What to keep human
Let your assistant do the gathering, drafting and filing — you make the attestations.
An attestation is a statement a named person is accountable for: this policy is approved, this risk is acceptable, this review was adequate. Everything before that point — pulling the data together, writing the draft, filing the document — is work, and work is exactly what you connected an assistant to do. Reading needs no rule at all; asking your assistant to look at your posture changes nothing.
The six calls to keep
An assistant holding an Owner's key can technically make every one of these six calls. The reason to keep them is not that the platform can't do it — it's that each one is a claim somebody has to stand behind.
- Approving and publishing a policy. An approval is your signature on "this is how we operate." Let the assistant mark up the draft and send it for review; you approve it.
- Accepting a risk, or setting its scores. A risk decision is a business judgment about what your company is willing to live with, and only you know that appetite. The assistant can research the risk and stage the assessment; the number and the acceptance are yours.
- Setting a vendor's risk level. No test passes or fails on this value — your auditor is the one who reads it, and they will ask you why you chose it. Have an answer that isn't "the assistant picked it."
- Answering a vendor's questionnaire on their behalf. Answers submitted this way go in as the vendor, so you are asserting something about another company's security posture. An assistant grounding those answers in the vendor's public documentation gives you a strong starting draft — never a finished answer.
- Completing a vendor review. Completing a review is a statement that the review happened and was adequate. Read what came back before you close it.
- Deciding which findings become tracked risks. Findings from a vendor review don't move onto your risk register on their own. Your register is your statement of what you're actually managing, so choose what belongs there deliberately.
This isn't a new rule invented for AI. UprootSecurity already treats approval as a human act: only the organization owner can approve a policy, and nobody can approve their own draft. Connecting an assistant doesn't loosen that — and the other five deserve the same instinct.
What your auditor actually thinks about AI-assisted work
The assistance is fine. Nobody expects you to have typed every field by hand — auditors have looked at compliance work built from templates, consultants and spreadsheets for years, and a well-drafted policy is a well-drafted policy regardless of what helped write it. What they test is whether the evidence is accurate and whether a responsible person stands behind it.
What isn't fine is an assertion with nobody accountable behind it. When an auditor points at an approved policy and asks "who approved this, and on what basis?", the answer needs a name and a reason. "Our assistant did it" is not a reason. So the thing to protect isn't the drafting — it's your ability to say, honestly, that you read it and made the call.
How to work this way in practice
Ask the assistant to prepare and stage everything, then decide.
- Have it do the legwork out loud. Ask it to pull the vendor's public security documentation, summarize the questionnaire answers it drafted, list the findings with a recommendation on each, and mark up the policy draft with a note on what changed.
- Have it stop one step short. The assistant sends the policy for review; you approve it. The assistant fills in the assessment; you accept the risk. The assistant hands you the findings; you decide which ones belong on your register.
- Then read and make the call yourself. The goal is to make the human step small, not ceremonial — five minutes of real reading on a decision that used to take an afternoon is a win. If you're clicking approve without reading, you've given up the one part of this that only you could do.
