Watney
Watney is your AI governance guide. It answers plain-language questions about your program — "are we ready for an external audit?", "which vendors have no agreement on file?", "where are we weakest?" — and cites the figures it used.
How it stays grounded
Every answer is generated from a snapshot of your organization's own data: your compliance score and its dimensions, open findings by severity, overdue remediation, vendor agreement coverage, policy review status, open risks, and the AI registry: systems by stage and tier, open reviews, approvals expiring soon, systems past their re-review date, and AI vendors whose training practice is not yet known. It never sees an incident's title or narrative. Your score's Incident Response dimension, which reflects how many incidents have been open more than 30 days, is part of the snapshot, and a system card draft includes a count of that system's incidents by type. Watney is instructed to answer only from that snapshot and to say so when the snapshot doesn't contain the answer — it will not invent counts or dates, and it distinguishes what your data shows from professional inference.
What else Watney does
- Suggests a risk tier and an EU AI Act classification for an AI system, with its reasoning, from the system's page. It fills the fields; you save.
- Drafts model and system cards from the registry, in the card editor. It fills the fields; you save and publish.
- Drafts risks, remediation plans and policy text; drafts and evaluates assessment answers; explains requirements; runs mock audits; writes board narratives.
Watney never records a decision. It cannot approve or reject a system, sign a review, set a risk tier, a classification or a lifecycle stage, or publish a card. Its services and the endpoints that hand you its drafts have no code path that does, and an automated check on every change looks for one. Watney is an AI system itself, and its own system card describes it.
What it does and doesn't see
- Sees: aggregate counts, your score, and short titles you wrote (for example the titles of your top open findings). It has no free database access, but a title you type is sent as-is, so keep personal data out of finding titles.
- Single-turn: each question is answered independently from a fresh snapshot — it isn't a memoryful chatbot, so include the context you need in each question.
- Resists manipulation: your question and the snapshot are treated strictly as data. Text that tries to change Watney's task, dictate an answer, or extract its instructions is ignored, and Watney answers conservatively.
Today's brief
When AI is enabled, the Watney page leads with a daily brief: a short list of what changed in your program in the last day (posture movement, new findings, newly-overdue tasks, stale evidence) plus the single highest-leverage step to take next. The "what changed" lines are computed directly from your data and are exact; the recommended step is AI-generated from your grounded snapshot. A daily cron also notifies org admins when something material changes (this follows your weekly digest notification preference).
Evidence radar
The evidence radar is a deterministic, no-AI view of two audit risks:
- Stale evidence — files past their review date or expiry that haven't been superseded by a newer version.
- Gaps — questions you answered "yes" or "partial" that an auditor expects evidence for, but where nothing is attached.
Both are computed straight from your evidence dates and answers — there is no model involved, so the lists are exact. Each row links straight to where you fix it: a gap jumps to the question so you can attach evidence, and a stale item jumps to it in the Evidence library to refresh.
Notes
- Answers are AI-generated and stream in as they're written. Treat them as a fast read on your posture, and verify before relying on one for a compliance decision.
- Each answer has a 👍 / 👎 "Was this helpful?" control — your rating is private to your organization and helps surface which AI features are landing (see Settings → AI Usage).
- Watney is also one click away from any page via the Ask Watney button in the top bar.
- Questions are counted on Settings → AI Usage. Watney is included in Premium and Enterprise, not in the demo, and runs only after an org admin opts in.
- For the full picture of what AI can do across the app, see the AI overview.
Shortcuts
- Press <kbd>g</kbd> then <kbd>c</kbd> from anywhere to jump to Watney.
- On the Watney page, <kbd>/</kbd> focuses the question box, <kbd>Enter</kbd> sends it, and <kbd>Esc</kbd> clears and unfocuses it.