PurpAI guide

Navigate records and workflows with PurpAI

Move from a PurpAI result set to an exact authorised Risk, Asset, Control or Third Party, then open supported module-owned workflows without losing context.

Any authorised PurpleWASP user 5–10 minutes Updated 10 September 2026

1. Start from an authorised result set

Ask PurpAI for the records you want to work with, for example “Show me our high Risks”, “Show me our Assets”, “Show me our Controls” or “Show me our third parties”. PurpAI returns a bounded visible list while retaining the authoritative result context needed for follow-up questions.

2. Select one record conversationally

When several records are visible, identify the record rather than using an ambiguous singular reference. You can say “Open the first one”, “Open the second one” or another supported ordinal. Once the record is verified, that one-record set becomes the current subject and the previous set remains available in the conversation lineage.

PurpAI will not silently pick a record. If the current result contains several records and you say only “Open it”, PurpAI asks which record you mean.

3. Open supported deep workflows

After one record is selected, PurpAI can use a follow-up such as “Assess it” or “Open its evidence” to launch the supported workflow for that exact record. The destination page remains responsible for the workflow state, permissions and validation.

4. Use Control workspaces directly

Control Management supports the richest deep navigation. For a selected organisation Control, PurpAI can open its Scope, Assets, Assessments, Evidence, Testing, Issues, Exceptions or Risks workspace. It can also open the existing editors for a new assessment, evidence item, test or issue.

Opening an editor is not the same as saving a record. You still complete and submit the normal Control workflow.

5. Understand register-level fallbacks

Not every PurpleWASP page exposes the same deep-link contract. Where an exact sub-workflow cannot be safely targeted, PurpAI opens the exact verified record or the owning register rather than inventing unsupported page behaviour.

6. Why record selection is safe

Conversation-carried IDs are treated as hints, not permissions. Before PurpAI produces a record-specific action, the owning module re-reads that record for the signed-in user. If the record is no longer available or access has changed, the action is not produced.

Examples

Example sequences

Show me our high Risks.
Open the second one.
Assess it.

Show me our Controls.
Open the first one.
Open its assessments.
Open its evidence.
Start a new assessment for it.

Show me our third parties.
Open the first one.