Features, organised by obligation
Everything you need to run a grant-funded program
Tasks, milestones, timelines, a board, status reports and a team view — the project management you would expect — plus the award, subrecipient, evidence and retention records that 2 CFR 200 asks for. Each section below states the obligation, how Kharazm satisfies it, and what the person reviewing you actually sees.
How to read this page. Kharazm does not interpret the Uniform Guidance for you and does not certify your compliance. It gives each obligation somewhere to live so the record exists when a monitor, an auditor or a program officer asks. Confirm your own obligations with your awarding agency and your auditor.
2 CFR 200.329
Immutable performance reports
The requirement
Recipients must monitor their programme and report performance for defined periods — typically an SF-PPR, an RPPR or an agency-specific narrative on a quarterly, semi-annual or annual cadence. The report describes a closed period and is expected to reflect what was known and true at the time it was submitted.
How Kharazm satisfies it
You draft the report inside the period it covers, then publish it. Publication writes a fixed, versioned snapshot: the narrative, the health rating, the period boundaries, the publishing user and the timestamp, plus a frozen copy of the evidence index as it stood. There is no edit path on a published report. A correction is a new version; the earlier version remains readable.
What the auditor sees
A numbered series of reports for the award, each with its period, its author and its publication time — and the ability to open version 1 after version 3 exists. The absence of an edit path is the point: there is no way for the organisation to have quietly revised what it said last spring.
2 CFR 200.332
Subrecipient risk assessment and monitoring
The requirement
A pass-through entity must evaluate each subrecipient's risk of non-compliance, apply monitoring proportionate to that risk, review findings, issue management decisions, and ensure corrective action. The evaluation has to be documented — an unwritten judgement is not testable and therefore does not count.
How Kharazm satisfies it
Each subrecipient carries a legal name, UEI, subaward amount and dates, a risk level, and a written basis for that risk level which the form requires rather than suggests. The monitoring plan follows from the risk level. Monitoring events — desk reviews, site visits, invoice reviews, audit reviews, technical assistance — are logged with a date, a named performer, findings and corrective action, and are closed with a written resolution.
What the auditor sees
A monitoring log per subrecipient showing risk level, the reasoning behind it, what monitoring was planned, what actually happened and when, and how each finding was resolved. Gaps show as gaps rather than being omitted, which is the honest and more useful behaviour while there is still time to close them.
Supports 2 CFR 200.303 and management decisions
Decision records with written resolution
The requirement
Programme decisions that change scope, budget, schedule or approach need to be explainable later. When a monitor asks why a milestone moved or why funds were reallocated, "we discussed it in a meeting" is not a record.
How Kharazm satisfies it
The RAID register holds risks, assumptions, issues and decisions. Each carries an owner, a due date, an impact statement and — when closed — a written resolution. Closed items stay in the record rather than disappearing, and the items open during a reporting period are captured in that period's published report.
What the auditor sees
A dated register of what went wrong, who owned it, and what was decided — with names attached. This is the single artifact most often missing entirely from a reconstructed file, because it is the one thing email threads cannot be turned into after the fact.
2 CFR 200.303
Audit-log evidence of internal control
The requirement
Recipients must establish and maintain effective internal control over the award, providing reasonable assurance that it is managed in compliance with the terms and conditions — and must be able to show that the control operated, not merely that a policy exists.
How Kharazm satisfies it
Access is decided on the server from the session and membership, never from the request body — a signed-in viewer who forges a write request is rejected, and that behaviour is covered by an integration test rather than a claim. Material actions are summarised into a per-organisation audit log with actor, action and timestamp. Organisations are the tenant boundary and membership is checked before every read and write.
What the auditor sees
Four access levels with real boundaries — admin, manager, member, viewer — and a log showing who did what and when. Combined with the immutability of published reports, this answers the control question with evidence rather than assertion.
2 CFR 200.334
Retention policy and legal hold
The requirement
Financial records, supporting documents and statistical records must be retained for three years from the date of submission of the final expenditure report — longer if litigation, a claim or an audit started before that period expired.
How Kharazm satisfies it
The workspace carries a retention setting expressed in years after the final report. A legal hold can be placed on an award with a stated reason and a named person, and while it is active deletion and archival are blocked in the domain layer rather than merely hidden in the interface. Closed awards move to an archive that keeps them readable and exportable.
What the auditor sees
Records that still exist, with a stated policy for why, and evidence that the organisation cannot casually delete an award that is under hold. This is also the answer to "what happens when our grant ends" — the record outlives the programme, because it has to.
2 CFR 200.337
Scoped external access for funders and auditors
The requirement
The awarding agency, the Inspector General, the Comptroller General and the pass-through entity must have access to records pertinent to the award. In practice you also want to give a subrecipient sight of their own subaward — without exposing everything else.
How Kharazm satisfies it
An external viewer is granted read-only access scoped to a single award, optionally with an expiry date. The scope is enforced in the same server-side capability check that governs internal roles, taken from the session — not a share link that anyone holding the URL can use, and not a client-side filter.
What the auditor sees
Exactly one award: its published reports, its evidence index, its decision record and its monitoring log. Nothing from any other award, and nothing they could reach by changing an identifier in the address bar.
See it against one of your own awards
Take a 14-day trial, publish one report, and judge the record on your own material.