Ask the assistant
The AI assistant floats over every page in SolveGRC, and the Knowledge Graph is one of the sources it can read. Ask it about a control, a framework, or a piece of evidence and it searches the graph, walks the links, and answers with citations that open the concepts it used. This page covers how to ask, how to read what comes back, and what the assistant will and will not do with your data.
Open the assistant
Click the chat button in the bottom-right corner of any page. The panel floats over whatever you were doing, so nothing is blocked while you chat.
Use the persona dropdown at the top of the panel to steer its expertise: GRC Advisor for general questions, Risk Analyst for risk work, or Compliance Officer for framework and control questions. Switching persona starts a fresh conversation.
Ask in plain language
Type a question and press Enter. Questions the graph is good at:
- "Which SOC 2 controls are marked compliant but have no evidence?"
- "What evidence do we have for access reviews, and which frameworks does it cover?"
- "Is CC6.1 mapped to anything in ISO 27001, and was that mapping reviewed?"
The assistant answers from your organization's own records, never from the open web. For a graph question it first searches the graph for the concepts closest to what you asked, then walks their relationships to gather the controls, evidence, and hubs around them, and only then writes. If the graph has nothing relevant, it says so instead of guessing.
Read the answer
Every answer cites its evidence with numbered references like [1] and a Sources footer listing the records it drew from. Click a citation to open the source: a document, a diagram, or a knowledge graph concept, which opens in the same detail view the Knowledge Graph page uses.
Under each reply, expand How this was answered. It lists the governed tools the assistant called to produce the reply, in order, each with the audit identifier of that call. For a graph question you will see a search followed by one or more navigation steps. This trace is written for auditors as much as for you: it is the record of what the assistant looked at, and nothing outside that list contributed to the answer.
The History panel in the assistant's header reloads any past conversation so you can continue it.
What the assistant will not do
- It never sees another organization. Every tool the assistant calls is bound to your organization on the server before the conversation starts. The assistant cannot name, pass, or reason about an organization identifier; the tools do not accept one.
- It only reads. There is no tool that changes a control, attaches evidence, or approves a mapping. A gap the assistant finds is fixed in Frameworks or Evidence by a person.
- It respects your permissions, not its own. Graph questions need the same access the Knowledge Graph page needs: read permission on Frameworks and a two-factor session. Evidence and cloud posture concepts additionally need read access to the Evidence Locker and Cloud Posture. Ask about something you cannot see and the assistant tells you the tool was refused rather than answering around it.
- It stays inside the graph you have. If your organization's graph has not been built yet, the assistant reports that plainly and answers from your documents alone.
Switch it off
An organization administrator can disable every AI tool for the organization in one step, with a written reason that is recorded. The Knowledge Graph page keeps working, because it reads the built graph directly; only the assistant's tools stop. Re-enabling is done through the same permission settings, deliberately, rather than with a single toggle.
The same graph behind questionnaire drafts
You do not have to ask the assistant to benefit from the graph. Every AI-drafted questionnaire answer pulls the most relevant graph concepts alongside your documents, so a draft about access control can cite the control and the evidence behind it as well as the sentence in your policy. Those concept citations appear in the Review Center like any other source. See How AI answers are grounded for the rules every draft follows.