AI Sidekick
Meet the five expert personas, start your first conversation, and know when Sidekick pauses for your approval.
AI Sidekick is the platform's built-in AI vCISO. Rather than one generalist assistant, it is offered as five expert personas, each suited to a different job, with a human always in the loop before anything higher-risk happens.
Meet the personas
Each one introduces itself by name in the chat, so the names are listed here too.
| Persona | Name | Best for |
|---|---|---|
| CISO | Faust | Executive-level risk summaries, compliance status and deciding what to prioritise first. This is the persona you land on by default. |
| Compliance Officer | Lex | Mapping controls to frameworks, reviewing assessment scores and gaps, and drafting remediation proposals. |
| Security Analyst | Sage | Triaging findings and vulnerabilities, correlating CVEs, and ranking remediation by real risk rather than raw counts. |
| Incident Responder | Robin | Scoping an incident fast: affected assets, related findings, and open vulnerabilities at a glance. |
| Pentester | Janus | Enumerating your attack surface and identifying high-value targets, always within authorised scope. |
Starting a conversation
Open a persona from the AI Sidekick group in the left-hand navigation, or switch between them using the tabs at the top of the page once you're there. Switching doesn't lose your place, since each persona keeps its own separate conversation.
The first time you open a persona, it greets you with what it can help with and a handful of example prompts you can click to send straight away.
Every persona can reach every capability. Choosing one picks the perspective you get — Lex cites chapter and verse, Sage reasons from evidence, Faust leads with the business impact — not what the assistant is able to do. Ask Sage a compliance question or Janus about your plan and you get an answer. What you are permitted to change is decided by your own role and the approval rules.
Nothing to show yet?
A persona's advice is only as good as what it can see. Run the setup wizard and let your first scan and assessment complete before expecting much beyond general guidance. See Getting started.
Ask about the product, not just your data
Every persona can also answer questions about the platform itself, from this documentation and from your plan: how a feature works, what your plan includes, how close you are to each limit, why something asked you to upgrade, and what the next plan up would unlock. It links the documentation page it used, so you can check the answer. Ask "how close am I to my plan limits?" and you get domains, assets, projects, seats, scans this month, AI credits and evidence storage in one reply, with the numbers you would actually hit.
The same two capabilities are available to your own agent over MCP — see Connect your AI agent.
When Sidekick needs your approval
Most actions run on their own
Reading your findings and routine triage happen without asking. Higher-risk or hard-to-reverse actions, including accepting a risk during triage, pause and show an inline card asking you to approve or reject. Nothing runs until you do.
This applies across every persona: the point of AI Sidekick is to save you the busywork of reading and drafting, not to make decisions on your behalf that you would want to have made yourself.
Tailoring a persona
Under organisation settings, an Agent personas tab lets an admin set a short operating policy per persona and a handful of shared facts the assistant should remember across conversations, for example a compliance deadline or a system that's out of scope. The same editor is also reachable mid-conversation from the gear icon on the AI Sidekick page.