The residue is the product
The honest end of the course: the controls a machine can prove today, the ones still owed a recipe, and the ones that close as documents — with the register that names each, so nothing has to be taken on faith.
The last distinction is the one that makes every earlier one safe to use in public: some controls no machine can prove, and saying so is not a failure — it is the product. A segmentation policy can be queried; where your racks physically sit cannot. A team that knows its residue can staff it; a team sold “everything automated” discovers the residue during the assessment, which is the most expensive possible time.
Here is this site’s own register, live — every control a Key Security Indicator reaches, judged one at a time:
The registercontrols a Key Security Indicator reaches
- Already collected
- 95 of 209a command is written; you run it
- A machine could
- 0 of 209one call would settle it — nobody has written it
- A machine gets part of the way
- 27 of 209the call proves some of it; you write the rest
- Only a person can
- 29 of 209no AWS or pipeline API answers this — it is a document you write
- Nobody has looked
- 58 of 209not judged either way, by us or anyone
Read the last two rows as carefully as the first. A control closed as narrative was looked at, against named planes, and the written reason is on its row — which is a different fact from a control nobody has reviewed. Keeping those two states distinguishable is what lets the rest of the register be believed. The full table, with every rationale, is at /automation; the proportions are drawn at /frontier.
One more fact belongs in your team’s planning, from the rules rather than from this corpus: FedRAMP’s RFC-0024 moves authorization packages themselves to machine-readable formats, on dates already set. The evidence you collect and the package you submit are converging on the same discipline — deterministic data from authoritative sources, and a stated residue where no such data exists.
That is the course. From here the site works as a tool: state your class once and /plan becomes your collection plan, /map your scope, and /collect the commands themselves.
Exit check — a stakeholder asks “so what percentage is automated?” What is the honest answer?
A pointer, not a number from memory: the register above, with its denominator stated — and the reminder that the denominator is the KSI-reached surface, not the whole baseline. Any single percentage quoted without its denominator and date is already rotting; the honest artifact is the live register, which is why this site ends every path at one.