PurpAI guide

Use Suggested Attention and safe PurpAI actions

Review current authorised warning and danger signals on demand, and understand the confirmation boundary for supported actions that create governed work.

Authorised PurpleWASP users 5–10 minutes Updated 10 September 2026

1. Open Suggested Attention when you need it

Open PurpAI and choose Suggested attention beside Guide PurpAI. The panel is on demand; simply opening the chat does not automatically open the signals panel.

2. Interpret Suggested Attention as triage, not a score

Suggested Attention uses current authorised warning and danger metrics to surface a short list of leading human-review priorities. It can include signals such as high or very high Risks, overdue corrective actions, overdue supplier reviews, incidents or unimplemented Controls.

It is not a PurpleWASP risk score. The ordering is a triage aid and does not make a Risk appetite decision, approve remediation sequencing or replace management judgement.

3. Refresh or close the panel

Use the refresh control to re-read the current authorised signals. Use the close control to dismiss Suggested Attention while keeping the PurpAI chat open. Selecting a suggestion opens the owning PurpleWASP area.

4. Start supported governed actions from context

Most PurpAI actions are navigation or workflow preparation. A small allow-listed set can create governed Third-Party work after one Third Party has been verified. The currently supported confirmed actions are starting a periodic review and starting or resuming due diligence where the TPRM workflow supports it.

5. Confirm before execution

When a supported action will create governed work, PurpAI presents a confirmation step. Cancelling leaves the workflow unchanged. Confirming is required before the action is handed to the existing TPRM workflow.

6. Existing permissions and audit paths remain authoritative

The action still requires the user's normal Third-Party Risk write permission. PurpAI does not write directly around the module; the existing TPRM service, validation and audit path remain responsible for the result.

7. Current boundaries

  • PurpAI does not automatically approve, accept or close governance decisions.
  • Risk and Control editors opened by PurpAI still require the user to complete and submit their ordinary forms.
  • Contextual Risk drafts do not persist until saved by the user.
  • Confirmation-gated write execution is currently limited to the supported TPRM review and due-diligence actions.