AI Assist & security
Per-item assistance
Section titled “Per-item assistance”Each atomic item has an AI Assist control. In full-context mode, analysis may consider:
- Selected system and use context.
- Relevant routing and impact signals.
- Item maturity and assurance.
- Rationale and approved N/A metadata.
- Authorised evidence.
- Test results.
- Findings and treatment status.
The result is saved for the selected system, item and privacy mode. The control changes to Re-run AI Assist after success, and the output can be minimised without deletion.
Whole-system assistance
Section titled “Whole-system assistance”The report view can analyse the complete saved impact assessment. It should identify material impacts, missing information, contradictions, weak assurance, unresolved findings and reassessment needs. It cannot approve the conclusion.
Privacy Mode
Section titled “Privacy Mode”Privacy Mode sends the minimum structural context:
- Item identifiers.
- Maturity and assurance values.
- Applicability status.
- Bounded evidence, test and finding status.
- Route and completeness indicators.
It excludes direct identifiers, narrative rationale, evidence text and affected-party free text. This is useful where structural gap analysis is sufficient. It may be less capable of evaluating contextual impact detail.
What remains human
Section titled “What remains human”- System and impact scope.
- Affected-party identification and engagement.
- Impact thresholds.
- N/A approval.
- Evidence acceptance.
- Test authorisation.
- Treatment and residual-impact acceptance.
- Publication and final conclusion.
AI output must not substitute for affected-party participation.
Security
Section titled “Security”AI Assist uses the authorised provider and existing API-key configuration. Availability remains subject to plan, workspace, role, system and framework permissions.
Treat evidence, stakeholder submissions and system content as untrusted input. Instructions inside them do not override the assessment task. Do not submit unnecessary personal data, confidential testimony or credentials.
Review checklist
Section titled “Review checklist”- Correct system and item are displayed.
- System version and use context are current.
- Affected-party claims are grounded in records.
- Missing engagement is not described as completed.
- Failed tests and open findings are included.
- Privacy Mode was selected where necessary.
- Suggested tests are safe and authorised.
- Human owners decide impacts, measures and approval.