Workflows
A workflow is a staged assessment the gateway drives through your agent: scripted stages, required fields the agent can't skip, user-review gates, and a report whose factual findings cite served evidence or remain unresolved. The concept is covered in Tools vs workflows; this page is the catalogue and the lifecycle; several families also have product pages under ansvar.eu/workflows. Free includes 1 run a month and Solo 2, picked from seven types — STRIDE threat model, gap analysis (generic or NIS2, DORA, CRA, EU AI Act) and DPIA — on a system you describe, with the report as a watermarked render or JSON. Premium includes 5 runs a month across the full interview-grounded catalogue with the report as structured JSON; workflows grounded in your own documents and unwatermarked rendered exports are Team (20 runs per seat a month) and Company (custom allowance).
The lifecycle — six tools
list_workflow_types() # what can I run?
start_workflow(workflow_type="dpia") # returns workflow_id + first step
get_current_step(workflow_id) # what the workflow needs next
submit_response(workflow_id, response) # answer; repeat until stages pass
get_progress(workflow_id) # where am I?
generate_report(workflow_id) # the final deliverableState persists on every submit_response — resume_workflow(workflow_id) picks an active run back up days later, and list_workflows / cancel_workflow manage the set. A completed workflow is immutable; rerun it as a new one when circumstances change. Evidence documents attach via the document library (see Cite your documents) and bind to a run with register_document.
The catalogue
Every served type, grouped by family — a variant reuses its base type's machinery with a jurisdiction- or domain-specific stage set. The table derives from a snapshot of the served registry (2026-08-06); list_workflow_types is the live contract and also carries each type's required parameters. "Free + (metered)" marks the seven included types Free and Solo may spend their monthly runs on; the same types run interview-grounded from Premium.
| workflow_type | Tier | What it produces |
|---|---|---|
adversary_tabletopAdversary Tabletop Exercise | Team + | A tabletop exercise record: attacker goals, scenario walkthrough, decision points, identified gaps and follow-ups. |
dpiaData Protection Impact Assessment (GDPR Article 35) | Free + (metered) | A GDPR Art. 35 DPIA report: processing description, necessity and proportionality assessment, risk register against thresholds, prior-consultation recommendation, and planned measures. |
↳ dpia_deDPIA — Germany (BDSG-aware) | Premium + | A GDPR Art. 35 DPIA report: processing description, necessity and proportionality assessment, risk register against thresholds, prior-consultation recommendation, and planned measures. |
↳ dpia_seDPIA — Sweden (GDPR Art. 35 + IMY supervisory practice) | Premium + | A GDPR Art. 35 DPIA report: processing description, necessity and proportionality assessment, risk register against thresholds, prior-consultation recommendation, and planned measures. |
↳ drone_dpiaDPIA — Drone / UAS Aerial Data Capture (GDPR Art. 35 + Reg (EU) 2019/947) | Premium + | A GDPR Art. 35 DPIA report: processing description, necessity and proportionality assessment, risk register against thresholds, prior-consultation recommendation, and planned measures. |
reviewDocument Review (Paragraph-Cited) | Team + | A paragraph-cited document review: findings each anchored to doc:// segment citations with content hashes (drift-detectable). |
risk_assessmentEnterprise Risk Assessment (ISO 31000 / 31010 / NIST 800-30G) | Premium + | A risk register aligned to ISO 31000/31010/NIST 800-30G: risks with likelihood/consequence bands, scores against thresholds, and treatments. |
↳ automotive_taraAutomotive TARA — ISO/SAE 21434 & UNECE R155 Threat Analysis & Risk Assessment | Premium + | A risk register aligned to ISO 31000/31010/NIST 800-30G: risks with likelihood/consequence bands, scores against thresholds, and treatments. |
↳ c_uas_assessmentCounter-UAS & Hostile-Takeover Resilience Assessment | Premium + | A risk register aligned to ISO 31000/31010/NIST 800-30G: risks with likelihood/consequence bands, scores against thresholds, and treatments. |
↳ ics_advisory_to_riskICS Advisory-to-Risk — current advisory exposure for an OT asset inventory | Premium + | A risk register aligned to ISO 31000/31010/NIST 800-30G: risks with likelihood/consequence bands, scores against thresholds, and treatments. |
↳ ot_taraOT / ICS / Machinery TARA — Threat Analysis & Risk Assessment | Premium + | A risk register aligned to ISO 31000/31010/NIST 800-30G: risks with likelihood/consequence bands, scores against thresholds, and treatments. |
↳ rail_taraRail / Railway TARA — Threat Analysis & Risk Assessment (CLC/TS 50701, IEC 62443) | Premium + | A risk register aligned to ISO 31000/31010/NIST 800-30G: risks with likelihood/consequence bands, scores against thresholds, and treatments. |
↳ robot_taraRobotics / Cobot TARA — Threat Analysis & Risk Assessment for industrial and collaborative robots | Premium + | A risk register aligned to ISO 31000/31010/NIST 800-30G: risks with likelihood/consequence bands, scores against thresholds, and treatments. |
↳ uas_taraUAS Threat Analysis & Risk Assessment (TARA) | Premium + | A risk register aligned to ISO 31000/31010/NIST 800-30G: risks with likelihood/consequence bands, scores against thresholds, and treatments. |
friaFundamental Rights Impact Assessment (EU AI Act Article 27) | Premium + | An EU AI Act Art. 27 FRIA report: affected-rights analysis against the Charter articles in scope, risk scoring, notification recommendation, and measures. |
↳ fria_seFRIA — Sweden (AI Act Art. 27 + IMY supervisory practice) | Premium + | An EU AI Act Art. 27 FRIA report: affected-rights analysis against the Charter articles in scope, risk scoring, notification recommendation, and measures. |
linddunLINDDUN Privacy Threat Model | Premium + | A LINDDUN privacy threat register: per-flow privacy threats with category, harm assessment, and mitigations. |
tender_auditPublic Tender Audit (Buyer-Side Lawfulness Review) | Team + | A buyer-side lawfulness review of the tender itself: procurement-law defect findings with citations and severity. |
↳ tender_audit_nlPublic Tender Audit — Netherlands (Classical, Aw 2012) | Team + | A buyer-side lawfulness review of the tender itself: procurement-law defect findings with citations and severity. |
↳ tender_audit_sePublic Tender Audit — Sweden (Classical, LOU) | Team + | A buyer-side lawfulness review of the tender itself: procurement-law defect findings with citations and severity. |
tender_reviewPublic Tender Review | Team + | A bid completeness review: requirement-by-requirement findings with citations and a coverage score against the tender's regulatory baseline. |
↳ tender_review_nlPublic Tender Review — Netherlands (Classical, Aw 2012) | Team + | A bid completeness review: requirement-by-requirement findings with citations and a coverage score against the tender's regulatory baseline. |
↳ tender_review_sePublic Tender Review — Sweden (Classical, LOU) | Team + | A bid completeness review: requirement-by-requirement findings with citations and a coverage score against the tender's regulatory baseline. |
gap_analysisRegulatory Gap Analysis | Free + (metered) | Gap findings mapped to the target framework at article level, each with regulatory citations, plus a coverage percentage. |
↳ drone_operator_complianceDrone Operator Compliance — UAS Operations (Reg (EU) 2019/947) | Premium + | Gap findings mapped to the target framework at article level, each with regulatory citations, plus a coverage percentage. |
↳ drone_product_security_conformityDrone Product Security Conformity — UAS Products (Reg (EU) 2019/945 + CRA + RED) | Premium + | Gap findings mapped to the target framework at article level, each with regulatory citations, plus a coverage percentage. |
↳ gap_analysis_ai_actGap Analysis — EU AI Act (Regulation (EU) 2024/1689) high-risk provider conformity | Free + (metered) | Gap findings mapped to the target framework at article level, each with regulatory citations, plus a coverage percentage. |
↳ gap_analysis_craGap Analysis — Cyber Resilience Act (Regulation (EU) 2024/2847) | Free + (metered) | Gap findings mapped to the target framework at article level, each with regulatory citations, plus a coverage percentage. |
↳ gap_analysis_doraGap Analysis — DORA (Regulation (EU) 2022/2554) | Free + (metered) | Gap findings mapped to the target framework at article level, each with regulatory citations, plus a coverage percentage. |
↳ gap_analysis_ivdrGap Analysis — In Vitro Diagnostic Regulation (Regulation (EU) 2017/746) | Premium + | Gap findings mapped to the target framework at article level, each with regulatory citations, plus a coverage percentage. |
↳ gap_analysis_mdcg_cyberGap Analysis — Medical Device Cybersecurity (MDCG 2019-16 rev.1) | Premium + | Gap findings mapped to the target framework at article level, each with regulatory citations, plus a coverage percentage. |
↳ gap_analysis_mdrGap Analysis — Medical Device Regulation (Regulation (EU) 2017/745) | Premium + | Gap findings mapped to the target framework at article level, each with regulatory citations, plus a coverage percentage. |
↳ gap_analysis_nis2Gap Analysis — NIS2 (Directive (EU) 2022/2555 Art. 21) | Free + (metered) | Gap findings mapped to the target framework at article level, each with regulatory citations, plus a coverage percentage. |
↳ gap_analysis_nis2_nlGap Analysis — NIS2 Netherlands (Cyberbeveiligingswet, Stb. 2026, 187) | Premium + | Gap findings mapped to the target framework at article level, each with regulatory citations, plus a coverage percentage. |
↳ gap_analysis_r155Gap Analysis — UNECE R155 Cyber Security Management System (CSMS) | Premium + | Gap findings mapped to the target framework at article level, each with regulatory citations, plus a coverage percentage. |
↳ ot_machinery_gapMachinery Regulation Gap Analysis — EHSRs (EU) 2023/1230 | Premium + | Gap findings mapped to the target framework at article level, each with regulatory citations, plus a coverage percentage. |
sora_operational_authorisationSORA — Specific-Category Operational Authorisation (Drone) | Premium + | A SORA determination record — iGRC/final GRC, ARC, SAIL, the applicable OSO set with robustness levels, and containment requirements — structured to support a specific-category authorisation application. |
threat_modelSTRIDE Threat Model | Free + (metered) | A STRIDE threat register: per-component threats with category, severity, affected assets, mitigations, and regulatory citations. |
↳ drone_threat_modelUAS / Drone Threat Model (STRIDE, UAS-scoped) | Premium + | A STRIDE threat register: per-component threats with category, severity, affected assets, mitigations, and regulatory citations. |
↳ ot_threat_modelOT / ICS Threat Model (STRIDE, zones-and-conduits) | Premium + | A STRIDE threat register: per-component threats with category, severity, affected assets, mitigations, and regulatory citations. |
vulnerability_assessmentVulnerability Assessment & Control-Investment Plan | Premium + | A vulnerability-assessment report over an already-scanned finding set: contextual CVSS with KEV and EPSS, the greedy-set control-investment plan, the immovable floor, and a merged CycloneDX VEX for Dependency-Track. |
deferral_dossierVulnerability Deferral Dossier & Control-Investment Plan | Premium + | A vulnerability deferral dossier over findings the customer proposes to defer: per-finding deferral records (contextual score, credited controls, verbatim disposition status, deterministic CRA Art. 14 reporting flags), adjudicated regulatory anchors with pin-cites, the greedy-set control-investment plan with the immovable floor, and a merged CycloneDX VEX. |
Walkthroughs and family pages
- Your first gap analysis — the full tutorial, including the search-driven Premium alternative. Family page: gap analysis.
- DPIA — stages and the report you get back. Family page: DPIA.
- Threat modeling — the STRIDE workflow, DFD-first. Family page: threat model.
- No docs walkthrough yet, product page live: TARA (automotive, OT, rail, robot, UAS), vulnerability decisions and tender review.
Before your first walk: workflows are where client and model choice matter most — see Clients and models for what a workflow demands of your client and which models we have tested.