewers see and comment; auditors see only. Role assignments live in Settings → Users, audited like every other compliance entity.
-
April 2026
FedRAMP status on tooling
Each tool in your inventory now carries its FedRAMP authorization status — Authorized, In Process, or Not Authorized. Assessors see at a glance which third-party services in your stack are FedRAMP-aligned and which need a compensating control.
Want a capability in here? Tell us what you'd ship next.