Back to the module/Cortex, and the boundaries on it
The point

An AI layer is only useful in a risk platform if every answer is grounded in the same records the platform is audited on.

One grounded layer, every module

Where the AI layer appears in the product, and what each surface is grounded in.

Surfaces and their grounding

Each place the AI layer appears, and the records it is restricted to

SurfaceGrounded in
Ask across your dataYour register, controls, findings and vendors
Summarise a recordThe record itself and its linked evidence
Triage an alertThe alert, the asset, and the current vulnerability catalogue
Draft a responseThe control set, with citations to each control used

Why it matters

There is one retrieval layer and one policy layer underneath all four. That matters more than it sounds: separate assistants per module is how an organisation ends up with four different answers to the same question, each confidently sourced.

Why a bolt-on assistant fails here

A general assistant pointed at a risk platform can read documents and cannot read permissions, lineage or test results. It will summarise a control as effective because a document says so, in a system that exists precisely to distinguish what a document says from what the evidence shows.

Cortex, and the boundaries on it | GeneSecure