Skip to main content

Who it's for

Who CREED serves, and what each role can hold it to.

Authorizing Official

A portfolio of every system under your authority: current state, unmet requirements, waiver exposure, and drift since the last decision. The only role that records a risk decision.

AO Designated Representative

Returns, acceptances, and waivers within delegated limits — maximum expiry, excluded constraint classes — that the server enforces and records.

AO staff

Composition and publication of requirement sets from versioned framework definitions, system onboarding, rebinding, and reference-binder pinning.

Security Control Assessor

Read access to every binder in scope: evaluation, coverage by framework, drift, and the audit chain.

Submitter

A template package and an offline validator that reproduce the server's evaluation before submission — plus a submission page with immediate, explained results.

Auditor

The complete chain of digests behind any binder and its decisions, plus the spillage log. Every question of what was known, by whom, under what authority, when — answered by digests the server already holds.

Request the pilot

Tell us which role you sit in.