Skip to content

AI Consultant

The AI Consultant is an in-platform advisory tool that analyses and drafts from your live assessment records, the system context, framework scores, evidence entries, risk items and findings already recorded. It draws on what is in the workspace, not on general knowledge alone, so its output is specific to the governance situation in front of it.

Every consultation reads the current assessment at the moment of the query. That grounding is both the Consultant’s strength and its limit:

  • When the record is detailed, scored controls with notes, evidence linked to controls, named risk owners, a specific system description, the Consultant produces directly relevant analysis.
  • When the record is thin, the output is generic, because there is nothing specific to draw from.

The practical consequence: the Consultant cannot compensate for an incomplete assessment. The screen shows a Workspace context included manifest with the current workspace and record counts for systems, intake, risks, evidence, tests, findings and agentic governance. Use that manifest to check what can ground the answer. A zero count or unavailable module is a limitation, even when the answer reads fluently. Treat the output as a drafting accelerator for well-prepared records, not as authoritative governance and not as a substitute for the work that produces the record.

The Consultant offers focused modes, each oriented to a specific governance activity. Matching the mode to the question produces sharper output than a general query:

ModeWhat it produces
Governance ReviewOwnership, accountability, approval gaps and operating-model weaknesses.
Risk ReviewRisk statements, exposure summaries and treatment options from the assessment data.
Evidence ReviewWhat evidence is present, what is missing, and which requests would strengthen assurance.
Policy SupportGenerates or improves policy wording from the governance record.
Report SupportReport-ready narrative.
Agentic AI ReviewScoped to agentic governance: agent controls, approval gates, ATF readiness and Gateway records.
Board SummaryThe assessment distilled into executive priorities and decisions needed.
Remediation PlanningSequenced actions with owners, dependencies and closure tests.
General AdviceOpen-ended questions, broader output than the task-specific modes.

The selected output type controls the intended artefact, for example Advisory Note, Risk Summary, Evidence Gap Review, Agentic AI Control Review, Remediation Plan, Board Briefing, Policy Improvement Note, Report Narrative or Executive Summary. Mode controls the analytical lens; output type controls the form of the draft.

The Consultant uses permitted workspace records, notes and other free text so that it can answer workspace-specific questions. The framework scores-only privacy mode does not narrow Consultant context. If scores-only mode is enabled, the Consultant displays a warning explaining this difference.

Before sending a question:

  1. Check the Workspace context included manifest.
  2. Confirm that the selected workspace is the intended one.
  3. Do not paste secrets, credentials or unnecessary personal data into the question.
  4. Do not use the Consultant if the permitted workspace context should not be sent to the configured model provider; use the relevant framework’s scores-only AI Assist instead.
  5. Review the provider and organisational data-handling terms that govern your deployment.

The Consultant is held to the same controls as every other AI feature in Gamut:

  • Server-side only. Prompts and responses are proxied server-side; model provider keys are never exposed to the browser. See AI assistance & data handling.
  • Entitlement and permission gated. It requires both the ai_chat entitlement and the AI Consultant permission, an Advanced-tier capability. See Plans & entitlements and Users & roles.
  • Usage-metered. AI calls count against the plan’s daily and monthly quotas.
  • Tenant-scoped. It only ever sees the records of the workspace you are in.
  • Visible context boundary. The screen identifies the categories and record counts available to the consultation before the question is sent.
  • Complete the assessment first. A half-finished assessment leaves the Consultant blind to large parts of the picture, and the output will sound more complete than it is.
  • Pick the right mode. “What are the ownership gaps here?” belongs in Governance Review, not General Advice.
  • Treat output as a draft. Review and own everything it produces before it becomes a governance artefact.