Assessment Workbench
The Assessment Workbench is the focused workspace for examining one objective at a time. Where the assessment overview shows you the whole picture, the workbench zooms all the way in: for a single NIST SP 800-171A assessment objective, it puts the official guidance, your team's implementation narrative, the evidence that backs it, and any interviews and tests you've recorded side by side — so you can judge whether the objective is truly satisfied without hunting across the app.
It's built for the person doing the reviewing — an internal reviewer, a consultant, or an assessor doing a dry run. The workbench keeps a formal 800-171A assessment record that is deliberately separate from the day-to-day implementation tracking your team uses, so a review finding here never overwrites the status your engineers are working against.
/dashboard/assessments). Reading it is available to every role that can view assessment data, including read-only reviewers and assessors; recording findings, interviews, and tests requires an editing role — see Permissions.Key concepts
The objective finding
For each objective you reach a finding — your judgment of how well it's met. This is a formal assessment result, distinct from the implementation status your team maintains elsewhere.
| Finding | Meaning |
|---|---|
| Implemented | The objective is fully satisfied |
| Partially implemented | Some, but not all, of the objective is met |
| Not implemented | The objective is not met |
| Not applicable | The objective does not apply to this environment |
The 800-171A assessment guide
Every objective carries the official assessor guidance, laid out as the sections an assessor actually works from.
| Section | What it gives you |
|---|---|
| Assessor Perspective | Plain-language context on what a certified assessor is really looking for |
| Determine if | The exact condition that must be true for the objective to pass |
| Examine / Interview / Test | The three assessment methods — what to look at, who to talk to, what to try |
| Discussion & Further discussion | Background on the intent of the control |
| Examples | Concrete illustrations of acceptable implementations |
| Considerations | Nuances and edge cases to weigh |
| Common findings | The mistakes that most often cause this objective to fail |
| Related controls | Other objectives that interact with this one |
Evidence in context
The workbench shows the evidence already linked to the objective — files and links alike — so you can open and read each item without leaving the review. As you work, you can select the evidence that actually supports your finding and attach a short note explaining why it's relevant. When a piece of evidence is shared across several objectives, the workbench points out the other objectives it's also relevant to.
Interviews and tests
Two of the three assessment methods produce records you capture as you go:
| Record | What you note |
|---|---|
| Interview | Who you spoke with (one or more people) and a summary of the discussion |
| Test | What you tried or observed, and who performed it |
Assessment setup
Beyond individual objectives, the workbench holds the setup for the assessment as a whole: an editable title, the start and end dates, free-text methodology notes, and the participants — each with a name, title, role, and the dates they took part.
| Participant role | Typical use |
|---|---|
| Primary Assessor | The person leading the review |
| Interviewee | A staff member who answered questions |
| Technical Reviewer | A subject-matter reviewer |
| Executive Sponsor | Leadership accountable for the effort |
| Other | Anyone else who participated |
Using the workbench
The workbench is a three-part workspace: a list of objectives grouped by control family on one side, the work area for the selected objective in the middle, and its evidence and records alongside. A live SPRS score updates as you record findings, and a resume screen drops you back at the last objective you worked on.
Review an objective
Pick an objective
Choose an objective from the family list. Its guidance, implementation narrative, evidence, and any existing interviews and tests load into the work area.
Read the guidance
Expand the 800-171A Assessment Guide to see the Assessor Perspective, the "Determine if" condition, the three assessment methods, common findings, and examples for this objective.
Read the implementation statement
Review the narrative your team wrote describing how the objective is met. It's shown read-only here so the reviewer's judgment stays independent of the author's.
Check the evidence
Open each linked file or URL directly in the pane. Mark the items that genuinely support the objective as selected, and add a note explaining the connection.
Record a finding
Set the finding — Implemented, Partially implemented, Not implemented, or Not applicable — and write the rationale behind it. The assessor of record and the assessment date default to you and today, and both can be changed.
Record an interview
Add an interview
From the objective's interview section, start a new interview record.
Name the interviewees
Add one or more people — pick teammates from your organization or type a name for anyone external.
Summarize the discussion
Write what was covered. The record is kept with the objective as part of the assessment trail.
Record a test
Add a test
From the objective's test section, start a new test record.
Describe what you did
Note what you tried or observed and what the result showed.
Record who tested
Attribute the test to the person who performed it — a teammate or a typed name.
Set up the assessment
Open the assessment setup to give the review a title, set its start and end dates, capture your methodology notes, and build the participant list. Participants can be linked to people in your organization or entered by name, each with a role and the dates they took part.
Permissions
Access is split between reading the workbench and recording into it.
| Capability | Permission |
|---|---|
| Open the workbench, read guidance, implementation, and evidence | VIEW_EVIDENCE |
| Record findings, interviews, tests, evidence selections, and setup | UPLOAD_EVIDENCE |
Reading the workbench follows the same access as viewing assessment and evidence data, so reviewers and assessors can open it and study every objective in full. Recording into the record — findings, interviews, tests, evidence selections, and setup — requires an editing role (Org Admin, Org User, and the equivalent MSP roles).
WRITE_REVIEW_NOTES), keeping an outside reviewer's commentary separate from the organization's assessment record.How it works
Extra detail on what the workbench records and how it behaves — product behavior, not internals.
A record kept separate from implementation tracking
The workbench maintains its own formal 800-171A assessment: one finding per objective, per assessment. This record is deliberately independent of the implementation status your team edits while doing the work. Recording "Partially implemented" as a review finding does not flip the objective's working status, and vice-versa — so a reviewer's judgment and the team's remediation progress never overwrite each other.
What each objective record holds
The live SPRS score
As you record findings, the workbench recomputes the assessment's projected SPRS score on the spot, using the DoD weighting for each objective. A practice counts as met only when all of its in-scope objectives are satisfied, so the number you see mirrors how the assessment would actually score — useful for spotting the objectives that move the needle most.
Supporting internal validation
Because the workbench mirrors the structure an assessor uses — the same guidance sections, the same Examine / Interview / Test methods, findings and rationale, and a participant-and-methodology setup — it's a natural place to run an internal dry run before a formal assessment. You can walk every objective, decide whether the evidence truly supports it, note where common findings might trip you up, and build a defensible, point-in-time record of the review.
Related features
Systems & Objectives
Catalog the systems in your CUI environment, categorize each by its role in scope, and work every control objective against them — the day-to-day compliance work that drives your assessment, SPRS score, and SSP.
Overview
Collect evidence, build policies, and generate your System Security Plan.

