Workflows

    A workflow is a staged assessment the gateway drives through your agent: scripted stages, required fields the agent can't skip, user-review gates, and a report whose factual findings cite served evidence or remain unresolved. The concept is covered in Tools vs workflows; this page is the catalogue and the lifecycle; several families also have product pages under ansvar.eu/workflows. Free includes 1 run a month and Solo 2, picked from seven types — STRIDE threat model, gap analysis (generic or NIS2, DORA, CRA, EU AI Act) and DPIA — on a system you describe, with the report as a watermarked render or JSON. Premium includes 5 runs a month across the full interview-grounded catalogue with the report as structured JSON; workflows grounded in your own documents and unwatermarked rendered exports are Team (20 runs per seat a month) and Company (custom allowance).

    The lifecycle — six tools

    list_workflow_types()                    # what can I run?
    start_workflow(workflow_type="dpia")     # returns workflow_id + first step
    get_current_step(workflow_id)            # what the workflow needs next
    submit_response(workflow_id, response)   # answer; repeat until stages pass
    get_progress(workflow_id)                # where am I?
    generate_report(workflow_id)             # the final deliverable

    State persists on every submit_response resume_workflow(workflow_id) picks an active run back up days later, and list_workflows / cancel_workflow manage the set. A completed workflow is immutable; rerun it as a new one when circumstances change. Evidence documents attach via the document library (see Cite your documents) and bind to a run with register_document.

    The catalogue

    Every served type, grouped by family — a variant reuses its base type's machinery with a jurisdiction- or domain-specific stage set. The table derives from a snapshot of the served registry (2026-08-06); list_workflow_types is the live contract and also carries each type's required parameters. "Free + (metered)" marks the seven included types Free and Solo may spend their monthly runs on; the same types run interview-grounded from Premium.

    workflow_typeTierWhat it produces
    adversary_tabletop
    Adversary Tabletop Exercise
    Team +A tabletop exercise record: attacker goals, scenario walkthrough, decision points, identified gaps and follow-ups.
    dpia
    Data Protection Impact Assessment (GDPR Article 35)
    Free + (metered)A GDPR Art. 35 DPIA report: processing description, necessity and proportionality assessment, risk register against thresholds, prior-consultation recommendation, and planned measures.
    dpia_de
    DPIA — Germany (BDSG-aware)
    Premium +A GDPR Art. 35 DPIA report: processing description, necessity and proportionality assessment, risk register against thresholds, prior-consultation recommendation, and planned measures.
    dpia_se
    DPIA — Sweden (GDPR Art. 35 + IMY supervisory practice)
    Premium +A GDPR Art. 35 DPIA report: processing description, necessity and proportionality assessment, risk register against thresholds, prior-consultation recommendation, and planned measures.
    drone_dpia
    DPIA — Drone / UAS Aerial Data Capture (GDPR Art. 35 + Reg (EU) 2019/947)
    Premium +A GDPR Art. 35 DPIA report: processing description, necessity and proportionality assessment, risk register against thresholds, prior-consultation recommendation, and planned measures.
    review
    Document Review (Paragraph-Cited)
    Team +A paragraph-cited document review: findings each anchored to doc:// segment citations with content hashes (drift-detectable).
    risk_assessment
    Enterprise Risk Assessment (ISO 31000 / 31010 / NIST 800-30G)
    Premium +A risk register aligned to ISO 31000/31010/NIST 800-30G: risks with likelihood/consequence bands, scores against thresholds, and treatments.
    automotive_tara
    Automotive TARA — ISO/SAE 21434 & UNECE R155 Threat Analysis & Risk Assessment
    Premium +A risk register aligned to ISO 31000/31010/NIST 800-30G: risks with likelihood/consequence bands, scores against thresholds, and treatments.
    c_uas_assessment
    Counter-UAS & Hostile-Takeover Resilience Assessment
    Premium +A risk register aligned to ISO 31000/31010/NIST 800-30G: risks with likelihood/consequence bands, scores against thresholds, and treatments.
    ics_advisory_to_risk
    ICS Advisory-to-Risk — current advisory exposure for an OT asset inventory
    Premium +A risk register aligned to ISO 31000/31010/NIST 800-30G: risks with likelihood/consequence bands, scores against thresholds, and treatments.
    ot_tara
    OT / ICS / Machinery TARA — Threat Analysis & Risk Assessment
    Premium +A risk register aligned to ISO 31000/31010/NIST 800-30G: risks with likelihood/consequence bands, scores against thresholds, and treatments.
    rail_tara
    Rail / Railway TARA — Threat Analysis & Risk Assessment (CLC/TS 50701, IEC 62443)
    Premium +A risk register aligned to ISO 31000/31010/NIST 800-30G: risks with likelihood/consequence bands, scores against thresholds, and treatments.
    robot_tara
    Robotics / Cobot TARA — Threat Analysis & Risk Assessment for industrial and collaborative robots
    Premium +A risk register aligned to ISO 31000/31010/NIST 800-30G: risks with likelihood/consequence bands, scores against thresholds, and treatments.
    uas_tara
    UAS Threat Analysis & Risk Assessment (TARA)
    Premium +A risk register aligned to ISO 31000/31010/NIST 800-30G: risks with likelihood/consequence bands, scores against thresholds, and treatments.
    fria
    Fundamental Rights Impact Assessment (EU AI Act Article 27)
    Premium +An EU AI Act Art. 27 FRIA report: affected-rights analysis against the Charter articles in scope, risk scoring, notification recommendation, and measures.
    fria_se
    FRIA — Sweden (AI Act Art. 27 + IMY supervisory practice)
    Premium +An EU AI Act Art. 27 FRIA report: affected-rights analysis against the Charter articles in scope, risk scoring, notification recommendation, and measures.
    linddun
    LINDDUN Privacy Threat Model
    Premium +A LINDDUN privacy threat register: per-flow privacy threats with category, harm assessment, and mitigations.
    tender_audit
    Public Tender Audit (Buyer-Side Lawfulness Review)
    Team +A buyer-side lawfulness review of the tender itself: procurement-law defect findings with citations and severity.
    tender_audit_nl
    Public Tender Audit — Netherlands (Classical, Aw 2012)
    Team +A buyer-side lawfulness review of the tender itself: procurement-law defect findings with citations and severity.
    tender_audit_se
    Public Tender Audit — Sweden (Classical, LOU)
    Team +A buyer-side lawfulness review of the tender itself: procurement-law defect findings with citations and severity.
    tender_review
    Public Tender Review
    Team +A bid completeness review: requirement-by-requirement findings with citations and a coverage score against the tender's regulatory baseline.
    tender_review_nl
    Public Tender Review — Netherlands (Classical, Aw 2012)
    Team +A bid completeness review: requirement-by-requirement findings with citations and a coverage score against the tender's regulatory baseline.
    tender_review_se
    Public Tender Review — Sweden (Classical, LOU)
    Team +A bid completeness review: requirement-by-requirement findings with citations and a coverage score against the tender's regulatory baseline.
    gap_analysis
    Regulatory Gap Analysis
    Free + (metered)Gap findings mapped to the target framework at article level, each with regulatory citations, plus a coverage percentage.
    drone_operator_compliance
    Drone Operator Compliance — UAS Operations (Reg (EU) 2019/947)
    Premium +Gap findings mapped to the target framework at article level, each with regulatory citations, plus a coverage percentage.
    drone_product_security_conformity
    Drone Product Security Conformity — UAS Products (Reg (EU) 2019/945 + CRA + RED)
    Premium +Gap findings mapped to the target framework at article level, each with regulatory citations, plus a coverage percentage.
    gap_analysis_ai_act
    Gap Analysis — EU AI Act (Regulation (EU) 2024/1689) high-risk provider conformity
    Free + (metered)Gap findings mapped to the target framework at article level, each with regulatory citations, plus a coverage percentage.
    gap_analysis_cra
    Gap Analysis — Cyber Resilience Act (Regulation (EU) 2024/2847)
    Free + (metered)Gap findings mapped to the target framework at article level, each with regulatory citations, plus a coverage percentage.
    gap_analysis_dora
    Gap Analysis — DORA (Regulation (EU) 2022/2554)
    Free + (metered)Gap findings mapped to the target framework at article level, each with regulatory citations, plus a coverage percentage.
    gap_analysis_ivdr
    Gap Analysis — In Vitro Diagnostic Regulation (Regulation (EU) 2017/746)
    Premium +Gap findings mapped to the target framework at article level, each with regulatory citations, plus a coverage percentage.
    gap_analysis_mdcg_cyber
    Gap Analysis — Medical Device Cybersecurity (MDCG 2019-16 rev.1)
    Premium +Gap findings mapped to the target framework at article level, each with regulatory citations, plus a coverage percentage.
    gap_analysis_mdr
    Gap Analysis — Medical Device Regulation (Regulation (EU) 2017/745)
    Premium +Gap findings mapped to the target framework at article level, each with regulatory citations, plus a coverage percentage.
    gap_analysis_nis2
    Gap Analysis — NIS2 (Directive (EU) 2022/2555 Art. 21)
    Free + (metered)Gap findings mapped to the target framework at article level, each with regulatory citations, plus a coverage percentage.
    gap_analysis_nis2_nl
    Gap Analysis — NIS2 Netherlands (Cyberbeveiligingswet, Stb. 2026, 187)
    Premium +Gap findings mapped to the target framework at article level, each with regulatory citations, plus a coverage percentage.
    gap_analysis_r155
    Gap Analysis — UNECE R155 Cyber Security Management System (CSMS)
    Premium +Gap findings mapped to the target framework at article level, each with regulatory citations, plus a coverage percentage.
    ot_machinery_gap
    Machinery Regulation Gap Analysis — EHSRs (EU) 2023/1230
    Premium +Gap findings mapped to the target framework at article level, each with regulatory citations, plus a coverage percentage.
    sora_operational_authorisation
    SORA — Specific-Category Operational Authorisation (Drone)
    Premium +A SORA determination record — iGRC/final GRC, ARC, SAIL, the applicable OSO set with robustness levels, and containment requirements — structured to support a specific-category authorisation application.
    threat_model
    STRIDE Threat Model
    Free + (metered)A STRIDE threat register: per-component threats with category, severity, affected assets, mitigations, and regulatory citations.
    drone_threat_model
    UAS / Drone Threat Model (STRIDE, UAS-scoped)
    Premium +A STRIDE threat register: per-component threats with category, severity, affected assets, mitigations, and regulatory citations.
    ot_threat_model
    OT / ICS Threat Model (STRIDE, zones-and-conduits)
    Premium +A STRIDE threat register: per-component threats with category, severity, affected assets, mitigations, and regulatory citations.
    vulnerability_assessment
    Vulnerability Assessment & Control-Investment Plan
    Premium +A vulnerability-assessment report over an already-scanned finding set: contextual CVSS with KEV and EPSS, the greedy-set control-investment plan, the immovable floor, and a merged CycloneDX VEX for Dependency-Track.
    deferral_dossier
    Vulnerability Deferral Dossier & Control-Investment Plan
    Premium +A vulnerability deferral dossier over findings the customer proposes to defer: per-finding deferral records (contextual score, credited controls, verbatim disposition status, deterministic CRA Art. 14 reporting flags), adjudicated regulatory anchors with pin-cites, the greedy-set control-investment plan with the immovable floor, and a merged CycloneDX VEX.

    Walkthroughs and family pages

    Before your first walk: workflows are where client and model choice matter most — see Clients and models for what a workflow demands of your client and which models we have tested.