For Prime · The fourth seat

Your subcontractors’ readiness after the certificate, on their grant.

One roster per prime: the subcontractors you name, each on a named award. Each subcontractor decides from its own page whether you see its readiness posture summary, and can withdraw at any time. Nothing is shared by default, and nothing is shared because you asked.

The question this seat answers

“How do I know the suppliers I rely on remain compliant after they gave me their certification or SPRS information?”

A certificate or an SPRS entry records a position on the day it was made; the affirmation of continuing compliance comes once a year (32 CFR 170.22). Between those dates, a subcontractor that measures with Enclave AI™ keeps a recorded readiness state in its own workspace, refreshed on a stated schedule: connected cloud sources are re-scanned about every seven days, a complete Level 1 cycle runs every 30 days, and the Level 2 package is refreshed on the subcontractor’s subscription tier cycle.

For each subcontractor that allowed it, your view shows that recorded state as of its last measurement, with its age in days, so you can see how current it is. It is a recurring record, not a live feed. The affirmation stays with each subcontractor’s Affirming Official.

How it works

  1. You name a subcontractor on an award. Company name, the contact email of the person who decides for that company, and the award identifier the relationship flows from. The award identifier is required: a request that cannot name its contract is one the subcontractor has no way to evaluate. The same subcontractor on two of your awards is two named relationships. A seat holds up to 500 named subcontractors. You name each one with the form on your dashboard, where each named subcontractor also has Re-send and Remove buttons; the same actions are available as JSON requests to your seat’s roster address.
  2. We email the subcontractor a link to its own page. You never receive that link, and you cannot make the decision for the subcontractor. The email names your company and the award, says that nothing is shared until the subcontractor allows it, and tells the subcontractor we cannot verify the award on its behalf. You can re-send the notice; you learn only whether it sent.
  3. The subcontractor decides on its own page. Two switches must both be on before you see anything: its decision for your company on that page, and the oversight-sharing switch in its own Enclave AI™ workspace. The page tells the subcontractor when the second switch is off.
  4. A subcontractor that has not measured has nothing to share. Its page says so and offers the free gap check. It cannot allow a view of a posture that does not exist.

What you see

Your roster, with the denominator stated in words, for example: “3 of 5 named subcontractors have consented; 2 have not.” Nothing is known about the posture of a subcontractor that has not consented, and every total on the view covers the consented set only. A subcontractor you remove from the roster stays in that set until it withdraws its consent (see Withdrawal and removal below).

The dashboard re-reads the recorded state every 5 minutes while it is open. That re-reads the record; it does not re-measure anything. The same data is available as a machine-readable status.json feed beside your dashboard link.

See the five seats side by side →

What you do not see

Withdrawal and removal

Consent is per prime, not per award. A subcontractor that withdraws closes your view across every award you named it on, on your next load. Every decision is kept as an append-only record: a change of mind is a new entry, and the earlier one stays readable.

You can remove a subcontractor from your roster. Its decision link stops working, and its own decision record is left untouched, because that record belongs to the subcontractor. Removal does not withdraw a consent the subcontractor already gave: that subcontractor’s posture stays in your contractor portfolio view, and in the totals across the consented set, until the subcontractor withdraws. With the link gone, it withdraws from its own workspace, either for your company alone or by turning its oversight disclosure off. Naming the same company on the same award again issues a new link and a new notice.

What this seat does not do

It does not assess, certify or affirm. It does not verify award identifiers, review your subcontract clauses, or decide whether a subcontractor may receive an award. It supports your supplier oversight; your flow-down obligations and your subcontractors’ obligations remain yours and theirs. Each subcontractor’s Affirming Official makes its affirmation decision; assessments are conducted by the subcontractor itself or by an independent Cyber AB-authorized C3PAO.

One record, five seats

The prime seat is one of five views of the same recorded state: the contractor’s own workspace, its MSP, MSSP or ESP, its C3PAO, its prime, and an authorized program office or agency. Each seat sees only what the contractor granted it. That same recorded state supports self-assessment, C3PAO assessment, delta assessment, prime oversight and government verification without recreating the compliance record for every audience.

Cost

Enclave AI is priced by compliance function and agent workload, never by seat. Any price for the prime view is published here before it applies. Each subcontractor’s own subscription pays for the agents’ work on its environment; see pricing, Level 1 and Level 2.

Set up a prime seat

The dashboard link goes to the contact address after it is confirmed. A business email address is needed (free-mail addresses are refused), and each email domain holds one prime seat. For its first 14 days a new seat can send at most 3 subcontractor notices in any 24 hours. A seat whose link was lost can have it sent to its contact address again from the help page. No call is needed.

See the five seats → For MSP / MSSP / ESP →
Read more: CMMC Level 2, CMMC Level 1, the sample report, and the C3PAO seat.