analystadmin
AI Copilot
Use read-only, cited assistance over authorised evidence.
Reviewed 2026-08-13Product 1.1
AI Copilot explains assessments and drafts investigation artifacts from evidence already available to the authorised user.
Copilot never changes scores, actions, review outcomes, feedback, or policy. Deterministic workflows continue when it is unavailable.
Grounding
- The server assembles a tenant-scoped evidence bundle.
- Summaries, findings, and next steps must cite evidence IDs in that bundle.
- Unknown references are removed; text left without support is withheld and listed as a limitation.
- Chart values are calculated by the backend. The model can select an offered chart and caption it, but cannot create its numbers.
Workflow
- Attach an assessment so evidence routing and available tasks are explicit.
- Choose a structured task for triage, ring investigation, false-positive review, or reporting.
- Follow each citation to its deterministic source view.
- Verify the draft before using or sharing it.
AI actions are metered per company. New generations stop when the plan limit is reached; deterministic views remain available.
Access
The deployment provider and company AI policy must be enabled. The plan must include the feature. Users need ai:use, task-specific data access, and ai:chat for conversations. The interface identifies the missing condition when generation is unavailable.
Privacy and retention
- Evidence is assembled server-side within the tenant boundary; raw event bodies, arbitrary metadata, credentials, and payment data are excluded.
- Indicators are hashed by default. A readable field requires encrypted storage policy, administrator AI opt-in, user permission, and plan entitlement.
- Conversations, evidence snapshots, and artifacts are encrypted at rest and expire according to the administrator-selected retention window.
- User-supplied text is treated as untrusted and redacted before processing. Never paste secrets.
Related: Risk Scores, Graph Explorer, and Permissions.