PurpAI guide

Ask PurpAI effectively

Use natural language to get PurpleWASP product guidance, inspect authorised posture and records, follow relationships and continue from the current conversational subject.

Any authorised PurpleWASP user 5–10 minutes Updated 10 September 2026

1. Ask for the outcome you need

Use normal business language rather than trying to describe database fields. Questions such as “Show me our high risks”, “Which Controls cover those Assets?” or “What Compliance work is overdue?” let PurpAI resolve the relevant authorised PurpleWASP context.

2. Ask how PurpleWASP works

PurpAI can answer product-guidance questions such as “How do I create a Risk?”, “How do I add a Control?” or “How do I manage the SoA?”. These answers are grounded in the PurpleWASP Help Centre and can include a safe link into the owning workflow.

Action questions stay focused. When you ask how to perform a task, PurpAI prioritises the smallest relevant procedural guidance rather than mixing in unrelated troubleshooting material.

3. Follow connected records

PurpAI follows supported PurpleWASP relationships rather than guessing from similar names. Examples include Risk → Controls, Control → Assets, Asset → Controls, Third Party → Risks/Assets, SoA → Controls and supported Compliance → Evidence relationships.

4. Continue from the current subject

PurpAI keeps bounded conversational lineage. After a result set is returned, phrases such as “those”, “the second one”, “its evidence”, “previous controls” or “the original risks” can continue from the current or earlier subject when the reference is unambiguous.

If several records are in the current result and you say only “open it”, PurpAI will ask which record instead of choosing one silently.

5. Interpret results in the owning module's terms

PurpAI preserves important PurpleWASP distinctions. Current Risk and residual Risk are different; a catalogue Control and an adopted organisation Control are different; TPRM tiering and linked Risk severity are different; and the authoritative Compliance Score remains owned by the Compliance Dashboard.

The owning record remains the source of truth. Use PurpAI to understand and navigate the context, then use the PurpleWASP module to make or verify governed decisions.

6. Understand the permission boundary

  • PurpAI only returns context available to the signed-in user.
  • Organisation AI settings can disable PurpAI.
  • Record IDs carried in the conversation do not grant access; record-specific actions are verified again server-side.
  • Cross-module questions must also pass the destination module's access checks.
  • Some supported actions require write permission as well as explicit user confirmation.

Useful question patterns

  • How do I create a Risk?
  • Show me the high or very high active Risks.
  • Which Controls mitigate those Risks?
  • Open the second one.
  • Open its evidence.
  • Which Assets do those Controls cover?
  • Show me the SoA implementation gaps.
  • What Compliance work is overdue?
  • Which third parties concern us most?
  • What about the original Risks?