The agents
Each works inside your tenant, on your control library, against your regulatory perimeter.
None of them operates across tenants, and none trains on your data.
Regulatory Change Agent
Draft, human-approvedReads a published change from an authority you answer to, works out which of your controls, policies and obligations it touches, and drafts the impact assessment with owners already named.
- Monitors NCA, SAMA, SDAIA, CBUAE, CBO, NCSA, CBB, CITRA, ICO, FCA and the standards bodies
- Produces a diff against the version of the requirement you last assessed
- Routes to the accountable owner with a due date, not to a shared mailbox
- Flags where wording has diverged enough that one control test will no longer satisfy both regimes
Nothing publishes to your control library until a named owner approves the assessment.
Control Mapping Agent
Draft, human-approvedProposes how a newly loaded framework or market pack maps onto the control set you already operate, so adding a jurisdiction is a mapping exercise rather than a second programme.
- Suggests many-to-many mappings with a confidence position and the reasoning behind each
- Identifies controls that would satisfy several regimes from a single test
- Separates genuine equivalence from superficial similarity, and says which is which
- Highlights obligations with no matching control — the gaps worth knowing about early
Mappings are proposals. A control owner accepts, amends or rejects each one.
Evidence Agent
Assistive, continuousChecks what has been submitted against what the control actually requires, and returns what is missing before an auditor does.
- Reads evidence against the control's stated requirement, not just its presence
- Detects stale evidence, wrong period, wrong system, wrong scope
- Chases the owner on the schedule, with escalation when it ages
- Distinguishes machine-collected evidence from asserted evidence in every pack
It can reject evidence as incomplete. It cannot accept evidence as sufficient — that is a human decision.
Scenario Calibration Agent
Draft, human-approvedProposes Open FAIR parameters for a loss scenario from your incident history, asset criticality and comparable sector loss data — then argues with the estimators when a range looks wrong.
- Suggests minimum, most likely and maximum for each factor, with the evidence for each
- Flags estimates that sit outside what the supporting evidence will bear
- Surfaces where the group is converging too quickly, which usually means anchoring
- Re-runs affected scenarios when a control changes or an incident is recorded
The calibrated estimators set the numbers. The agent supplies the starting position and the challenge.
Third-Party Agent
Assistive, continuousRuns the supplier assessment cycle that otherwise consumes a team: tiering, questionnaires, evidence review, clause tracking and reassessment scheduling.
- Tiers new suppliers from contract, data exposure and service dependency
- Reviews returned questionnaires and marks the answers that do not match the evidence supplied
- Tracks clause expiry, right-to-audit position and sub-processor change notifications
- Recalculates portfolio concentration whenever the supplier master changes
Supplier risk acceptance and offboarding decisions stay with the contract owner.
Narrative Agent
Draft, human-approvedWrites the first draft of a board paper, a post-incident review, a regulator response or a customer security questionnaire — from the live record, with every figure traceable.
- Assembles board packs on the committee's cadence from current platform data
- Drafts post-incident reviews from the incident timeline and the controls it exercised
- Answers customer due-diligence questionnaires from your control and evidence base
- Writes in your organisation's register of terms, not in vendor language
Nothing reaches a board, a regulator or a customer without a named person approving it.
Privacy Operations Agent
Assistive, continuousKeeps the privacy record current across several regimes at once — the work that decays fastest when it is done by hand.
- Proposes records of processing entries from system and integration discovery
- Triages DPIA triggers from the change pipeline before deployment, not after
- Applies the governing regime's clock and conditions to each rights request
- Maintains the transfer register as systems, suppliers and hosting positions change
The DPO approves every assessment and every response to a data subject or a regulator.
Resilience Agent
Assistive, continuousWatches the dependency picture behind your important business services and tells you when it has quietly moved.
- Recalculates single points of failure when the asset or supplier master changes
- Flags services drifting toward their impact tolerance before a test does
- Proposes severe but plausible scenarios drawn from the same library used for quantification
- Tracks plan currency and exercise overdue positions against the agreed schedule
Impact tolerances and recovery strategies are approved by the service owner and the board.