Run a TARA

    A threat analysis and risk assessment turns threat scenarios into a risk register with assessed impacts, treatments and recorded decisions. Ansvar's TARA variants share the enterprise risk_assessment lifecycle, with sector-specific questions, criteria and sources. Start from Premium with a system you describe; customer-document grounding and unwatermarked rendered exports require Team or Company.

    Choose the assessment

    Ask your agent to call list_workflow_types and choose the variant for your system: automotive, OT, rail, robotics or UAS. Use scope_workflow if the objective is unclear, then confirm the returned choice before spending a workflow run. The workflow catalogue lists the current variants and their plan requirements.

    Using Ansvar, help me run an automotive TARA for a telematics ECU.
    Confirm the workflow type, system boundary and risk criteria with me first.
    Ask about the vehicle interfaces, remote services, assets and existing controls.
    Take me through each review gate, preserve unresolved evidence, and deliver
    the server's report and delivery receipt when the assessment is complete.

    This is a starter instruction for your own assessment. For the full run loop, install the TARA agent skill and keep the gateway connected.

    Describe the system and agree the criteria

    Identify the system boundary, assets, external connections, dependencies, operating environment and existing safeguards. Confirm the scoring bands and acceptance thresholds the selected workflow presents. A different sector can use different consequence categories and assessment criteria; carry the selected definitions into the report.

    Where the workflow offers a system data-flow diagram, review its components, flows and trust boundaries before accepting it. It is optional: follow the step's explicit skip path if you do not want to include one. Do not approve a diagram that invents missing interfaces or controls.

    Review scenarios, attack paths and treatments

    1. Confirm the risk list. Each scenario needs an affected asset, a threat and an outcome you can assess; add missing scenarios before the per-risk analysis starts.
    2. For each risk, review the impact and likelihood or feasibility criteria requested by the variant. Read the cited evidence and keep missing evidence visible.
    3. Where the variant requests attack paths, check the steps, entry points, preconditions and techniques. The report retains the path's provenance alongside its diagram; an unsupported technique must not acquire an invented citation.
    4. Record the treatment, owner and supporting safeguards. Keep existing protection separate from planned protection and a projected after-treatment position. A planned safeguard does not establish that today's risk has already fallen.
    5. Review the evaluation and compliance findings, including any risk that remains outside the agreed appetite. Complete the review gate before requesting the report.

    Receive and check the report

    Call generate_report after the required stages pass. Premium receives the structured JSON report; Team and Company can also request rendered exports. Your agent should display delivery_receipt.display_markdown unchanged and hand over the complete artifact. Check the criteria, current risk position, treatments, attack-path evidence and unresolved items. See report deliveryfor artifact hashes and the distinction from audit-ledger receipts.

    Use resume_workflow to continue an active run in a later session. When the system changes after completion, start a new assessment and identify which earlier evidence still applies. For component-level threat enumeration, see Threat modeling.