Contacts & Points of Contact
Infracast keeps a per-workspace registry of named responsible parties โ the people an assessor, auditor or Authorizing Official needs to reach. Those names are rendered directly into every generated document.
Why this mattersโ
FedRAMP SSP templates and NIST 800-18 both require named, reachable responsible
parties. An authorization package whose stakeholder table reads [Name] is not
submittable. Recording contacts once, in one place, means every SSP, SAP, FIPS 199
categorization and DPIA you generate carries the right people automatically.
Contacts are not platform usersโ
This is the distinction worth internalising:
- Team Members (Settings โ Team Members) are platform users. They have logins, passwords, MFA and RBAC roles.
- Contacts (Settings โ Contacts) are responsible parties. They are named in your compliance documentation.
An Authorizing Official or Data Protection Officer frequently has no Infracast login at all, yet must still appear by name in your SSP. The two lists overlap but are not the same, so Infracast keeps them separate.
Rolesโ
| Role | Appears in |
|---|---|
| Business Point of Contact | Document cover page, SSP ยง3, SAP ยง8 |
| Technical Point of Contact | Document cover page, SSP ยง3, SAP ยง8 |
| System Owner | SSP ยง3, SAP ยง8, FIPS 199, NIST 800-30 Risk Assessment |
| Information System Security Officer (ISSO) | SSP ยง3, SAP ยง8 |
| Information System Security Manager (ISSM) | SSP ยง3 |
| Authorizing Official | SSP ยง3, SAP ยง8 |
| AO Designated Representative | SSP ยง3 |
| Data Steward | FIPS 199 |
| Data Protection Officer (DPO) | GDPR DPIA |
| Incident Response Contact | Incident response documentation |
| Assessment Team Lead | SAP ยง8 |
Each role can hold multiple contacts; flag one as Primary and that is the one rendered into documents.
Adding a contactโ
- Go to Settings โ Contacts.
- Click Add Contact.
- Pick a role, enter name (required), and optionally title, organization, email and phone.
- Tick Primary contact for this role if this is the person documents should name.
Infracast warns you when System Owner, ISSO or Authorizing Official are still undesignated, since those three block a FedRAMP submission.
What happens when a role is emptyโ
Documents render "Not designated โ add in Settings โ Contacts".
That is deliberate. Infracast will not emit a blank cell or a plausible-looking placeholder for a responsible party who does not exist, because a reader cannot tell the difference between "nobody filled this in" and "intentionally left empty". A visible gap is safer than an invisible one.
Precedenceโ
If you have previously answered questionnaire questions such as "System Owner", those answers still work. The resolution order is:
- Contacts registry (Settings โ Contacts)
- Questionnaire answer
TBD
The registry wins because it is structured data you maintain, while questionnaire answers are captured once during an assessment and rarely revisited.
Scopeโ
Contacts are workspace-scoped. Different workspaces โ for example a production enclave and a development environment with different owners โ maintain their own registries. Switching workspace switches the contacts your documents will use.