A fact-based audit of the Argos GRC codebase (50+ apps, 19 frameworks) against the table-stakes and differentiators of Vanta, Drata, Secureframe, Cynomi, AuditBoard and peers. Verdict: the platform is materially more complete than assumed. Only a handful of genuine gaps remain — and one of them is closed by a tool IA already owns.
Nearly every capability a modern GRC platform is judged on already exists as a first-class app — risk register, questionnaire automation, auditor collaboration, assessments, maturity, BCP/DR, TPRM, and an unusually current framework set (CMMC 2.0, DORA, ISO 42001, PCI v4.0). The remaining work is narrow and high-leverage, not foundational.
risks: Risk / Treatment / Status / Library / Comment, plus risk_matrices for the heatmap. This was my #1 suspected gap — it's real and first-class.questionnaire: AnswerLibraryEntry + Session / Item / Settings — auto-answering DDQ / SIG / CAIQ from a reusable answer library.auditor: AuditorAssignment + AuditorEvidenceRequest — a scoped evidence-request (PBC) tracker for external auditors.assessments (templates / sections / questions / responses / evidence) + maturity scoring.audit workflow. A capability most competitors don't have at all.findings, exceptions (SecurityException = risk acceptance), gap (CoverageSnapshot).tprm + vendors + trust (Argos Trust, a TITAN/SecurityScorecard peer) + public Trust Center.bcp, incidents (NCISS scoring), vciso + portfolio + time-tracking → Service billing.sbom, CSPM, pentest, attack (MITRE ATT&CK), ransomsim, ma_diligence, ir_retainer, raci, privacy, perimeters — well beyond baseline GRC.ai_risk has an AISystem inventory and ISO 42001 is loaded, but model cards + a full AI risk-assessment workflow would make it a headline module as this becomes table stakes within a year.Minor data hygiene: CIS v8.1 is loaded twice (duplicate framework) — distorts coverage math; dedupe.
Argos Shield (the "Shield Scout" scanner) walks a device or environment, classifies and counts sensitive records, and prices them into a real dollar liability — PHI ≈ $408, PCI ≈ $295, PII ≈ $180, CUI ≈ $350, Creds ≈ $150, IP ≈ $1,000 per record (with low/expected/high ranges). It's IA's Actifile wedge. That output is precisely the quantitative input GRC's qualitative risk register lacks.
Turns "High/Med/Low" into "$X at risk" — the board-and-insurer language auditors and CFOs actually use.
Record counts (PHI/PCI/PII/CUI) satisfy data-classification & inventory controls: CIS 3, ISO A.5.9/5.12, PCI CHD discovery, HIPAA ePHI, GDPR/CCPA mapping.
Vanta/Drata don't quantify $ risk from real data; FAIR vendors don't own the scanner or the GRC. IA owns all three.
Wiring: Shield already has a planned --upload to /shield/agent/scan; GRC already integrates Argos Red (argos_red_compliance.py). Add a Shield-valuation pull → populate assets value + a $ field on the risk register + evidence for data-inventory controls.
Pull Shield valuations into assets + a dollar loss field on the risk register; render ALE. Closes the FAIR-lite gap and lights up a genuine differentiator using assets IA already owns.
Recurring access-certification campaigns: pull entitlements from Entra/Zitadel, route to managers, capture attestations as evidence for SOC 2 CC6 / ISO A.5.18. The one clear must-fix.
Normalize RMM/Overwatch endpoint posture (encryption, lock, OS, AV) into control evidence so "we monitor devices" becomes "here's the audit-grade proof."
Build on the AISystem inventory + ISO 42001: model/risk cards and an AI risk-assessment workflow. A differentiator today, expected within ~12 months.
Add connectors by client demand (Jira/Slack/cloud-config/MDM/Okta first). Not urgent given the owned-stack model — but it defuses the "does it connect to my stack?" objection.
Three tracks. Track 1 is the highest-value, lowest-lift move (and turns on a differentiator); Track 2 is the one true table-stakes fix; Track 3 mops up the partials. Every step names the actual app it touches.
integrations/argos_red_compliance.py to pull valuations; upsert apps/assets with monetary value + record-type breakdown.apps/risks: add loss_magnitude_{low,expected,high}, threat_frequency, computed ale; link Risk→Asset; render a $ heatmap/tornado in risk_matrices.apps/evidence) mapped to CIS 3, ISO A.5.9/5.12, PCI CHD, HIPAA ePHI. Cross with Cyber Insurance Readiness → "$ liability − coverage" gap tile.apps/access_reviews: AccessReviewCampaign (scope/cadence/due), AccessReviewItem (user × system × entitlement × risk), ReviewDecision (keep/revoke/flag + reviewer).m365_graph (Entra roles/groups), Zitadel, Argos Verify to populate items; map users→managers via HRIS/identity.ai_risk+ISO 42001: add AIModelCard + AIRiskAssessment (run through the existing assessments engine with a NIST AI RMF / ISO 42001 template); map to ISO 42001 Annex A.ninjarmm.py (+ Overwatch/Agent) to emit per-device posture (BitLocker/FileVault, screen-lock, OS build, AV/EDR health) → normalize to evidence, map to CIS 1/4/10, SOC 2 CC6, encryption. Data likely already available.connectors/sources/). Add by sales signal: Okta → Jira → Slack → cloud config (AWS/Azure/GCP) → MDM (Jamf/Intune/Kandji) → CrowdStrike. Not all at once.