← Help & guides
Every module explained4 min read

Module: Scoping wizard

The eleven questions that decide your risk tier and which controls you're held to.

Open this module →

What it's for

Turning "we have an AI agent" into a specific, defensible list of controls you're responsible for. Without scoping you'd either track all 36 controls (most irrelevant) or none.

When you use it

Once when you sign up, and again each time you add an agent. It's not a settings screen you revisit — see Changing your answers below.

What's on the screen

Eleven questions, one at a time, with a progress bar. Free-text for company/agent details; multiple choice for the risk-bearing ones.

How it works

Four answers carry most of the weight in a scoring function:

Answer Adds to risk
Agent type tool-using +1, autonomous +2
Data sensitivity internal +1, PII +2, regulated +3
Tool access read-only +1, write +2, financial/destructive +3
Autonomy supervised +1, fully autonomous +2

Customer-facing adds +1. Totals of 0–3 give low, 4–7 medium, 8+ high.

Your tier then filters the control library: each control has a minimum tier, and some are conditional on handling PII or having tools at all. A low-tier chat assistant with no tools might scope ~20 controls; a high-tier autonomous agent on regulated data gets the full set.

Gotchas

  • Answer honestly. Inflating your posture here produces policies and questionnaire answers you can't defend in a call.
  • Re-running creates a new agent, it doesn't edit the current one. That's deliberate: if your risk profile genuinely changed, the control set should change with it.
  • SOC 2 is asked but not scored. It isn't an AIUC-1 control; it's captured so your trust page can report it honestly.

Related

Set up your first agent · AIUC-1 and the six pillars

More in Every module explained