---
title: Assessment Workbench
description: Review a single objective in depth — its 800-171A guidance, the implementation narrative, linked evidence, and recorded interviews and tests — in one focused workspace built for internal validation before a formal assessment.
navigation:
  icon: i-lucide-microscope
---

# Assessment Workbench

The **Assessment Workbench** is the focused workspace for examining one objective at a time. Where the assessment overview shows you the whole picture, the workbench zooms all the way in: for a single NIST SP 800-171A assessment objective, it puts the **official guidance**, your team's **implementation narrative**, the **evidence** that backs it, and any **interviews and tests** you've recorded side by side — so you can judge whether the objective is truly satisfied without hunting across the app.

It's built for the person doing the reviewing — an internal reviewer, a consultant, or an assessor doing a dry run. The workbench keeps a **formal 800-171A assessment record** that is deliberately separate from the day-to-day implementation tracking your team uses, so a review finding here never overwrites the status your engineers are working against.

::note
Open the workbench from an assessment — it's the focused review view alongside the assessment overview (`/dashboard/assessments`). Reading it is available to every role that can view assessment data, including read-only reviewers and assessors; recording findings, interviews, and tests requires an editing role — see [Permissions](#permissions).
::

---

## Key concepts

### The objective finding

For each objective you reach a **finding** — your judgment of how well it's met. This is a formal assessment result, distinct from the implementation status your team maintains elsewhere.

| Finding | Meaning |
| --- | --- |
| :badge[Implemented]{color="success"} | The objective is fully satisfied |
| :badge[Partially implemented]{color="warning"} | Some, but not all, of the objective is met |
| :badge[Not implemented]{color="error"} | The objective is not met |
| :badge[Not applicable]{color="neutral"} | The objective does not apply to this environment |

::tip
Recording a finding in the workbench does **not** change the implementation status your team tracks day to day. The two are kept apart on purpose: the workbench is your assessment record, so a reviewer can form an independent judgment without disturbing ongoing remediation work.
::

### The 800-171A assessment guide

Every objective carries the official assessor guidance, laid out as the sections an assessor actually works from.

| Section | What it gives you |
| --- | --- |
| **Assessor Perspective** | Plain-language context on what a certified assessor is really looking for |
| **Determine if** | The exact condition that must be true for the objective to pass |
| **Examine / Interview / Test** | The three assessment methods — what to look at, who to talk to, what to try |
| **Discussion & Further discussion** | Background on the intent of the control |
| **Examples** | Concrete illustrations of acceptable implementations |
| **Considerations** | Nuances and edge cases to weigh |
| **Common findings** | The mistakes that most often cause this objective to fail |
| **Related controls** | Other objectives that interact with this one |

::note
Guidance sections only appear when there's content for them, so the panel stays uncluttered. The **Common findings** section is especially useful during a dry run — it tells you where organizations typically slip before an assessor ever arrives.
::

### Evidence in context

The workbench shows the evidence already linked to the objective — files and links alike — so you can open and read each item without leaving the review. As you work, you can **select** the evidence that actually supports your finding and attach a short **note** explaining why it's relevant. When a piece of evidence is shared across several objectives, the workbench points out the other objectives it's **also relevant to**.

### Interviews and tests

Two of the three assessment methods produce records you capture as you go:

| Record | What you note |
| --- | --- |
| **Interview** | Who you spoke with (one or more people) and a summary of the discussion |
| **Test** | What you tried or observed, and who performed it |

### Assessment setup

Beyond individual objectives, the workbench holds the **setup** for the assessment as a whole: an editable title, the start and end dates, free-text methodology notes, and the **participants** — each with a name, title, role, and the dates they took part.

| Participant role | Typical use |
| --- | --- |
| **Primary Assessor** | The person leading the review |
| **Interviewee** | A staff member who answered questions |
| **Technical Reviewer** | A subject-matter reviewer |
| **Executive Sponsor** | Leadership accountable for the effort |
| **Other** | Anyone else who participated |

---

## Using the workbench

The workbench is a three-part workspace: a **list of objectives** grouped by control family on one side, the **work area** for the selected objective in the middle, and its **evidence and records** alongside. A live **SPRS score** updates as you record findings, and a resume screen drops you back at the last objective you worked on.

### Review an objective

::steps{level="4"}

#### Pick an objective

Choose an objective from the family list. Its guidance, implementation narrative, evidence, and any existing interviews and tests load into the work area.

#### Read the guidance

Expand the **800-171A Assessment Guide** to see the Assessor Perspective, the "Determine if" condition, the three assessment methods, common findings, and examples for this objective.

#### Read the implementation statement

Review the narrative your team wrote describing how the objective is met. It's shown read-only here so the reviewer's judgment stays independent of the author's.

#### Check the evidence

Open each linked file or URL directly in the pane. Mark the items that genuinely support the objective as **selected**, and add a note explaining the connection.

#### Record a finding

Set the finding — Implemented, Partially implemented, Not implemented, or Not applicable — and write the rationale behind it. The assessor of record and the assessment date default to you and today, and both can be changed.

::

::tip
The finding, its rationale, and the assessor and date save as you go. The SPRS score on screen reflects your findings live, so you can watch the assessment's projected score take shape as you work through the objectives.
::

### Record an interview

::steps{level="4"}

#### Add an interview

From the objective's interview section, start a new interview record.

#### Name the interviewees

Add one or more people — pick teammates from your organization or type a name for anyone external.

#### Summarize the discussion

Write what was covered. The record is kept with the objective as part of the assessment trail.

::

### Record a test

::steps{level="4"}

#### Add a test

From the objective's test section, start a new test record.

#### Describe what you did

Note what you tried or observed and what the result showed.

#### Record who tested

Attribute the test to the person who performed it — a teammate or a typed name.

::

### Set up the assessment

Open the **assessment setup** to give the review a title, set its start and end dates, capture your methodology notes, and build the **participant list**. Participants can be linked to people in your organization or entered by name, each with a role and the dates they took part.

::note
Setup describes the assessment as a whole and provides the front-matter an assessor expects — who was involved, over what dates, and by what method — so the finished record reads as a complete, defensible review.
::

---

## Permissions

Access is split between reading the workbench and recording into it.

| Capability | Permission |
| --- | --- |
| Open the workbench, read guidance, implementation, and evidence | :badge[VIEW_EVIDENCE]{color="neutral"} |
| Record findings, interviews, tests, evidence selections, and setup | :badge[UPLOAD_EVIDENCE]{color="info"} |

Reading the workbench follows the same access as viewing assessment and evidence data, so **reviewers and assessors can open it and study every objective in full**. Recording into the record — findings, interviews, tests, evidence selections, and setup — requires an editing role (Org Admin, Org User, and the equivalent MSP roles).

::warning
The **Assessor** role is intentionally **read-only** in the workbench: an assessor can review every objective, its guidance, the implementation narrative, and the evidence, but does not record the organization's own findings. Assessors contribute their feedback through **review notes** in the review workflow (`WRITE_REVIEW_NOTES`), keeping an outside reviewer's commentary separate from the organization's assessment record.
::

---

## How it works

Extra detail on what the workbench records and how it behaves — product behavior, not internals.

### A record kept separate from implementation tracking

The workbench maintains its own formal 800-171A assessment: one finding per objective, per assessment. This record is deliberately **independent** of the implementation status your team edits while doing the work. Recording "Partially implemented" as a review finding does not flip the objective's working status, and vice-versa — so a reviewer's judgment and the team's remediation progress never overwrite each other.

### What each objective record holds

:::field-group
::field{name="Finding"}
Implemented, Partially implemented, Not implemented, or Not applicable — your assessment result for the objective.
::
::field{name="Rationale"}
The free-text reasoning behind the finding.
::
::field{name="Assessor of record"}
Who made the assessment — defaults to you, editable.
::
::field{name="Assessment date"}
When the objective was assessed — defaults to today, editable.
::
::field{name="Selected evidence"}
The evidence items you marked as supporting the finding, each with an optional note.
::
::field{name="Interviews"}
Who you spoke with and a summary of each discussion.
::
::field{name="Tests"}
What you tried or observed, and who performed it.
::
:::

### The live SPRS score

As you record findings, the workbench recomputes the assessment's projected **SPRS score** on the spot, using the DoD weighting for each objective. A practice counts as met only when all of its in-scope objectives are satisfied, so the number you see mirrors how the assessment would actually score — useful for spotting the objectives that move the needle most.

### Supporting internal validation

Because the workbench mirrors the structure an assessor uses — the same guidance sections, the same Examine / Interview / Test methods, findings and rationale, and a participant-and-methodology setup — it's a natural place to run an **internal dry run** before a formal assessment. You can walk every objective, decide whether the evidence truly supports it, note where common findings might trip you up, and build a defensible, point-in-time record of the review.

---

## Related features

:::card-group

::card{title="Assessments" icon="i-lucide-clipboard-list" to="https://app.dibfi.com/dashboard/assessments"}
Track objective status and overall compliance across the whole assessment.
::

::card{title="Reviews" icon="i-lucide-clipboard-check" to="https://app.dibfi.com/dashboard/reviews"}
Where assessors and reviewers leave review notes on submitted work.
::

::card{title="SPRS Scoring" icon="i-lucide-gauge"}
See how objective findings roll up into your DoD SPRS score.
::

:::
