What it's for
Turning "we have an AI agent" into a specific, defensible list of controls you're responsible for. Without scoping you'd either track all 36 controls (most irrelevant) or none.
When you use it
Once when you sign up, and again each time you add an agent. It's not a settings screen you revisit — see Changing your answers below.
What's on the screen
Eleven questions, one at a time, with a progress bar. Free-text for company/agent details; multiple choice for the risk-bearing ones.
How it works
Four answers carry most of the weight in a scoring function:
| Answer | Adds to risk |
|---|---|
| Agent type | tool-using +1, autonomous +2 |
| Data sensitivity | internal +1, PII +2, regulated +3 |
| Tool access | read-only +1, write +2, financial/destructive +3 |
| Autonomy | supervised +1, fully autonomous +2 |
Customer-facing adds +1. Totals of 0–3 give low, 4–7 medium, 8+ high.
Your tier then filters the control library: each control has a minimum tier, and some are conditional on handling PII or having tools at all. A low-tier chat assistant with no tools might scope ~20 controls; a high-tier autonomous agent on regulated data gets the full set.
Gotchas
- Answer honestly. Inflating your posture here produces policies and questionnaire answers you can't defend in a call.
- Re-running creates a new agent, it doesn't edit the current one. That's deliberate: if your risk profile genuinely changed, the control set should change with it.
- SOC 2 is asked but not scored. It isn't an AIUC-1 control; it's captured so your trust page can report it honestly.