PurpAI guide

Prepare contextual work with PurpAI

Use verified conversation context to prepare supported editable work without allowing PurpAI to silently save a governed record.

Users with the required module write permission 5 minutes Updated 10 September 2026

1. Understand contextual drafts

A contextual draft carries verified PurpleWASP context into an existing workflow so you do not have to re-enter information that is already known. The draft prepares the form; it does not create the final governed record by itself.

2. Prepare a Risk from a verified Asset

The current supported contextual draft starts from a selected Asset. After PurpAI has resolved one Asset, ask for a Risk to be created for it, optionally including scenario wording.

Example

Show me our Assets.
Open the fourth one.
Create a Risk for it about ransomware exposure.

PurpAI verifies the Asset again and opens the existing Create Risk workflow with that Asset selected. When scenario wording is supplied, it can be carried into the editable Risk description.

3. Review the draft before saving

Complete or verify the scenario, owner, assessment method and other required Risk inputs in the normal Risk workflow. The draft is assistance, not a management decision.

Nothing is saved automatically. The Risk exists only after an authorised user submits the ordinary PurpleWASP form successfully.

4. One-time draft behaviour

PurpAI draft context is intentionally short-lived and one-time. If the prepared draft is no longer valid, return to PurpAI and ask it to prepare the workflow again rather than relying on an old browser link.

5. Permissions still apply

Preparing a Risk draft requires the normal Risk write capability, and the source Asset must still be available to the user. PurpAI does not convert view access into write access.

Examples

  • Create a Risk for this Asset.
  • Create a Risk for the second one about ransomware exposure.
  • Prepare a Risk for it due to supplier service outage.