Workflows

    A workflow is a staged assessment the gateway drives through your agent: scripted stages, required fields the agent can't skip, user-review gates, and a report whose factual findings cite served evidence or remain unresolved. The concept is covered in Tools vs workflows; this page is the catalogue and the lifecycle; several families also have product pages under ansvar.eu/workflows. Free includes 1 run a month and Solo 2, picked from seven types — STRIDE threat model, gap analysis (generic or NIS2, DORA, CRA, EU AI Act) and DPIA — on a system you describe, with the report as a watermarked render or JSON. Premium includes 5 runs a month across the full interview-grounded catalogue with the report as structured JSON; workflows grounded in your own documents and unwatermarked rendered exports are Team (20 runs per seat a month) and Company (custom allowance).

    The lifecycle — six tools

    list_workflow_types()                    # what can I run?
    start_workflow(workflow_type="dpia")     # returns workflow_id + first step
    get_current_step(workflow_id)            # what the workflow needs next
    submit_response(workflow_id, response)   # answer; repeat until stages pass
    get_progress(workflow_id)                # where am I?
    generate_report(workflow_id)             # the final deliverable

    State persists on every submit_response — resume_workflow(workflow_id) picks an active run back up days later, and list_workflows / cancel_workflow manage the set. A completed workflow is immutable; rerun it as a new one when circumstances change. Evidence documents attach via the document library (see Cite your documents) and bind to a run with register_document.

    Receive the report and its delivery receipt

    generate_report returns the typed report and a server-authored delivery_receipt. Your agent displays delivery_receipt.display_markdown unchanged: it includes the report's summary, integrity state, items requiring attention and artifact information. A receipt preview is not the full findings set. For a JSON run, receive the complete structured report; for a rendered run, use the artifact link and retain its hash and expiry information.

    Free and Solo teaser runs can produce a watermarked render or JSON. Premium receives JSON. Team and Company add unwatermarked HTML, PDF and DOCX exports. Check the returned artifacts rather than assuming that a requested render succeeded. When present, depends_on records the declared obligation and library dependencies used by the report. This workflow delivery receipt is separate from the Company audit ledger's signed query receipts.

    Risk assessments and TARA, DPIA/FRIA and gap analyses can include an optional system data-flow diagram. Follow the current step's instructions to review it or explicitly skip it. Keep any unresolved evidence visible in the final report; adding a diagram does not resolve missing legal or customer evidence.

    The catalogue

    Every served type, grouped by family — a variant reuses its base type's machinery with a jurisdiction- or domain-specific stage set. The table derives from a snapshot of the served registry (2026-09-07); list_workflow_types is the live contract and also carries each type's required parameters. "Free + (metered)" marks the seven included types Free and Solo may spend their monthly runs on; the same types run interview-grounded from Premium.

    workflow_typeTierWhat it produces
    adversary_tabletop
    Adversary Tabletop Exercise
    Team +A tabletop exercise record: attacker goals, scenario walkthrough, decision points, identified gaps and follow-ups.
    dpia
    Data Protection Impact Assessment (GDPR Article 35)
    Free + (metered)A GDPR Art. 35 DPIA report: processing description, necessity and proportionality assessment, risk register against thresholds, prior-consultation recommendation, and planned measures.
    ↳ dpia_de
    DPIA — Germany (BDSG-aware)
    Premium +A GDPR Art. 35 DPIA report: processing description, necessity and proportionality assessment, risk register against thresholds, prior-consultation recommendation, and planned measures.
    ↳ dpia_se
    DPIA — Sweden (GDPR Art. 35 + IMY supervisory practice)
    Premium +A GDPR Art. 35 DPIA report: processing description, necessity and proportionality assessment, risk register against thresholds, prior-consultation recommendation, and planned measures.
    ↳ drone_dpia
    DPIA — Drone / UAS Aerial Data Capture (GDPR Art. 35 + Reg (EU) 2019/947)
    Premium +A GDPR Art. 35 DPIA report: processing description, necessity and proportionality assessment, risk register against thresholds, prior-consultation recommendation, and planned measures.
    review
    Document Review (Paragraph-Cited)
    Team +A paragraph-cited document review: findings each anchored to doc:// segment citations with content hashes (drift-detectable).
    risk_assessment
    Enterprise Risk Assessment (ISO 31000 / 31010 / NIST 800-30G)
    Premium +A risk register aligned to ISO 31000/31010/NIST 800-30G: risks with likelihood/consequence bands, scores against thresholds, and treatments.
    ↳ automotive_tara
    Automotive TARA — ISO/SAE 21434 & UNECE R155 Threat Analysis & Risk Assessment
    Premium +A risk register aligned to ISO 31000/31010/NIST 800-30G: risks with likelihood/consequence bands, scores against thresholds, and treatments.
    ↳ c_uas_assessment
    Counter-UAS & Hostile-Takeover Resilience Assessment
    Premium +A risk register aligned to ISO 31000/31010/NIST 800-30G: risks with likelihood/consequence bands, scores against thresholds, and treatments.
    ↳ ics_advisory_to_risk
    ICS Advisory-to-Risk — current advisory exposure for an OT asset inventory
    Premium +A risk register aligned to ISO 31000/31010/NIST 800-30G: risks with likelihood/consequence bands, scores against thresholds, and treatments.
    ↳ ot_tara
    OT / ICS / Machinery TARA — Threat Analysis & Risk Assessment
    Premium +A risk register aligned to ISO 31000/31010/NIST 800-30G: risks with likelihood/consequence bands, scores against thresholds, and treatments.
    ↳ rail_tara
    Rail / Railway TARA — Threat Analysis & Risk Assessment (CLC/TS 50701, IEC 62443)
    Premium +A risk register aligned to ISO 31000/31010/NIST 800-30G: risks with likelihood/consequence bands, scores against thresholds, and treatments.
    ↳ robot_tara
    Robotics / Cobot TARA — Threat Analysis & Risk Assessment for industrial and collaborative robots
    Premium +A risk register aligned to ISO 31000/31010/NIST 800-30G: risks with likelihood/consequence bands, scores against thresholds, and treatments.
    ↳ uas_tara
    UAS Threat Analysis & Risk Assessment (TARA)
    Premium +A risk register aligned to ISO 31000/31010/NIST 800-30G: risks with likelihood/consequence bands, scores against thresholds, and treatments.
    fria
    Fundamental Rights Impact Assessment (EU AI Act Article 27)
    Premium +An EU AI Act Art. 27 FRIA report: affected-rights analysis against the Charter articles in scope, risk scoring, notification recommendation, and measures.
    ↳ fria_se
    FRIA — Sweden (AI Act Art. 27, svensk myndighetsutpekning)
    Premium +An EU AI Act Art. 27 FRIA report: affected-rights analysis against the Charter articles in scope, risk scoring, notification recommendation, and measures.
    linddun
    LINDDUN Privacy Threat Model
    Premium +A LINDDUN privacy threat register: per-flow privacy threats with category, harm assessment, and mitigations.
    tender_audit
    Public Tender Audit (Buyer-Side Lawfulness Review)
    Team +A buyer-side lawfulness review of the tender itself: procurement-law defect findings with citations and severity.
    ↳ tender_audit_nl
    Public Tender Audit — Netherlands (Classical, Aw 2012)
    Team +A buyer-side lawfulness review of the tender itself: procurement-law defect findings with citations and severity.
    ↳ tender_audit_se
    Public Tender Audit — Sweden (Classical, LOU)
    Team +A buyer-side lawfulness review of the tender itself: procurement-law defect findings with citations and severity.
    tender_review
    Public Tender Review
    Team +A bid completeness review: requirement-by-requirement findings with citations and a coverage score against the tender's regulatory baseline.
    ↳ tender_review_nl
    Public Tender Review — Netherlands (Classical, Aw 2012)
    Team +A bid completeness review: requirement-by-requirement findings with citations and a coverage score against the tender's regulatory baseline.
    ↳ tender_review_se
    Public Tender Review — Sweden (Classical, LOU)
    Team +A bid completeness review: requirement-by-requirement findings with citations and a coverage score against the tender's regulatory baseline.
    gap_analysis
    Regulatory Gap Analysis
    Free + (metered)Gap findings mapped to the target framework at article level, each with regulatory citations, plus a coverage percentage.
    ↳ drone_operator_compliance
    Drone Operator Compliance — UAS Operations (Reg (EU) 2019/947)
    Premium +Gap findings mapped to the target framework at article level, each with regulatory citations, plus a coverage percentage.
    ↳ drone_product_security_conformity
    Drone Product Security Conformity — UAS Products (Reg (EU) 2019/945 + CRA + RED)
    Premium +Gap findings mapped to the target framework at article level, each with regulatory citations, plus a coverage percentage.
    ↳ gap_analysis_ai_act
    Gap Analysis — EU AI Act (Regulation (EU) 2024/1689) high-risk provider conformity
    Free + (metered)Gap findings mapped to the target framework at article level, each with regulatory citations, plus a coverage percentage.
    ↳ gap_analysis_cra
    Gap Analysis — Cyber Resilience Act (Regulation (EU) 2024/2847)
    Free + (metered)Gap findings mapped to the target framework at article level, each with regulatory citations, plus a coverage percentage.
    ↳ gap_analysis_dora
    Gap Analysis — DORA (Regulation (EU) 2022/2554)
    Free + (metered)Gap findings mapped to the target framework at article level, each with regulatory citations, plus a coverage percentage.
    ↳ gap_analysis_ivdr
    Gap Analysis — In Vitro Diagnostic Regulation (Regulation (EU) 2017/746)
    Premium +Gap findings mapped to the target framework at article level, each with regulatory citations, plus a coverage percentage.
    ↳ gap_analysis_mdcg_cyber
    Gap Analysis — Medical Device Cybersecurity (MDCG 2019-16 rev.1)
    Premium +Gap findings mapped to the target framework at article level, each with regulatory citations, plus a coverage percentage.
    ↳ gap_analysis_mdr
    Gap Analysis — Medical Device Regulation (Regulation (EU) 2017/745)
    Premium +Gap findings mapped to the target framework at article level, each with regulatory citations, plus a coverage percentage.
    ↳ gap_analysis_nis2
    Gap Analysis — NIS2 (Directive (EU) 2022/2555 Art. 21)
    Free + (metered)Gap findings mapped to the target framework at article level, each with regulatory citations, plus a coverage percentage.
    ↳ gap_analysis_nis2_nl
    Gap Analysis — NIS2 Netherlands (Cyberbeveiligingswet, Stb. 2026, 187)
    Premium +Gap findings mapped to the target framework at article level, each with regulatory citations, plus a coverage percentage.
    ↳ gap_analysis_nis2_pl
    Gap Analysis — NIS2 Poland (ustawa o KSC, Dz.U. 2018 poz. 1560; t.j. Dz.U. 2026 poz. 20, zm. Dz.U. 2026 poz. 252)
    Team +Gap findings mapped to the target framework at article level, each with regulatory citations, plus a coverage percentage.
    ↳ gap_analysis_r155
    Gap Analysis — UNECE R155 Cyber Security Management System (CSMS)
    Premium +Gap findings mapped to the target framework at article level, each with regulatory citations, plus a coverage percentage.
    ↳ ot_machinery_gap
    Machinery Regulation Gap Analysis — EHSRs (EU) 2023/1230
    Premium +Gap findings mapped to the target framework at article level, each with regulatory citations, plus a coverage percentage.
    sora_operational_authorisation
    SORA — Specific-Category Operational Authorisation (Drone)
    Premium +A SORA determination record — iGRC/final GRC, ARC, SAIL, the applicable OSO set with robustness levels, and containment requirements — structured to support a specific-category authorisation application.
    threat_model
    STRIDE Threat Model
    Free + (metered)A STRIDE threat register: per-component threats with category, severity, affected assets, mitigations, and regulatory citations.
    ↳ ai_threat_model
    AI / ML System Threat Model (STRIDE + ATLAS)
    Premium +A STRIDE threat register: per-component threats with category, severity, affected assets, mitigations, and regulatory citations.
    ↳ drone_threat_model
    UAS / Drone Threat Model (STRIDE, UAS-scoped)
    Premium +A STRIDE threat register: per-component threats with category, severity, affected assets, mitigations, and regulatory citations.
    ↳ ot_threat_model
    OT / ICS Threat Model (STRIDE, zones-and-conduits)
    Premium +A STRIDE threat register: per-component threats with category, severity, affected assets, mitigations, and regulatory citations.
    vulnerability_assessment
    Vulnerability Assessment & Control-Investment Plan
    Premium +A vulnerability-assessment report over an already-scanned finding set: contextual CVSS with KEV and EPSS, the greedy-set control-investment plan, the immovable floor, and a merged CycloneDX VEX for Dependency-Track.
    deferral_dossier
    Vulnerability Deferral Dossier & Control-Investment Plan
    Premium +A vulnerability deferral dossier over findings the customer proposes to defer: per-finding deferral records (contextual score, credited controls, verbatim disposition status, deterministic CRA Art. 14 reporting flags), adjudicated regulatory anchors with pin-cites, the greedy-set control-investment plan with the immovable floor, and a merged CycloneDX VEX.

    Walkthroughs and family pages

    Before your first walk: workflows are where client and model choice matter most — see Clients and models for what a workflow demands of your client and which models we have tested.