concept
Chat Assistant
A scoped assistant one click away on every page — it surfaces what is unfinished, does approval-gated setup with you (engagement brief, target verification, automations, evidence), and answers anything about your scope. It never runs an assessment.
Assistant chat is a scoped assistant that sits alongside your assessment work. It does two things: it answers questions about what the platform already knows for the active scope — assets, findings, evidence, coverage, readiness, engagement brief — and it helps you finish setting a scope up, proposing configuration changes that only take effect once you approve them.
What it never does is run an assessment. It has no scanning, browsing, or active-testing tools. The line is simple: chat analyzes and configures; runs test. For "is this vulnerable?", launch a run.
What the assistant is
The assistant sits alongside your work on every page: a tab on the edge opens a panel scoped to the active scope, and Chat opens the full page. It has structured read access to everything the platform already knows — assets, findings, evidence, coverage, readiness, the engagement brief — plus a set of approval-gated tools that help you configure a scope. The line is simple: it analyzes and configures; it never runs an assessment.
It surfaces what is unfinished
The panel opens on suggested actions for the active scope — setup gaps first. If a scope is missing a verified target, an engagement brief, or useful context, the assistant surfaces it there, with a count on the edge tab, so nothing important is left half-done. Acting on a suggestion starts a conversation aimed at closing that specific gap.
It does the setup with you
Most of the setup you would otherwise click through, the assistant can do for you — as a proposed change you review and approve before anything is written. You describe the outcome; it prepares the change and shows you exactly what it will apply. Nothing happens silently.
- Fill the engagement brief and rules of engagement — attach an existing RoE or architecture document and it reads it into structured scope context, or it walks you through the questions and drafts it.
- Verify a target the right way — it recommends the best method for that target (platform plugin, DNS, or HTTP) and walks you through the steps.
- Create an automation without touching the UI — describe the schedule and goal in plain words and it prepares the automation for you to approve.
- Organize compliance evidence — point it at what a control is asking for and it helps attach and map the evidence to it.
It answers anything about your scope
The other half is question answering. Because it can read what the platform has already collected, it turns your data into plain-language answers — explaining a finding and how to fix it, prioritizing what to remediate first, summarizing a run, or briefing your team from your company context.
- Explain this finding in plain language and tell me how to fix it.
- Which assets in this scope currently have critical findings, and what should we fix first?
- Summarize the open findings across the customer portal for our weekly review.
- What changed in this scope since the last run?
- What does the engagement brief currently exclude, and what is the testing posture?
- Which compliance controls are still missing evidence?
Where the line is
One boundary, and it is intentional: the assistant never runs an assessment. It has no scanning, browsing, or active-testing tools, and it never applies a setup change without your approval. New testing belongs in a run, so the platform can plan it, execute it under the engagement brief, and capture evidence.
If you find yourself asking chat to test something
Open the home launcher and start the same question as a run. The platform will plan it, execute it inside the scope's engagement brief, and preserve the evidence. Chat analyzes and configures; runs test.
Scope-bound by design
The assistant always operates against the active scope selected in the sidebar. To analyze or configure a different environment, switch the active scope first. This keeps answers focused and prevents accidental cross-environment leakage in shared screenshots or notes.
Related articles
Last updated Jul 14, 2026
