How it works
This tool is a risk‑weighted backlog generator built on the LLDF agentic model. It locks the sensitivity tier to Tier 3 · Regulated, then weights every control by:
BaseImpact × Exposure × DataTier (3)Exposure is derived from runtime toggles and execution conditions.
Deliverables
Architecture Snapshot
Define your runtime exposure profileRuntime exposure
Set the toggles that match how your AI system runs in production.
Reality checks (recommended)
Refine your leverage map without requiring vendor details.
Highest‑Leverage LLDF Layers
Your leverage map (Tier 3 · Regulated)Top 3 leverage layers
Generated from exposure toggles and execution conditions. Tier‑3 always elevates L4 and L6.
Layer heatmap (L1–L6)
Highest → do first · High → next 30–90 days · Baseline → required
Tier‑3 Control Backlog
Prioritized controls aligned to exposure togglesGenerate a prioritized backlog of Tier‑3 controls mapped to LLDF layers and Prevent/Detect/Respond categories.
| # | Technique | Exposure | Risk Score | Layers | P/D/R | Owner |
|---|---|---|---|---|---|---|
| Generate a backlog to see the highest‑impact controls for Tier‑3 regulated leakage risk. | ||||||
Action Plan Builder
Assign owners, sprint targets, and exportSelected plan items
| # | Control | Owner | Sprint | Layers | P/D/R | Remove |
|---|---|---|---|---|---|---|
| No items yet. Open a backlog row and click "Add to action plan." | ||||||
Plan summary
Each planned control needs: (1) config or code change, (2) detection/telemetry, (3) evidence artifact(s), (4) regression test.
Evidence Kit
Tier‑3 audit-ready · repeatable and defensibleDefines what to capture so you can prove controls work without creating unnecessary privacy risk.
Prompt/policy versions, routing decisions, context provenance, tool invocations, retrieval logs
Policy compliance rate, grounding/citation coverage, refusal drift over time
Leakage attempt/success rate, blocked tool misuse rate, deviation from intent/policy
Runbooks, escalation paths, change approvals, MTTD/MTTR drills, regression pass rate
Next Steps
Stage 2 → Stage 3: OperationalizeOperationalize real behavior
Stage 2 produces a Tier‑3 backlog and execution plan. Stage 3 (Train) turns it into repeatable practice by role.
Generate the Tier‑3 backlog or add at least one control to the Action Plan to continue.
Runs entirely in your browser. Don't paste regulated data. Export your backlog, action plan, and evidence kit locally.