How Assessments Work

Overview of the operational risk assessment workflow, session lifecycle, and report issuance.

An assessment is the end-to-end workflow for completing a ten-phase operational risk assessment and producing a final report. For a screenshot-led guide through every phase, see Risk Assessment Walkthrough.

User flow

  1. Sign in (Google today; Microsoft planned).
  2. The product checks access (admin, grant, or credits — see billing).
  3. The product loads your active session if one exists.
  4. If there is no active session, start from Assessments → Risk Assessment.
  5. Work through each phase: capture data, review AI suggestions, confirm artifacts.
  6. Generate, edit, and issue the final report in Phase 10.
  7. The session is archived; you can still issue additional report variants from the report studio, or clone for a fresh AI budget.
See Report generation and variants for AI Fill limits, issued report labels, and post-conclusion behaviour.
Credits for credit-based users are reserved when a session becomes active and consumed when the report is issued, not when the assessment begins.See How sessions work for resume, clone, and import.

What you do in each phase

Each phase builds on prior artifacts. The walkthrough doc shows the UI for every step; this table is a quick reference.See How phases work for runtime rules (preview-first, preload, commit).
PhaseFocus
1System profile — owners, purpose, technologies
2Architectural model — zones, apps, flows, CTL
3Control scope and implementation status
4Threat actors and threats
5Likelihood and impact (VL / TEL)
6Inherent risk
7Compensating controls
8Remediation plan
9Residual risk
10Final report

Assessment screen

The assessment UI combines:
  • the current phase and roadmap
  • conversation with structured quick picks and worksheets
  • a status panel — phase JSON, DOT diagrams, tables, validation alerts
  • Reset phase when you need to restart a phase cleanly
  • AI enrichment where the phase policy allows external context
  • Worksheets for row-level edits in later phases

Final report and completion

  1. Configure report audience and purpose (Phase 10).
  2. Preview HTML and edit Markdown.
  3. Run AI fill for marked narrative sections.
  4. Issue the report — this renders PDF and archives the session.
  1. Download PDF, HTML, or DOCX from your profile.
  2. Clone the archived assessment to start a new session from the same baseline.

Related guides