Run the wizard
On first sign-in you land on the scoping wizard. It asks eleven questions. Answer them honestly — overstating your posture here produces policies and answers you can't defend later.
The questions that most affect your outcome:
- Agent type — chat assistant, RAG assistant, tool-using agent, or autonomous agent
- Data sensitivity — public, internal, customer PII, or regulated (health, financial, minors)
- Tool access — none, read-only, write actions, or financial/destructive
- Autonomy — human approves each action, supervised, or fully autonomous
- SOC 2 status — not part of AIUC-1, but buyers treat it as the floor, so Veriflow reports it honestly
What happens when you finish
Veriflow computes a risk tier (low / medium / high) from your answers, then selects the controls that apply. A chat-only assistant with no tools doesn't get tool-permission controls; an agent touching regulated data picks up the regulated-data handling control.
You'll land on the Overview with a scoped checklist — typically 20–36 controls out of the full library, not all of them.
Adding more agents
Use the agent dropdown in the sidebar → Add another agent. Each agent gets its own risk tier, control set, statuses, and evidence. Multiple agents require the Scale plan.
Changing your answers later
Re-running the wizard creates a new agent rather than editing the existing one. If your agent's risk profile genuinely changed (you added write-access tools, say), creating a new agent and retiring the old one is the honest move — the control set should change with it.