Continuous controls monitoring without a false green dashboard

ConMon automation moves repeatable collection and comparison into a scheduled, inspectable workflow: pull permitted security signals, normalize findings, check evidence freshness, flag drift, and prepare a versioned report. It should never convert a failed or partial pull into a clean bill of health. Human owners still decide remediation, accept risk, review reports, and attest to facts the software cannot observe.

Product measurement: scm.cc main defines 13 targeted KSI collector checks across GitHub, Supabase, AWS and scanner facts. That is a count of implemented checks, not 13 verified KSIs or proof that every tenant has the necessary connected sources.

FedRAMP now uses Certification and Classes A-D for package baselines. During the transition through December 31, 2026, Class B (Low), Class C (Moderate) and Class D (High) pair the new class with the earlier label; Class A is a pilot. Certification does not replace an agency's own authorization to operate. Historical Rev 5 baseline identifiers in records stay unchanged.

Which ConMon steps can be automated?

A useful pipeline retains provenance from the original connector run through a finding, its mapped control and a dated report. The current monthly package code creates a content-addressed manifest for its sections; a hash helps detect changed bytes but is not an independent signature. scm.cc can run configured read-only sources on a schedule, deduplicate findings, record open and resolved states, and recompute its tenant coverage dashboard. Monthly runs pin an input snapshot and baseline so a later change does not silently rewrite history. Where a loader fails, the run must show partial or failed rather than succeeded.

What can no automation honestly decide?

A policy's wording and an owner's signature are not scanner outputs. An agency's risk tolerance, a deviation approval and an independent assessor's finding are also decisions by people. A KSI with fewer than the required automated methods remains unverified; a successful data pull does not create a second method. FedRAMP's 20x principles favor automatic validation where possible while retaining accountability for the security decisions themselves.

How should a team test an automation vendor?

Run a complete workflow with one real connector and verify a known source finding reaches the product with the same discovery date. Then intentionally remove a permission or hit a page cap in a test account and check that the run is degraded, not empty-and-clean. Export a monthly package and compare its snapshot and source references with what the tenant dashboard showed. Confirm the owner can see what changed between runs.

What is the cost and operational limit in scm.cc?

A free account allows one connected repo and one connector; the pricing page lists monthly Starter ($299), Pro ($599) and Business ($999) with increasing repo and connector caps. The operational limit matters more than a feature list: the live ConMon run is monthly today. The separate Class C three-day machine-verification path is not yet a production guarantee. Customers must still validate each integration with their own permissions and data.

Questions teams ask

Can ConMon be fully automated?
Collection and comparison can be automated in part. Risk decisions, signatures, independent assessment and source-scope review remain human responsibilities.
What happens if a connector fails?
The honest result is a degraded or partial run and no inference that missing findings were fixed. A clean result is only meaningful over the scope actually checked.
Are 13 collectors equal to 13 compliant KSIs?
No. They are code-defined checks. Each KSI needs its own qualifying evidence methods and source data; unverified states remain unverified.
Does the public demo show my company?
No. /demo is clearly labeled fixture data. The signed-in tenant dashboard is the place to inspect your own connected records.

Primary sources

Source and product behavior reviewed September 30, 2026. Check current FedRAMP rules before relying on a schedule or submission requirement. This is product guidance, not an assessment, legal advice, certification or authorization.