OCTAAR

// METHODOLOGY

Audit-defensible assessment.

Most readiness records cannot survive this chain. They were never built to. OCTAAR records are built to.

Audit-defensible assessment An assessment is audit-defensible when an external reviewer can trace any score back to its rubric version, the evaluator's calibration state at the time, the observation it was based on, the finding it produced, the action assigned, the evidence of closure, and the outcome. Every link in the chain is preserved and immutable.

// 01 — THE CHAIN

Eight links, no gaps.

Observation. The data primitive. Time-stamped, observer-attributed, context-anchored.

Rubric version. The specific calibrated rubric in force at the time of scoring, with full version history.

Scoring evaluator. The named evaluator who applied the rubric.

Calibration state. The evaluator's IRR and drift posture at the moment of scoring.

Finding. The structured statement inheriting from one or more observations.

Action. The assigned remediation, with owner and due date.

Evidence. The documentation, record, or follow-up observation that satisfies the action.

Closure. The verified completion state, with the evidence attached.

Eight links. The chain is audit-defensible if and only if every link is intact and traceable.

// 02 — WHY MOST RECORDS FAIL

Where the chain breaks.

It breaks at the rubric version when the rubric is a Google doc that was edited without version history. The score is real; the standard it was scored against is lost.

It breaks at the evaluator's calibration state when calibration was annual and the cycle is in October. The score has no defensible context.

It breaks at finding inheritance when the AAR is free text and no one can reconstruct which observation supports which finding.

It breaks at action closure when 'closed' is a status the evaluator marked rather than a verified completion with attached evidence.

Each break is invisible during the cycle. Each is exposed by audit or by incident.

// 03 — WHAT OCTAAR PRESERVES

Substrate-level provenance.

OCTAAR's data model preserves the chain at the substrate level. Versions are immutable. Personnel rotation does not break attribution. Rubric edits produce new versions; historical scores stay attached to their version. Findings inherit from observations by hard reference; actions inherit from findings; evidence attaches to actions; closure inherits from evidence.

An external reviewer querying the system can reconstruct the chain for any score in any cycle. The platform is the chain made operational.

// 04 — UNDER AUDIT

What audit-defensible means in practice.

It means the auditor's request for evidence is satisfied by query, not by assembly. The records exist in the form the auditor needs, because they were built that way at the moment of capture.

It means a finding from three cycles ago, surfaced by a different observer, scored against a prior rubric version, can be reconstructed without ambiguity.

It means the answer to 'show me the evidence this unit was assessed against this standard last year, by whom, with what result, and how the finding was closed' is one query, not a week of email.

// Last updated · · OCTAAR Methodology Team

// FAQ

Direct answers.

Is OCTAAR FedRAMP authorized?
OCTAAR's architecture is aligned to a FedRAMP pathway. Specific authorization status is shared on request under NDA. The platform does not claim certifications it has not been granted.
Can OCTAAR export the audit chain to a regulator's format?
Yes. The data model is exportable to common audit-evidence formats. The chain travels with the record.
What if a record needs to be amended after closure?
Amendment produces an audit trail entry, not a silent edit. The original record persists; the amendment is attached with its own attribution and timestamp. Audit-defensibility means immutability of the prior state, not impossibility of correction.
How does OCTAAR handle records when personnel rotate?
Attribution stays attached to the historical actor. The rotation does not strip the chain. A new owner inherits the open actions; the closed actions retain their original closure attribution.

// READY

See the discipline as an operating cycle.