Skip to main content

GRC Platform Integrations

Infracast integrates with the major GRC platforms used by DoD and federal civilian agencies — eliminating manual re-entry and keeping every system in sync.

Note on Scope

This page covers federal GRC integrations (eMASS, CSAM, ServiceNow GRC module, RSA Archer). For ITSM and SIEM integrations (ServiceNow CMDB, Jira, Splunk, Slack, Teams, Okta SSO), see Integrations Overview.

eMASS (Enterprise Mission Assurance Support Service)​

eMASS is the DoD's authoritative system for RMF ATO management. Infracast pushes POA&M items and control assessment results directly to eMASS.

What Syncs​

DirectionData
Infracast → eMASSPOA&M items (create, update, close)
Infracast → eMASSControl assessment results
Infracast → eMASSMonthly scan result summaries
eMASS → InfracastManual assessment updates
eMASS → InfracastPOA&M status updates

STIG Checklist Export​

For DISA STIG-regulated systems, Infracast generates CKL files from agent configuration assessments:

infracast emass export-ckl --tenant acme --host web-01 --output web-01.ckl

Configuration​

Settings → Integrations → eMASS

- eMASS API URL
- API Key
- System ID
- Sync direction: Push only | Pull only | Bidirectional
- Schedule: On ConMon package | Daily | On change

CSAM (Cyber Security Assessment and Management)​

CSAM is the primary GRC tool for civilian federal agencies (CISA, GSA, DHS). Infracast auto-submits monthly ConMon deliverables to CSAM.

What Syncs​

DirectionData
Infracast → CSAMMonthly ConMon packages (POA&M, scan results)
Infracast → CSAMControl implementation status
Infracast → CSAMSignificant change notifications
CSAM → InfracastManual attestations

Monthly Auto-Submit​

When enabled, Infracast automatically submits the ConMon package to CSAM on the last business day of each month.

ServiceNow GRC​

Integrates with the ServiceNow GRC module (separate from the CMDB/ITSM integration).

What Syncs​

InfracastServiceNow GRC
POA&M itemRisk (sn_risk_risk)
FindingIndicator result
ControlPolicy Control (sn_compliance_control)
Evidence artifactEvidence (sn_compliance_evidence)

Configuration​

Settings → Integrations → ServiceNow GRC

- ServiceNow instance URL
- OAuth token
- GRC module scope
- Control framework mapping (NIST 800-53 → your policy framework)

RSA Archer​

Export control status and finding data to Archer's IRM content.

Export Format​

# Trigger a sync to the RSA Archer GRC integration ({platform} = rsa_archer)
POST /api/v1/tenants/{tenantID}/grc-integrations/{platform}/sync

The sync pushes control status and finding data to Archer's Data Feed Manager endpoint configured in the integration settings.

API paths corrected 2026-09-14

The previously documented export endpoint under the integrations/archer/ prefix does not exist. RSA Archer is managed through the standard GRC integration endpoints under /api/v1/tenants/{tenantID}/grc-integrations/{platform} (use rsa_archer as the platform value).

Common API Endpoints​

GRC platform integrations live under grc-integrations. {platform} is one of emass, csam, servicenow_grc, or rsa_archer.

# Configure
GET /api/v1/tenants/{tenantID}/grc-integrations
GET /api/v1/tenants/{tenantID}/grc-integrations/{platform}
PUT /api/v1/tenants/{tenantID}/grc-integrations/{platform}
DELETE /api/v1/tenants/{tenantID}/grc-integrations/{platform}

# Test a connection
POST /api/v1/tenants/{tenantID}/grc-integrations/{platform}/test

# Trigger sync
POST /api/v1/tenants/{tenantID}/grc-integrations/{platform}/sync
POST /api/v1/tenants/{tenantID}/grc-integrations/sync-all

# Sync history
GET /api/v1/tenants/{tenantID}/grc-integrations/{platform}/logs
Path corrected 2026-09-14

These endpoints were previously documented here as /integrations/{type}/..., which does not exist — those calls would have returned 404. The correct prefix is /grc-integrations/, and the platform identifiers are the exact values listed above. There is no separate /status endpoint; use /logs for sync history.

Security​

  • All credentials stored encrypted (AES-256-GCM) in Postgres
  • API responses redact secrets — credentials are write-only after initial save
  • Failed syncs retry up to 3× with exponential backoff
  • Persistent failures generate in-app alert + optional email notification

Availability​

IntegrationTier Required
eMASS pushEnterprise Pro / Gov
eMASS bidirectionalGov
CSAM pushEnterprise Pro / Gov
CSAM auto-submitGov
ServiceNow GRCEnterprise Pro / Gov
RSA ArcherEnterprise Pro / Gov