Continuous vetting has changed personnel security at its core. In the old model, an adjudicator reviewed a complete report of investigation, made a determination, and often didn’t look at the case again for five years. Now risk information arrives in pieces, through Continuous Vetting Action Reports (CVARs) generated by seven record checks that run around the clock.
“Workforce risk is no longer arriving in one package. It develops over time,” Aarti Smith, CEO of Chainbridge Solutions, said on a recent episode of ClearedCast.
Smith called continuous vetting the right policy direction, but said agencies face a “continuous vetting gap.” That’s the space between receiving an alert and being able to manage it well. Roster management, enrollment and unenrollment, alert retrieval, and triage still depend heavily on manual work. Multi-affiliation makes it harder: when one person supports several agencies, only the enrolling agency receives that person’s CVARs.
Smith described DCSA’s consolidation of functions into DISS as a shared services hub as “a wonderful step forward.” But pulling records manually, one person at a time, still limits efficiency. API integrations would let agency case management systems exchange data directly.
The stakes will rise as Trusted Workforce 2.0 expands to public trust and suitability populations. “God forbid, significant high-risk alerts are missed. That can be devastating,” Smith said.
She said modern personnel security systems should automate CVAR triage, apply risk weights so high-risk alerts rise to the top, provide real-time dashboards, and integrate with HR, identity management, and insider threat systems. Applied AI can gather and summarize information from separate systems, but the adjudicator stays the decision-maker.
Smith also urged agencies not to overlook applicants. Secure portals keep personal information out of email, cut down on errors, and give new hires a better first impression.



