Argos GRC · Platform Assessment

Gap analysis vs. the commercial GRC field — and where Shield fits

A fact-based audit of the Argos GRC codebase (50+ apps, 19 frameworks) against the table-stakes and differentiators of Vanta, Drata, Secureframe, Cynomi, AuditBoard and peers. Verdict: the platform is materially more complete than assumed. Only a handful of genuine gaps remain — and one of them is closed by a tool IA already owns.

The honest verdict

Nearly every capability a modern GRC platform is judged on already exists as a first-class app — risk register, questionnaire automation, auditor collaboration, assessments, maturity, BCP/DR, TPRM, and an unusually current framework set (CMMC 2.0, DORA, ISO 42001, PCI v4.0). The remaining work is narrow and high-leverage, not foundational.

20Built & strong
3Partial
2True gaps
Have first-class, in production Partial exists, needs depth Gap genuinely missing
Built & strong — the platform already leads here
Multi-framework + crosswalk
Have
19 frameworks incl. CMMC L1/L2, DORA, ISO 42001, PCI v4.0, NIST 800-53/171/172, HIPAA, ISO 27001, SOC 2, CIS v8.1, CJIS, NY DFS 500, HICP 405(d), CPG 2.0, SMB1001. More current than most competitors.
Evidence automation
Have
8 deep connectors (M365, Google, Sophos MDR, NinjaRMM, Verify, BambooHR, DigitalOcean, Forgejo) + auto-collectors and run-status derivation.
Risk register + heatmap
Have
risks: Risk / Treatment / Status / Library / Comment, plus risk_matrices for the heatmap. This was my #1 suspected gap — it's real and first-class.
Inbound questionnaire automation
Have
questionnaire: AnswerLibraryEntry + Session / Item / Settings — auto-answering DDQ / SIG / CAIQ from a reusable answer library.
Auditor collaboration / PBC
Have
auditor: AuditorAssignment + AuditorEvidenceRequest — a scoped evidence-request (PBC) tracker for external auditors.
Policy management + e-sign
Have
Recreated IA-owned library (52 policies, 27 languages), acknowledgment blocks, Argos Endorse as default signing path.
Assessments & maturity
Have
assessments (templates / sections / questions / responses / evidence) + maturity scoring.
Audit + AI Mock Auditor
Have
Athena Mock Auditor (AI) + audit workflow. A capability most competitors don't have at all.
Findings / exceptions / gap
Have
findings, exceptions (SecurityException = risk acceptance), gap (CoverageSnapshot).
TPRM / vendor risk + Trust Center
Have
tprm + vendors + trust (Argos Trust, a TITAN/SecurityScorecard peer) + public Trust Center.
Awareness training + phishing
Have
Now owned end-to-end (was OEM): 78 modules, 165 phishing templates incl. an Expert tier, 19 landing pages, Phish Alert Button. Cost + margin advantage over Vanta/Drata.
BCP/DR · Incidents · vCISO
Have
bcp, incidents (NCISS scoring), vciso + portfolio + time-tracking → Service billing.
Cyber insurance readiness
Have
Insurance-application → control mapping + claim-ready evidence packet. Pairs with Shield: quantified $ data liability vs. actual coverage = a coverage-gap figure no competitor produces.
Bonus breadth
Have
sbom, CSPM, pentest, attack (MITRE ATT&CK), ransomsim, ma_diligence, ir_retainer, raci, privacy, perimeters — well beyond baseline GRC.
Gaps & partials — the narrow, high-leverage list
User Access Reviews (UAR)
Gap
No dedicated access-certification campaign / attestation model found. Table stakes for SOC 2 CC6.2–6.3 and ISO A.5.18. Identity plumbing (Entra / Zitadel / Verify) exists — the review workflow is the missing piece.
Risk quantification in $
Gap
The risk register is qualitative (likelihood × impact). No dollar-denominated (FAIR-lite) loss modeling. Closed by Shield — see below.
Integration long-tail
Partial
~8 connectors + ~15 integration points vs. Vanta's 300+. Missing the expected tail: Jira, Slack, AWS/Azure/GCP config, MDM (Jamf/Intune/Kandji), Okta, CrowdStrike. Strategically optional given IA owns its own stack — prioritize by client demand.
Device compliance → control evidence
Partial
No disk-encryption / screen-lock / OS-version evidence normalization surfaced. RMM (NinjaRMM / Overwatch / Agent) data likely lives in security ops, not rolled up as control evidence. Verify + wire the bridge.
AI governance depth
Partial
ai_risk has an AISystem inventory and ISO 42001 is loaded, but model cards + a full AI risk-assessment workflow would make it a headline module as this becomes table stakes within a year.

Minor data hygiene: CIS v8.1 is loaded twice (duplicate framework) — distorts coverage math; dedupe.


Adjacent asset · Argos Red

Shield closes the one differentiator gap — and competitors can't match it

Argos Shield (the "Shield Scout" scanner) walks a device or environment, classifies and counts sensitive records, and prices them into a real dollar liability — PHI ≈ $408, PCI ≈ $295, PII ≈ $180, CUI ≈ $350, Creds ≈ $150, IP ≈ $1,000 per record (with low/expected/high ranges). It's IA's Actifile wedge. That output is precisely the quantitative input GRC's qualitative risk register lacks.

Shield: data value $ Asset valuation× Risk-register likelihood Annualized Loss Expectancy ($)
Dollar-denominated risk

Turns "High/Med/Low" into "$X at risk" — the board-and-insurer language auditors and CFOs actually use.

Data-inventory evidence

Record counts (PHI/PCI/PII/CUI) satisfy data-classification & inventory controls: CIS 3, ISO A.5.9/5.12, PCI CHD discovery, HIPAA ePHI, GDPR/CCPA mapping.

A moat, not a me-too

Vanta/Drata don't quantify $ risk from real data; FAIR vendors don't own the scanner or the GRC. IA owns all three.

Wiring: Shield already has a planned --upload to /shield/agent/scan; GRC already integrates Argos Red (argos_red_compliance.py). Add a Shield-valuation pull → populate assets value + a $ field on the risk register + evidence for data-inventory controls.

Recommended sequence — by leverage, not effort
  1. Shield → GRC risk quantification high value · low lift

    Pull Shield valuations into assets + a dollar loss field on the risk register; render ALE. Closes the FAIR-lite gap and lights up a genuine differentiator using assets IA already owns.

  2. User Access Review module true table stakes

    Recurring access-certification campaigns: pull entitlements from Entra/Zitadel, route to managers, capture attestations as evidence for SOC 2 CC6 / ISO A.5.18. The one clear must-fix.

  3. Device-compliance evidence bridge verify + wire

    Normalize RMM/Overwatch endpoint posture (encryption, lock, OS, AV) into control evidence so "we monitor devices" becomes "here's the audit-grade proof."

  4. AI governance depth get ahead of table stakes

    Build on the AISystem inventory + ISO 42001: model/risk cards and an AI risk-assessment workflow. A differentiator today, expected within ~12 months.

  5. Integration long-tail opportunistic

    Add connectors by client demand (Jira/Slack/cloud-config/MDM/Okta first). Not urgent given the owned-stack model — but it defuses the "does it connect to my stack?" objection.


Execution

Build roadmap — closing the list in leverage order

Three tracks. Track 1 is the highest-value, lowest-lift move (and turns on a differentiator); Track 2 is the one true table-stakes fix; Track 3 mops up the partials. Every step names the actual app it touches.

Track 1 · Shield → GRC wiring + dollar risk quantification  ~1–2 wks · highest leverage
1 · Red exposes valuations
Build
Add a per-tenant Shield valuation summary endpoint in Argos Red (record counts by type + $ low/expected/high). Red already holds the scan data.
2 · GRC pulls + values assets
Build
Extend integrations/argos_red_compliance.py to pull valuations; upsert apps/assets with monetary value + record-type breakdown.
3 · Quantify the register
Build
Migration on apps/risks: add loss_magnitude_{low,expected,high}, threat_frequency, computed ale; link Risk→Asset; render a $ heatmap/tornado in risk_matrices.
4 · Evidence + coverage gap
Build
File each scan as data-inventory evidence (apps/evidence) mapped to CIS 3, ISO A.5.9/5.12, PCI CHD, HIPAA ePHI. Cross with Cyber Insurance Readiness → "$ liability − coverage" gap tile.
Track 2 · User Access Reviews  ~2–3 wks · true table stakes
1 · New app + models
Build
New apps/access_reviews: AccessReviewCampaign (scope/cadence/due), AccessReviewItem (user × system × entitlement × risk), ReviewDecision (keep/revoke/flag + reviewer).
2 · Entitlement pull
Build
Reuse m365_graph (Entra roles/groups), Zitadel, Argos Verify to populate items; map users→managers via HRIS/identity.
3 · Attest + evidence
Build
Manager review UI + reminders (reuse the training/questionnaire cadence engine); completed campaign auto-emits evidence for SOC 2 CC6.2/6.3, ISO A.5.18, CIS 5/6. Quarterly Celery schedule.
Track 3 · Close the partials  parallel / by demand
AI governance depth
~1–2 wks
On ai_risk+ISO 42001: add AIModelCard + AIRiskAssessment (run through the existing assessments engine with a NIST AI RMF / ISO 42001 template); map to ISO 42001 Annex A.
Device-compliance evidence
~1 wk
Extend ninjarmm.py (+ Overwatch/Agent) to emit per-device posture (BitLocker/FileVault, screen-lock, OS build, AV/EDR health) → normalize to evidence, map to CIS 1/4/10, SOC 2 CC6, encryption. Data likely already available.
Integration long-tail
2–4 d each
Framework exists (connectors/sources/). Add by sales signal: Okta → Jira → Slack → cloud config (AWS/Azure/GCP) → MDM (Jamf/Intune/Kandji) → CrowdStrike. Not all at once.
Data hygiene
1 line
Dedupe the double-loaded CIS v8.1 framework so coverage math is exact.

Secured by IA