Sign in

How analysis works

Retrieval over the project's own material, a practitioner question library, and the rules that stop it filling gaps from general knowledge.

Updated August 19, 2026
3 min read
analysis
ai
overview

Analysis runs per review area. For each area, the platform works through a question library, retrieves evidence for each question from this project's material only, and drafts a finding from what it found.

The question library

Each area's questions are written by practitioners, not improvised at run time. A question carries:

  • Phrasings. More than one way to ask, because a target's own documents will not use our words.
  • Alternate vocabulary. A company that calls it an "engineering handbook" should still match a probe for onboarding documentation. Where a target's wiki uses developer slang for a risk, retrieval searches the slang deliberately so a documented risk is not reported as unmentioned.
  • What counts as an answer. A policy document is evidence of a policy. It is not evidence the policy is followed, and the two do not get conflated.
  • What absence implies. For some questions, nothing found is neutral. For others it is itself the finding.

The evidence boundary

Two bodies of knowledge are kept strictly apart:

  • The project's material — everything you added. This is the only thing that can be cited in a finding about the target.
  • Reference material — how a well-run engineering organization usually looks, what a normal dependency profile is, what a typical control set includes. This calibrates judgment. It can never appear as a fact about the target.

That separation is why a finding can be checked. If the report says the target has no disaster recovery test on record, that statement came from the target's documents, not from an assumption about companies of that size.

Absence is a result

If the material does not answer a question, the finding says so. It is recorded as unanswered, it flows back onto the request list, and the review area's rating reflects that it could not be assessed rather than inventing a grade.

What comes out

For each area: findings with ratings, the assessment text, tables where the evidence is tabular, and citations on every statement. All of it arrives as Draft — produced from evidence, not yet read by a person.

Re-running it

Analysis re-runs when new material arrives or when you ask it to. Extraction results are cached per document by content hash, so re-running after adding two files does not re-read the other two hundred. If you need a genuinely clean pass — after changing analysis rules, for example — use the full re-analysis option, which clears the cache for that project.

What it will not do

  • Cite a document that is not in the project.
  • Answer a question the material does not answer.
  • Grade an area it could not examine.
  • Publish anything as final. Every draft waits for review.

Next

Was this article helpful?

Votes are read: an article that keeps failing gets rewritten.