Skip to content
Foxx Cyberfoxxcyber/docs

Diagrams, Documentation Matrix and Activity

Keep boundary diagrams (Mermaid or images), track the 201 policies, procedures and records NIST 800-53 expects, and read the package activity log.

The last three tabs of a package hold what an assessor reads around the controls: the boundary diagrams, the documentation matrix of required policies and procedures, and the activity log that proves who changed what. Assessments is also here, as a placeholder for now.

Boundary diagrams

Open Diagrams in the package sidebar. The page reads Network Topology & Boundary Diagrams — Upload images or create Mermaid diagrams to document network boundaries. with + New Diagram.

The Diagrams page with a Mermaid boundary diagram card

The dialog asks for Name ("e.g., Network Boundary Diagram v1"), Type (mermaid or image upload), Description, Version ("e.g., 1.0") and, for Mermaid, the Mermaid Source (the placeholder shows a sample graph TD) with a live Preview. Click Create Diagram.

Each diagram card shows the name, a type badge, the description, a source preview, the version and date, and three icons: view (eye), edit (pencil) and delete. The eye opens the rendered diagram inline, with Edit and a close button.

A rendered Mermaid boundary diagram opened from its card

Mermaid keeps the diagram reviewable

A Mermaid diagram is text: it diffs, it can be copied into the SSP, and the version field plus the audit trail show exactly when the boundary changed. Use an image upload when the diagram comes from a network tool you cannot reproduce in Mermaid.

The documentation matrix

Open Documentation in the package sidebar. On first visit the page shows Initialize Documentation Tracker — Load the NIST 800-53 documentation matrix for this ATO package. This creates 201 document tracking entries mapped to controls across all 20 families. Click Initialize Documentation.

The documentation matrix with the AC-1 policy entry expanded

After that the page reads Documentation Matrix — Required policies, procedures, and records per NIST 800-53 controls, with counts for Documents / Complete / In Progress / Draft / Not Started and a completion percentage, family buttons (ALL 0/201 …) and Filter documents….

Columns: Control, Document, Type (Policy / Procedure / …), Priority, Status, Review, Owner, Evidence, Target Date. Click a row to expand it:

  • Status — not_started, draft, in_progress, complete
  • Review Status — pending …
  • Owner — "Assign owner…"
  • Target Date
  • Evidence Location — "URL or path…"
  • Notes
  • Attached Document — a URL or file name
  • Linked Evidence — Link Evidence to an item from the package's Evidence tab
  • Save

Activity

Activity is the package-scoped view of the audit trail — an Activity Log with an "all" filter and entries such as "Admin updated POA&M · 2m ago" or "Admin updated Implementation (complianceStatus)". The workspace-wide log, with every package, is Admin → Audit Log.

The package Activity log

Assessments

The Assessments tab is a placeholder in this release ("coming soon"). Until it lands, assessment work is tracked through the SCTM's VALIDATION methods (Examine / Interview / Test) and the STIG Center's test plans — see STIG posture.

The Assessments placeholder

Last updated August 27, 2026