Phase 4 — Threats (once-through)
Threat set seeded from architecture and controls, then curated. Once-through approach — forced AI.
Approach: Once-through · Switch approach
Threat set seeded from architecture and controls, then curated.
In once-through mode this phase usually advances in the unattended run after intake, with forced AI enrichment. You review and accept at the end of the track (and in Phase 10 for the report).
Workflow diagram
In this approach
| Server | Advances the phase during the unattended run; validates structured payloads. |
| You | Confirm intake up front; review outcomes; accept at the end. |
| AI | Forced enrichment (not the free Skip path). |