Skip to main content

AI Configuration

ConcertoGRC embeds AI across the platform for analysis, generation, mapping, and orchestration tasks. The AI tab in Administration → Settings lets you view feature configurations, model assignments, prompt templates, and inference settings.

Overview

Settings AI tab showing AI Features heading, info banner about platform-managed settings, category filter buttons (All Features, Orchestrator, Auto-Suggest, Analysis, Generation), search bar, and feature cards organized by category showing Orchestrator Queries with Claude Sonnet 4.5, Auto-Suggest Embeddings with Titan Embeddings V2, Auto-Suggest Explanations and Migration Field Mapping, and Analysis features including Vendor URL Discovery

Features are organized into four categories, each filterable from the tab bar. A search field helps locate specific features. Each feature card shows:

  • Feature name and description
  • Badges — Streaming (real-time output), Platform Default (inherited from platform config)
  • Model — The AI model assigned to this feature
  • Enable/disable toggle — Controls whether the feature is active
  • Settings — Inference parameters (max tokens, temperature)
  • Prompt — Editable prompt template (available on features that use prompt templates)
info

Model and prompt settings are managed by your platform administrator. Tenant users can view configurations but must contact support to request changes.

Feature Categories

Orchestrator

Core AI interactions powering the platform's conversational capabilities.

FeatureModelDescription
Orchestrator — QueriesClaude Sonnet 4.5Status lookups, complex reasoning, actions, reports, and compliance guidance (streaming)

Auto-Suggest

Automated suggestions and intelligent field mapping powered by embeddings and language models.

FeatureModelDescription
EmbeddingsTitan Embeddings V2Vector embeddings for controls, evidence, and policies for similarity search
ExplanationsClaude Sonnet 4.5"Why?" explanations for suggested mappings between controls, evidence, etc.
Migration Field MappingClaude Haiku 4.5Column-to-field mapping suggestions for migration wizard imports

Analysis

AI-powered review, risk assessment, and document analysis across modules.

FeatureModelDescription
Vendor URL DiscoveryClaude Haiku 4.5Auto-discovers vendor website, trust center, and privacy policy URLs
Vendor Due DiligenceClaude Sonnet 4.5Vendor questionnaire response analysis and risk assessment
Vendor Legal ReviewClaude Sonnet 4.5Legal analysis of vendor privacy, terms of service, and data processing documents
Questionnaire ReviewClaude Sonnet 4.5AI-assisted review and scoring of questionnaire responses
Risk RemediationClaude Haiku 4.5Remediation plans and treatment suggestions for identified risks
Document AnalysisClaude Sonnet 4.5Evidence document analysis for compliance completeness
Evidence MappingClaude Haiku 4.5Mapping evidence artifacts to framework controls
Evidence ReviewClaude Sonnet 4.5Evidence review against control requirements for external audit assessments
Task PrioritizationClaude Haiku 4.5Compliance-aware rationale for dashboard task priority rankings
Security AnalysisClaude Haiku 4.5Network security group rule analysis for misconfigurations and overly permissive access
Infrastructure RemediationClaude Haiku 4.5Step-by-step remediation with AWS CLI commands for infrastructure findings
Transcript AnalyserClaude Sonnet 4.5Compliance meeting transcript analysis with categorized action items
PIA Gap AnalysisClaude Sonnet 4.5Privacy impact assessment gap analysis across GDPR, CCPA, and ISO 27701
Scan Finding AnalysisClaude Haiku 4.5Vulnerability scan finding explanation, impact, and remediation guidance
Contract Commitment ExtractionClaude Sonnet 4.5Security and compliance commitment extraction from customer contracts
Contract Text OCRClaude Haiku 4.5Text extraction from scanned/image-based PDF contracts via Textract

Generation

Content creation, drafting, and structured data generation.

FeatureModelDescription
Policy DraftingClaude Sonnet 4.5Policy document generation from framework requirements (streaming)
Report NarrativeClaude Sonnet 4.5Executive summary and compliance report narrative generation (streaming)
Initiative Status UpdateClaude Sonnet 4.5Status updates for initiatives based on description and supporting tasks
AI Generate (General)Claude Haiku 4.5General-purpose generation via the prompt template system
Policy Variable SuggestionsClaude Sonnet 4.5Suggests template variable placements in policy content
Evidence Gap SuggestionClaude Haiku 4.5Draft evidence requests for controls lacking evidence mappings
Activity GenerationClaude Haiku 4.5Draft recurring activity definitions for controls without activity mappings
Assessment Finding GenerationClaude Haiku 4.5Formal assessment finding drafts from auditor descriptions
BIA Environment ImportClaude Sonnet 4.5BIA record generation from environment description with vendor/risk linking
Risk Register GenerationClaude Sonnet 4.5Risk register records from environment description with control mapping
AI WorkspaceClaude Sonnet 4.5General-purpose assistant with document upload, analysis, and streaming chat
PIA Section DraftingClaude Sonnet 4.5Privacy impact assessment section responses given vendor context
Training Content GenerationClaude Sonnet 4.5Complete training modules with slides, quizzes, scenarios, and artifacts
Infrastructure Diagram — AI GenerateClaude Sonnet 4.5Network infrastructure diagrams from text descriptions (streaming)
Infrastructure Diagram — Import from FileClaude Sonnet 4.5Infrastructure component extraction from uploaded PDF or image diagrams
Customer Notification DraftClaude Sonnet 4.5Customer notifications personalized to tier, contract language, and incident details

Models

ModelUse Cases
Claude Sonnet 4.5Complex analysis, document review, detailed generation, streaming tasks
Claude Haiku 4.5High-volume field suggestions, quick mappings, lightweight analysis
Titan Embeddings V2Vector embeddings for similarity search across compliance records

Prompt Templates

Features marked with a Prompt button have editable prompt templates. Each template includes:

FieldDescription
System PromptInstructions defining the AI's role, tone, and constraints
User Prompt TemplateThe prompt sent to the model, with {{variable}} placeholders
Model OverrideOptional model different from the feature default
Max TokensMaximum response length
TemperatureCreativity level (0 = deterministic, 1 = creative)

Template Variables

Templates use {{variableName}} placeholders populated from record fields at runtime. Available variables depend on the feature type and record context.

Inference Settings

Each feature has configurable inference parameters accessible via the Settings button:

  • Max Tokens — Limit response length (higher = longer, more detailed)
  • Temperature — Control randomness (0.0 = consistent; 1.0 = varied)

For compliance tasks, lower temperatures (0.0–0.3) produce more reliable outputs. For creative tasks like policy drafting, slightly higher temperatures (0.3–0.7) add useful variety.

Access Control

AI feature management follows the platform's role hierarchy:

RoleCapabilities
Platform AdminConfigure all features, models, prompts, and inference settings
Tenant AdminView feature configurations; request changes through support
User / AuditorUse AI features where enabled; no configuration access