Back to AssureDeck

Fictional demo

Sample AssureDeck Review Pack

A buyer-facing example of the evidence pack format for a fictional AI support workflow. It shows the structure, not a real customer result.

Status: fictional sample. Not legal advice, certification, audit opinion, penetration test, or a real customer review.

Executive summary

Northstar Ops AI: OpsPilot Agent

Reviewed workflow: support-ticket triage, CRM lookup, draft customer replies, and workflow task creation.

Model/provider pathReady

Provider route, region, retention, and training-use position documented.

Customer data handlingReview

Data classes mapped; admin retention documentation still needed.

Agent permissionsReady

Read/write actions and human approval gates documented.

Prompt injectionReview

Direct tests exist; indirect tests need CI-backed evidence.

Audit reconstructionGap

Internal reconstruction works; customer-facing export is planned.

System scope

AI feature inventory

FeaturePurposeCustomer data involved
Ticket triage assistantClassify support ticket priority and topicSupport ticket text, account tier
CRM context lookupRetrieve customer plan and account ownerCRM metadata and recent internal notes
Draft reply generatorDraft response for support agent reviewTicket text and KB snippets
Workflow task creatorCreate internal follow-up taskTicket id, account id, task summary

Permissions

Agent action matrix

Tool/actionRead/writeRiskPermission scopeHuman approval
Read ticketReadMediumTenant + user roleN/A
Read CRM accountReadMediumTenant + OAuth scopeN/A
Draft replyWrite draftMediumHelpdesk draft scopeYes before send
Send replyExternal actionHighHuman support agent onlyAlways
Create internal taskWrite internalMediumWorkflow task scopeUser confirmation

Reusable answers

AI security questionnaire answer bank

What customer data does the AI process?

Support tickets, selected KB snippets, CRM account metadata, and workflow task context.

Ready

Is customer data used to train models?

No. Customer data is not used to train foundation models.

Review

What autonomous actions can the agent take?

It can recommend, draft, and create internal tasks after confirmation. It cannot send external replies without human approval.

Ready

Can you reconstruct an AI incident?

Partially. Internal admins can reconstruct action path; self-serve customer export is planned.

Review

Gap list

Prioritized remediation plan

PriorityGapRecommended fix
P0PHI exclusion is not explicit enoughAdd prohibited-data language and admin warning
P1Indirect prompt-injection tests are not CI-backedAdd regression suite for ticket/email/HTML payloads
P1Audit reconstruction is internal-onlyAdd exportable audit summary
P2Tool/action docs are too technicalCreate buyer-facing permission page

What changes in a paid pilot

AssureDeck replaces fictional placeholders with the customer's real architecture, model/provider settings, DPA/subprocessor references, tool inventory, audit-log schema, customer-facing answer bank, confidence levels, and unsupported-claim flags.

The pilot does not invent security claims or certify the product.