PurpAI
Use PurpleWASP's contextual assistant to understand authorised governance posture, follow connected records, get product guidance, prepare supported work and launch governed workflows safely.
Ask, resolve, navigate and complete the work
PurpAI keeps conversational context while the owning PurpleWASP module remains authoritative for permissions, records, assessment logic and final governed decisions.
Ask about PurpleWASP workflows, current posture, records or relationships in natural language.
PurpAI identifies the relevant authorised module, record set or Help Centre guidance.
Refine a result set conversationally, including safe choices such as “open the second one”.
Open the exact record, deep workflow or supported contextual draft.
Review, confirm and complete the work through the normal PurpleWASP workflow and permissions.
Understand what PurpAI can do
Learn the conversational patterns that work well and the boundaries that keep PurpAI aligned with PurpleWASP governance.
Move from an answer into the right workflow
PurpAI can resolve exact records and launch supported module-owned workflows while retaining the normal permission and validation boundary.
Navigate records and workflows
Select a record conversationally and open the exact Risk, Asset, Control or Third Party, including supported deep workflow views.
DraftingPrepare contextual work
Use existing context to prepare editable work, such as creating a Risk draft from a verified Asset without saving it automatically.
SafetySuggested Attention and safe actions
Review on-demand organisation signals and understand when PurpAI requires confirmation before a supported governed action.
PurpAI assists; PurpleWASP remains authoritative
PurpAI can now do more than read data, but it still does not bypass governance. Record access is re-authorised, drafts remain editable until the user saves them, and supported write actions require the module's existing permissions and explicit confirmation.
- PurpAI respects organisation AI settings and the signed-in user's module permissions.
- Browser-carried record IDs are treated as hints and are verified again before record-specific actions are offered.
- Contextual drafts do not persist a governed record until the user reviews and submits the normal module form.
- Supported confirmed actions use the existing module workflow and audit path rather than a separate PurpAI write path.
- Suggested Attention is a triage aid based on current authorised signals; it is not a PurpleWASP risk score, appetite decision or management approval.
No guidance matches that search.