Skip to content

What's New

Notable documentation additions and changes, newest first. For the platform's own change history, see the Significant Changes report in your Trust Center.


September 2026

  • Trust Center Uploads -- the write-path companion to the Trust Center Access Guide: how to upload your FedRAMP certification JSON artifacts into Certification Documents through the three-call Halo Attachment presigned-URL flow, using the credentials and the site, folder, and document-type ids your provider issues.
  • Operations Meetings -- a new cross-cutting policy and procedure for the recurring meeting that runs a certified system from its GRC-ITSM records: one Project per period and one task per meeting, a status report rendered from current records, certification-risk tiers reviewed first, a fixed nine-item agenda, and every outcome recorded on the ticket it concerns. It also carries a KB download and the FedRAMP and CMMC requirements the meeting evidences.
  • AI -- the page now covers what the grcitsm-analyst plugin does beyond onboarding: gap remediation, policy library adoption, project management, ticket updates, webhook integration help, automated-check coverage lookups, the daily update check, and a new section on running your system through the Operations Meeting with AI assistance, stating plainly which parts are available today.

August 2026

  • Personnel Security template -- a sixth client template for the one control family the platform cannot execute for you: position risk designation, screening before access, rescreening, access agreements, personnel actions, external personnel, and sanctions, mapped to the Rev5 PS family, the five 20x Key Security Indicators carrying PS lineage, and both CMMC Level 2 PS practices.
  • Integrations -- the page now says plainly that the platform is built on HaloITSM and inherits its native integration catalog, pointing to the vendor for the complete list and setup guides; what remains is what Stratus refines and the connectors that carry weight inside an authorization boundary.
  • KSI Tracking -- how FedRAMP 20x Key Security Indicators are structured in the platform: the parent KSI ticket, its per-check child tickets, the dated validation records underneath, and the check ID scheme whose suffix identifies the cloud provider. Published under Compliance.
  • Compliance Exemptions -- tagging a cloud resource so the compliance scan reports it as skipped instead of failing, with the exact tag format and its silent failure modes, the resource to tag for each of the 176 exemptable checks, the 50 checks that ignore the tag, and the review discipline that keeps exemptions time-bounded.
  • Downloads -- a new top-level section collecting every file the site publishes: the policy and procedure documents ready to import into a Knowledge Base, and the Stratus GRCITSM plugin marketplace, now downloadable here with a published version and SHA-256 rather than supplied by hand.
  • Steampipe/Powerpipe Stack -- the Stratus-provided deployment template that runs Steampipe and Powerpipe with Stratus mods in your own environment, with the ingestion pipeline that turns benchmark results into machine-based KSI validation records; includes the end-to-end architecture and an AWS deployment guide.
  • Integrations reorganized -- the integration catalog moved from Administrative to its own top-level section, joined by a new Datadog page: the payload refinements that route Datadog monitor and security alerts into the Alert ticket type, with category-driven framework linkage and populated technical fields.
  • AI -- how AI assistants connect to and operate GRC-ITSM over MCP: capability areas, the Stratus GRCITSM plugin marketplace setup in Claude (claude.ai organization plugins and Claude Code), the instance-side connector configuration, and the guardrails that keep AI work governed. Published as a top-level page.

July 2026

  • Role and CAB management documented -- the Agent Roles page now covers the live role families (Capability, Agent Membership, Agent Assignment, Approver, notifications, and named roles) with a new Role Management section tying role changes to UAR governance and recertification; the Approval Processes page documents the four CABs and their role-based membership. The change CAB is named Change Approvers throughout.
  • Site-wide consistency pass -- field names, workflows, and concepts aligned everywhere with the Policies & Procedures layer: named approval CABs with the optional organizational stage, the four deviation types and their live workflow statuses, PAIN-based incident evaluation and reporting in the Incident Response playbook, the seven change types, in-place alert escalation, and current Trust Center report names.
  • KB import downloads realigned -- the downloadable article files now place the full document in the Description field (matching the GRC-ITSM article convention), with the summary and paste instructions in the Internal Memo.
  • Policies & Procedures section -- the eight platform policy-and-procedure documents (Access Management, Asset/Inventory/Scope, Certification Data Sharing & Trust Center, Certification Package & SDR, Change Management, Continuous Monitoring & Reporting, Incident Response, Vulnerability Detection & Response) published in full, plus the five-document Client Template Library.
  • KB import downloads -- every Policies & Procedures page now carries a download button producing a Markdown file mapped to the GRC-ITSM KB article fields (Description, Resolution, Internal Memo, Tags), ready to import into your own instance.
  • Trust Center Access Guide -- the customer-facing guide to portal and programmatic (REST API) access to certification data, published as a top-level page.
  • Glossary -- one reference for the compliance and platform terms used across the documentation.
  • DB Integrator Operations -- version checks and troubleshooting for on-prem deployments.
  • Approval workflow documentation aligned -- guides now describe the named per-type approval CABs with the optional organizational sign-off stage.
  • Baseline-specific remediation SLAs -- vulnerability remediation documentation now covers both the FedRAMP Rev5 severity timelines and the FedRAMP 20x PAIN-based Class Remediation SLA ladder.
  • Refreshed screenshots -- current-platform captures across the Trust Center, agent dashboard, ConMon, change management, user access, compliance validations, and asset documentation pages.
  • Official FedRAMP references -- every policy and procedure page links its rule families and Key Security Indicators on fedramp.gov.

May 2026

  • On-Prem Maintenance runbooks -- upgrading the host OS and upgrading Halo, with reader-substituted environment placeholders.