Skip to main content

Contacts & Points of Contact

Infracast keeps a per-workspace registry of named responsible parties โ€” the people an assessor, auditor or Authorizing Official needs to reach. Those names are rendered directly into every generated document.

Why this mattersโ€‹

FedRAMP SSP templates and NIST 800-18 both require named, reachable responsible parties. An authorization package whose stakeholder table reads [Name] is not submittable. Recording contacts once, in one place, means every SSP, SAP, FIPS 199 categorization and DPIA you generate carries the right people automatically.

Contacts are not platform usersโ€‹

This is the distinction worth internalising:

  • Team Members (Settings โ†’ Team Members) are platform users. They have logins, passwords, MFA and RBAC roles.
  • Contacts (Settings โ†’ Contacts) are responsible parties. They are named in your compliance documentation.

An Authorizing Official or Data Protection Officer frequently has no Infracast login at all, yet must still appear by name in your SSP. The two lists overlap but are not the same, so Infracast keeps them separate.

Rolesโ€‹

RoleAppears in
Business Point of ContactDocument cover page, SSP ยง3, SAP ยง8
Technical Point of ContactDocument cover page, SSP ยง3, SAP ยง8
System OwnerSSP ยง3, SAP ยง8, FIPS 199, NIST 800-30 Risk Assessment
Information System Security Officer (ISSO)SSP ยง3, SAP ยง8
Information System Security Manager (ISSM)SSP ยง3
Authorizing OfficialSSP ยง3, SAP ยง8
AO Designated RepresentativeSSP ยง3
Data StewardFIPS 199
Data Protection Officer (DPO)GDPR DPIA
Incident Response ContactIncident response documentation
Assessment Team LeadSAP ยง8

Each role can hold multiple contacts; flag one as Primary and that is the one rendered into documents.

Adding a contactโ€‹

  1. Go to Settings โ†’ Contacts.
  2. Click Add Contact.
  3. Pick a role, enter name (required), and optionally title, organization, email and phone.
  4. Tick Primary contact for this role if this is the person documents should name.

Infracast warns you when System Owner, ISSO or Authorizing Official are still undesignated, since those three block a FedRAMP submission.

What happens when a role is emptyโ€‹

Documents render "Not designated โ€” add in Settings โ†’ Contacts".

That is deliberate. Infracast will not emit a blank cell or a plausible-looking placeholder for a responsible party who does not exist, because a reader cannot tell the difference between "nobody filled this in" and "intentionally left empty". A visible gap is safer than an invisible one.

Precedenceโ€‹

If you have previously answered questionnaire questions such as "System Owner", those answers still work. The resolution order is:

  1. Contacts registry (Settings โ†’ Contacts)
  2. Questionnaire answer
  3. TBD

The registry wins because it is structured data you maintain, while questionnaire answers are captured once during an assessment and rarely revisited.

Scopeโ€‹

Contacts are workspace-scoped. Different workspaces โ€” for example a production enclave and a development environment with different owners โ€” maintain their own registries. Switching workspace switches the contacts your documents will use.