Scoping cards
The scoping cards are the first step of qualification. You describe the project's context here, import the relevant documents, then link the assets and processes concerned.
The more thoroughly the scoping cards are filled in, the more precise the platform's AI generations (feared events, risks, summary, etc.) will be. Don't hesitate to take the time for this step: it conditions everything that follows in the project.
The scoping cards are organised in three subsections you can complete in the order of your choice.
Context and documents
This first subsection lets you describe the project context freely.
You have a free-text field in which you can enter:
- the business and organisational context
- the functional or technical architecture
- past experiences or known incidents
- any scoping element useful to the analysis
You can also import documents directly into the card: architecture diagrams, functional specifications, security procedures, meeting notes, and any other document you consider relevant.
Imported documents are used by the AI during later generations. They enrich the context taken into account to suggest feared events, risks and measures adapted to your project.
Assets
This subsection lets you link your organisation's assets to the current project. The selected assets constitute the material and logical scope of the analysis.
You have two modes to build this list:
- Manual linking — You select the assets to attach from the organisation's existing catalogue.
- Automatic generation — The AI suggests a list of assets based on the context and documents entered in the previous subsection.
Assets generated by the AI are automatically added to the organisation's catalogue. You can then validate or reject them to maintain a clean catalogue reusable across other projects.
To learn more about catalogue management, see the Manage assets section.
The magic wand: targeted generation
Next to the Generate button, you have a magic wand icon that lets you focus the generation on a specific criterion rather than on the entire block.
For example, if you are satisfied with the Confidentiality level but want to regenerate only the Availability level, the magic wand lets you do so without recalculating the other criteria.
The magic wand opens a small panel in which you can:
- select the criterion or element to regenerate
- add a complementary free-text instruction to guide the AI (for example: "take into account the recent addition of the backup process")
The magic wand is particularly useful for quick iteration: you keep the work already validated and only regenerate what needs to change.
Generation history
Next to the Generate button, a clock icon gives access to the history of previous generations. You can consult:
- the date and time of each generation
- the content produced at that moment
- the user who triggered the generation
You can compare versions, restore an earlier generation or simply keep a record of successive iterations.
The magic wand and the generation history are available on every Generate button of the platform, not only on the qualification summary. You will find them in the risk analysis as well, on feared events, risks, remediation measures, etc. The behaviour is identical everywhere.
Processes
This subsection lists the business processes linked to the project. The processes identified here will be used in the risk analysis to characterise feared events and their impacts.
Two creation modes are available:
- Manual creation — You enter processes one by one through the dedicated form.
- Automatic generation — The AI suggests a list of processes based on the information entered in Context and documents and in Assets.
You can enrich, modify or delete processes at any time before moving to the next step.
Move to the next step
Once the three subsections are filled in, you can move to the second step of qualification: the Questionnaire.