AI Assist & privacy
ATF AI Assist is placed beside each canonical requirement because the useful question is requirement-specific:
What does the current evidence say about this requirement for this named agent and target level?
There is no unscoped overview analysis that can substitute for the 25 decisions.
What full-context analysis may consider
Section titled “What full-context analysis may consider”- Selected agent identity, purpose and capability scope.
- Current and target ATF levels.
- The requirement’s MUST, SHOULD or MAY status at the target.
- Recorded result and implementation depth.
- Agent-specific rationale.
- Authorised linked evidence.
- Test status and results.
- Open findings and relevant incidents.
- Promotion-gate context.
The provider does not receive unrelated agents’ assessment records.
Privacy Mode
Section titled “Privacy Mode”Select Privacy Mode next to the AI Assist control when the assessment can be analysed without free text or direct identifiers. In this mode, the request is reduced to the minimum structural state, such as:
- Requirement identifier and target-level obligation.
- Current result and depth.
- Evidence, test and finding counts or bounded status.
- Promotion-state indicators.
- Completeness and contradiction signals.
Agent names, narrative rationale, free-text evidence content and other direct identifiers are excluded. Privacy Mode reduces data disclosure but may produce a less specific answer.
The mode applies to the request being run. Confirm its state before each analysis.
Output behaviour
Section titled “Output behaviour”- Run AI Assist creates a requirement-specific analysis.
- After a successful run, the control changes to Re-run AI Assist.
- The saved result remains associated with the selected agent, requirement and privacy mode.
- Minimise collapses the output without deleting it.
- Switching agent changes the scope; a result for one agent is not presented as another’s analysis.
What the model should return
Section titled “What the model should return”Useful output identifies:
- The assessed agent and requirement.
- Whether information is sufficient.
- The target-level obligation.
- Evidence-supported strengths.
- Missing facts or evidence.
- Contradictions and adverse findings.
- A safe proposed test.
- Residual uncertainty.
- A draft recommendation for human review.
Security and accountability
Section titled “Security and accountability”AI Assist uses the authorised provider and existing API-key configuration available to the user. Access remains subject to the user’s workspace, role, plan and framework permissions.
The model cannot:
- Change the result or implementation depth.
- Approve a SHOULD exception.
- Accept evidence.
- Mark a test passed.
- Close a finding.
- Pass a promotion gate.
- Promote or demote the agent.
- Accept residual risk.
Treat agent descriptions, retrieved content, logs and evidence as untrusted model input. Instructions inside those records are data, not authority.
Human review checklist
Section titled “Human review checklist”- Correct agent and requirement are displayed.
- Target level and normative status are correct.
- Every cited record exists for that agent.
- Failed tests, incidents and findings are not omitted.
- Proposed tests are authorised and non-destructive.
- Privacy Mode was used where needed.
- The recommendation does not exceed the evidence.
- Promotion and risk decisions remain human-owned.