Workflows
A workflow is a staged assessment the gateway drives through your agent: scripted stages, required fields the agent can't skip, user-review gates, and a report whose factual findings cite served evidence or remain unresolved. The concept is covered in Tools vs workflows; this page is the catalogue and the lifecycle; several families also have product pages under ansvar.eu/workflows. Free includes 1 run a month and Solo 2, picked from seven types — STRIDE threat model, gap analysis (generic or NIS2, DORA, CRA, EU AI Act) and DPIA — on a system you describe, with the report as a watermarked render or JSON. Premium includes 5 runs a month across the full interview-grounded catalogue with the report as structured JSON; workflows grounded in your own documents and unwatermarked rendered exports are Team (20 runs per seat a month) and Company (custom allowance).
The lifecycle — six tools
list_workflow_types() # what can I run?
start_workflow(workflow_type="dpia") # returns workflow_id + first step
get_current_step(workflow_id) # what the workflow needs next
submit_response(workflow_id, response) # answer; repeat until stages pass
get_progress(workflow_id) # where am I?
generate_report(workflow_id) # the final deliverableState persists on every submit_response — resume_workflow(workflow_id) picks an active run back up days later, and list_workflows / cancel_workflow manage the set. A completed workflow is immutable; rerun it as a new one when circumstances change. Evidence documents attach via the document library (see Cite your documents) and bind to a run with register_document.
Receive the report and its delivery receipt
generate_report returns the typed report and a server-authored delivery_receipt. Your agent displays delivery_receipt.display_markdown unchanged: it includes the report's summary, integrity state, items requiring attention and artifact information. A receipt preview is not the full findings set. For a JSON run, receive the complete structured report; for a rendered run, use the artifact link and retain its hash and expiry information.
Free and Solo teaser runs can produce a watermarked render or JSON. Premium receives JSON. Team and Company add unwatermarked HTML, PDF and DOCX exports. Check the returned artifacts rather than assuming that a requested render succeeded. When present, depends_on records the declared obligation and library dependencies used by the report. This workflow delivery receipt is separate from the Company audit ledger's signed query receipts.
Risk assessments and TARA, DPIA/FRIA and gap analyses can include an optional system data-flow diagram. Follow the current step's instructions to review it or explicitly skip it. Keep any unresolved evidence visible in the final report; adding a diagram does not resolve missing legal or customer evidence.
The catalogue
Every served type, grouped by family — a variant reuses its base type's machinery with a jurisdiction- or domain-specific stage set. The table derives from a snapshot of the served registry (2026-09-07); list_workflow_types is the live contract and also carries each type's required parameters. "Free + (metered)" marks the seven included types Free and Solo may spend their monthly runs on; the same types run interview-grounded from Premium.
| workflow_type | Tier | What it produces |
|---|---|---|
adversary_tabletopAdversary Tabletop Exercise | Team + | A tabletop exercise record: attacker goals, scenario walkthrough, decision points, identified gaps and follow-ups. |
dpiaData Protection Impact Assessment (GDPR Article 35) | Free + (metered) | A GDPR Art. 35 DPIA report: processing description, necessity and proportionality assessment, risk register against thresholds, prior-consultation recommendation, and planned measures. |
↳ dpia_deDPIA — Germany (BDSG-aware) | Premium + | A GDPR Art. 35 DPIA report: processing description, necessity and proportionality assessment, risk register against thresholds, prior-consultation recommendation, and planned measures. |
↳ dpia_seDPIA — Sweden (GDPR Art. 35 + IMY supervisory practice) | Premium + | A GDPR Art. 35 DPIA report: processing description, necessity and proportionality assessment, risk register against thresholds, prior-consultation recommendation, and planned measures. |
↳ drone_dpiaDPIA — Drone / UAS Aerial Data Capture (GDPR Art. 35 + Reg (EU) 2019/947) | Premium + | A GDPR Art. 35 DPIA report: processing description, necessity and proportionality assessment, risk register against thresholds, prior-consultation recommendation, and planned measures. |
reviewDocument Review (Paragraph-Cited) | Team + | A paragraph-cited document review: findings each anchored to doc:// segment citations with content hashes (drift-detectable). |
risk_assessmentEnterprise Risk Assessment (ISO 31000 / 31010 / NIST 800-30G) | Premium + | A risk register aligned to ISO 31000/31010/NIST 800-30G: risks with likelihood/consequence bands, scores against thresholds, and treatments. |
↳ automotive_taraAutomotive TARA — ISO/SAE 21434 & UNECE R155 Threat Analysis & Risk Assessment | Premium + | A risk register aligned to ISO 31000/31010/NIST 800-30G: risks with likelihood/consequence bands, scores against thresholds, and treatments. |
↳ c_uas_assessmentCounter-UAS & Hostile-Takeover Resilience Assessment | Premium + | A risk register aligned to ISO 31000/31010/NIST 800-30G: risks with likelihood/consequence bands, scores against thresholds, and treatments. |
↳ ics_advisory_to_riskICS Advisory-to-Risk — current advisory exposure for an OT asset inventory | Premium + | A risk register aligned to ISO 31000/31010/NIST 800-30G: risks with likelihood/consequence bands, scores against thresholds, and treatments. |
↳ ot_taraOT / ICS / Machinery TARA — Threat Analysis & Risk Assessment | Premium + | A risk register aligned to ISO 31000/31010/NIST 800-30G: risks with likelihood/consequence bands, scores against thresholds, and treatments. |
↳ rail_taraRail / Railway TARA — Threat Analysis & Risk Assessment (CLC/TS 50701, IEC 62443) | Premium + | A risk register aligned to ISO 31000/31010/NIST 800-30G: risks with likelihood/consequence bands, scores against thresholds, and treatments. |
↳ robot_taraRobotics / Cobot TARA — Threat Analysis & Risk Assessment for industrial and collaborative robots | Premium + | A risk register aligned to ISO 31000/31010/NIST 800-30G: risks with likelihood/consequence bands, scores against thresholds, and treatments. |
↳ uas_taraUAS Threat Analysis & Risk Assessment (TARA) | Premium + | A risk register aligned to ISO 31000/31010/NIST 800-30G: risks with likelihood/consequence bands, scores against thresholds, and treatments. |
friaFundamental Rights Impact Assessment (EU AI Act Article 27) | Premium + | An EU AI Act Art. 27 FRIA report: affected-rights analysis against the Charter articles in scope, risk scoring, notification recommendation, and measures. |
↳ fria_seFRIA — Sweden (AI Act Art. 27, svensk myndighetsutpekning) | Premium + | An EU AI Act Art. 27 FRIA report: affected-rights analysis against the Charter articles in scope, risk scoring, notification recommendation, and measures. |
linddunLINDDUN Privacy Threat Model | Premium + | A LINDDUN privacy threat register: per-flow privacy threats with category, harm assessment, and mitigations. |
tender_auditPublic Tender Audit (Buyer-Side Lawfulness Review) | Team + | A buyer-side lawfulness review of the tender itself: procurement-law defect findings with citations and severity. |
↳ tender_audit_nlPublic Tender Audit — Netherlands (Classical, Aw 2012) | Team + | A buyer-side lawfulness review of the tender itself: procurement-law defect findings with citations and severity. |
↳ tender_audit_sePublic Tender Audit — Sweden (Classical, LOU) | Team + | A buyer-side lawfulness review of the tender itself: procurement-law defect findings with citations and severity. |
tender_reviewPublic Tender Review | Team + | A bid completeness review: requirement-by-requirement findings with citations and a coverage score against the tender's regulatory baseline. |
↳ tender_review_nlPublic Tender Review — Netherlands (Classical, Aw 2012) | Team + | A bid completeness review: requirement-by-requirement findings with citations and a coverage score against the tender's regulatory baseline. |
↳ tender_review_sePublic Tender Review — Sweden (Classical, LOU) | Team + | A bid completeness review: requirement-by-requirement findings with citations and a coverage score against the tender's regulatory baseline. |
gap_analysisRegulatory Gap Analysis | Free + (metered) | Gap findings mapped to the target framework at article level, each with regulatory citations, plus a coverage percentage. |
↳ drone_operator_complianceDrone Operator Compliance — UAS Operations (Reg (EU) 2019/947) | Premium + | Gap findings mapped to the target framework at article level, each with regulatory citations, plus a coverage percentage. |
↳ drone_product_security_conformityDrone Product Security Conformity — UAS Products (Reg (EU) 2019/945 + CRA + RED) | Premium + | Gap findings mapped to the target framework at article level, each with regulatory citations, plus a coverage percentage. |
↳ gap_analysis_ai_actGap Analysis — EU AI Act (Regulation (EU) 2024/1689) high-risk provider conformity | Free + (metered) | Gap findings mapped to the target framework at article level, each with regulatory citations, plus a coverage percentage. |
↳ gap_analysis_craGap Analysis — Cyber Resilience Act (Regulation (EU) 2024/2847) | Free + (metered) | Gap findings mapped to the target framework at article level, each with regulatory citations, plus a coverage percentage. |
↳ gap_analysis_doraGap Analysis — DORA (Regulation (EU) 2022/2554) | Free + (metered) | Gap findings mapped to the target framework at article level, each with regulatory citations, plus a coverage percentage. |
↳ gap_analysis_ivdrGap Analysis — In Vitro Diagnostic Regulation (Regulation (EU) 2017/746) | Premium + | Gap findings mapped to the target framework at article level, each with regulatory citations, plus a coverage percentage. |
↳ gap_analysis_mdcg_cyberGap Analysis — Medical Device Cybersecurity (MDCG 2019-16 rev.1) | Premium + | Gap findings mapped to the target framework at article level, each with regulatory citations, plus a coverage percentage. |
↳ gap_analysis_mdrGap Analysis — Medical Device Regulation (Regulation (EU) 2017/745) | Premium + | Gap findings mapped to the target framework at article level, each with regulatory citations, plus a coverage percentage. |
↳ gap_analysis_nis2Gap Analysis — NIS2 (Directive (EU) 2022/2555 Art. 21) | Free + (metered) | Gap findings mapped to the target framework at article level, each with regulatory citations, plus a coverage percentage. |
↳ gap_analysis_nis2_nlGap Analysis — NIS2 Netherlands (Cyberbeveiligingswet, Stb. 2026, 187) | Premium + | Gap findings mapped to the target framework at article level, each with regulatory citations, plus a coverage percentage. |
↳ gap_analysis_nis2_plGap Analysis — NIS2 Poland (ustawa o KSC, Dz.U. 2018 poz. 1560; t.j. Dz.U. 2026 poz. 20, zm. Dz.U. 2026 poz. 252) | Team + | Gap findings mapped to the target framework at article level, each with regulatory citations, plus a coverage percentage. |
↳ gap_analysis_r155Gap Analysis — UNECE R155 Cyber Security Management System (CSMS) | Premium + | Gap findings mapped to the target framework at article level, each with regulatory citations, plus a coverage percentage. |
↳ ot_machinery_gapMachinery Regulation Gap Analysis — EHSRs (EU) 2023/1230 | Premium + | Gap findings mapped to the target framework at article level, each with regulatory citations, plus a coverage percentage. |
sora_operational_authorisationSORA — Specific-Category Operational Authorisation (Drone) | Premium + | A SORA determination record — iGRC/final GRC, ARC, SAIL, the applicable OSO set with robustness levels, and containment requirements — structured to support a specific-category authorisation application. |
threat_modelSTRIDE Threat Model | Free + (metered) | A STRIDE threat register: per-component threats with category, severity, affected assets, mitigations, and regulatory citations. |
↳ ai_threat_modelAI / ML System Threat Model (STRIDE + ATLAS) | Premium + | A STRIDE threat register: per-component threats with category, severity, affected assets, mitigations, and regulatory citations. |
↳ drone_threat_modelUAS / Drone Threat Model (STRIDE, UAS-scoped) | Premium + | A STRIDE threat register: per-component threats with category, severity, affected assets, mitigations, and regulatory citations. |
↳ ot_threat_modelOT / ICS Threat Model (STRIDE, zones-and-conduits) | Premium + | A STRIDE threat register: per-component threats with category, severity, affected assets, mitigations, and regulatory citations. |
vulnerability_assessmentVulnerability Assessment & Control-Investment Plan | Premium + | A vulnerability-assessment report over an already-scanned finding set: contextual CVSS with KEV and EPSS, the greedy-set control-investment plan, the immovable floor, and a merged CycloneDX VEX for Dependency-Track. |
deferral_dossierVulnerability Deferral Dossier & Control-Investment Plan | Premium + | A vulnerability deferral dossier over findings the customer proposes to defer: per-finding deferral records (contextual score, credited controls, verbatim disposition status, deterministic CRA Art. 14 reporting flags), adjudicated regulatory anchors with pin-cites, the greedy-set control-investment plan with the immovable floor, and a merged CycloneDX VEX. |
Walkthroughs and family pages
- Your first gap analysis — the full tutorial, including the search-driven Premium alternative. Family page: gap analysis.
- DPIA — stages and the report you get back. Family page: DPIA.
- Threat modeling — the STRIDE workflow, DFD-first. Family page: threat model.
- Run a TARA — scope, risk criteria, attack paths, treatments and report delivery. Family page: TARA.
- Product guides for vulnerability decisions.
Before your first walk: workflows are where client and model choice matter most — see Clients and models for what a workflow demands of your client and which models we have tested.