Assessment Workbench

Review a single objective in depth — its 800-171A guidance, the implementation narrative, linked evidence, and recorded interviews and tests — in one focused workspace built for internal validation before a formal assessment.

The Assessment Workbench is the focused workspace for examining one objective at a time. Where the assessment overview shows you the whole picture, the workbench zooms all the way in: for a single NIST SP 800-171A assessment objective, it puts the official guidance, your team's implementation narrative, the evidence that backs it, and any interviews and tests you've recorded side by side — so you can judge whether the objective is truly satisfied without hunting across the app.

It's built for the person doing the reviewing — an internal reviewer, a consultant, or an assessor doing a dry run. The workbench keeps a formal 800-171A assessment record that is deliberately separate from the day-to-day implementation tracking your team uses, so a review finding here never overwrites the status your engineers are working against.

Open the workbench from an assessment — it's the focused review view alongside the assessment overview (/dashboard/assessments). Reading it is available to every role that can view assessment data, including read-only reviewers and assessors; recording findings, interviews, and tests requires an editing role — see Permissions.

Key concepts

The objective finding

For each objective you reach a finding — your judgment of how well it's met. This is a formal assessment result, distinct from the implementation status your team maintains elsewhere.

FindingMeaning
ImplementedThe objective is fully satisfied
Partially implementedSome, but not all, of the objective is met
Not implementedThe objective is not met
Not applicableThe objective does not apply to this environment
Recording a finding in the workbench does not change the implementation status your team tracks day to day. The two are kept apart on purpose: the workbench is your assessment record, so a reviewer can form an independent judgment without disturbing ongoing remediation work.

The 800-171A assessment guide

Every objective carries the official assessor guidance, laid out as the sections an assessor actually works from.

SectionWhat it gives you
Assessor PerspectivePlain-language context on what a certified assessor is really looking for
Determine ifThe exact condition that must be true for the objective to pass
Examine / Interview / TestThe three assessment methods — what to look at, who to talk to, what to try
Discussion & Further discussionBackground on the intent of the control
ExamplesConcrete illustrations of acceptable implementations
ConsiderationsNuances and edge cases to weigh
Common findingsThe mistakes that most often cause this objective to fail
Related controlsOther objectives that interact with this one
Guidance sections only appear when there's content for them, so the panel stays uncluttered. The Common findings section is especially useful during a dry run — it tells you where organizations typically slip before an assessor ever arrives.

Evidence in context

The workbench shows the evidence already linked to the objective — files and links alike — so you can open and read each item without leaving the review. As you work, you can select the evidence that actually supports your finding and attach a short note explaining why it's relevant. When a piece of evidence is shared across several objectives, the workbench points out the other objectives it's also relevant to.

Interviews and tests

Two of the three assessment methods produce records you capture as you go:

RecordWhat you note
InterviewWho you spoke with (one or more people) and a summary of the discussion
TestWhat you tried or observed, and who performed it

Assessment setup

Beyond individual objectives, the workbench holds the setup for the assessment as a whole: an editable title, the start and end dates, free-text methodology notes, and the participants — each with a name, title, role, and the dates they took part.

Participant roleTypical use
Primary AssessorThe person leading the review
IntervieweeA staff member who answered questions
Technical ReviewerA subject-matter reviewer
Executive SponsorLeadership accountable for the effort
OtherAnyone else who participated

Using the workbench

The workbench is a three-part workspace: a list of objectives grouped by control family on one side, the work area for the selected objective in the middle, and its evidence and records alongside. A live SPRS score updates as you record findings, and a resume screen drops you back at the last objective you worked on.

Review an objective

Pick an objective

Choose an objective from the family list. Its guidance, implementation narrative, evidence, and any existing interviews and tests load into the work area.

Read the guidance

Expand the 800-171A Assessment Guide to see the Assessor Perspective, the "Determine if" condition, the three assessment methods, common findings, and examples for this objective.

Read the implementation statement

Review the narrative your team wrote describing how the objective is met. It's shown read-only here so the reviewer's judgment stays independent of the author's.

Check the evidence

Open each linked file or URL directly in the pane. Mark the items that genuinely support the objective as selected, and add a note explaining the connection.

Record a finding

Set the finding — Implemented, Partially implemented, Not implemented, or Not applicable — and write the rationale behind it. The assessor of record and the assessment date default to you and today, and both can be changed.

The finding, its rationale, and the assessor and date save as you go. The SPRS score on screen reflects your findings live, so you can watch the assessment's projected score take shape as you work through the objectives.

Record an interview

Add an interview

From the objective's interview section, start a new interview record.

Name the interviewees

Add one or more people — pick teammates from your organization or type a name for anyone external.

Summarize the discussion

Write what was covered. The record is kept with the objective as part of the assessment trail.

Record a test

Add a test

From the objective's test section, start a new test record.

Describe what you did

Note what you tried or observed and what the result showed.

Record who tested

Attribute the test to the person who performed it — a teammate or a typed name.

Set up the assessment

Open the assessment setup to give the review a title, set its start and end dates, capture your methodology notes, and build the participant list. Participants can be linked to people in your organization or entered by name, each with a role and the dates they took part.

Setup describes the assessment as a whole and provides the front-matter an assessor expects — who was involved, over what dates, and by what method — so the finished record reads as a complete, defensible review.

Permissions

Access is split between reading the workbench and recording into it.

CapabilityPermission
Open the workbench, read guidance, implementation, and evidenceVIEW_EVIDENCE
Record findings, interviews, tests, evidence selections, and setupUPLOAD_EVIDENCE

Reading the workbench follows the same access as viewing assessment and evidence data, so reviewers and assessors can open it and study every objective in full. Recording into the record — findings, interviews, tests, evidence selections, and setup — requires an editing role (Org Admin, Org User, and the equivalent MSP roles).

The Assessor role is intentionally read-only in the workbench: an assessor can review every objective, its guidance, the implementation narrative, and the evidence, but does not record the organization's own findings. Assessors contribute their feedback through review notes in the review workflow (WRITE_REVIEW_NOTES), keeping an outside reviewer's commentary separate from the organization's assessment record.

How it works

Extra detail on what the workbench records and how it behaves — product behavior, not internals.

A record kept separate from implementation tracking

The workbench maintains its own formal 800-171A assessment: one finding per objective, per assessment. This record is deliberately independent of the implementation status your team edits while doing the work. Recording "Partially implemented" as a review finding does not flip the objective's working status, and vice-versa — so a reviewer's judgment and the team's remediation progress never overwrite each other.

What each objective record holds

Finding
Implemented, Partially implemented, Not implemented, or Not applicable — your assessment result for the objective.
Rationale
The free-text reasoning behind the finding.
Assessor of record
Who made the assessment — defaults to you, editable.
Assessment date
When the objective was assessed — defaults to today, editable.
Selected evidence
The evidence items you marked as supporting the finding, each with an optional note.
Interviews
Who you spoke with and a summary of each discussion.
Tests
What you tried or observed, and who performed it.

The live SPRS score

As you record findings, the workbench recomputes the assessment's projected SPRS score on the spot, using the DoD weighting for each objective. A practice counts as met only when all of its in-scope objectives are satisfied, so the number you see mirrors how the assessment would actually score — useful for spotting the objectives that move the needle most.

Supporting internal validation

Because the workbench mirrors the structure an assessor uses — the same guidance sections, the same Examine / Interview / Test methods, findings and rationale, and a participant-and-methodology setup — it's a natural place to run an internal dry run before a formal assessment. You can walk every objective, decide whether the evidence truly supports it, note where common findings might trip you up, and build a defensible, point-in-time record of the review.


Assessments

Track objective status and overall compliance across the whole assessment.

Reviews

Where assessors and reviewers leave review notes on submitted work.

SPRS Scoring

See how objective findings roll up into your DoD SPRS score.