Step 1 of 5Brief
01 · Guided scenario · SaaS

Read the scenario brief

Demo mode — sign in to save your work

Treat the assignment as a multi-tenant product release where customer data, contractual promises, supplier changes and rollback readiness matter.

PRACTICE MODELoading

Restoring your saved mode and lab work…

SAAS WORKING CONTEXT

SaaS operating brief

A fast-growing software provider is embedding third-party AI into a multi-tenant product. Enterprise customers expect security, reliability and contractual clarity.

Evidence bar
  • Tenant-isolation and prompt-injection tests
  • Supplier change and incident terms
  • Release, rollback and customer-notification plan
WEEKS 10–11

GenAI, RAG and agent security

Threat-model the RAG and agent architecture, define security controls and decide whether the pilot is safe to release.

Practical output
RAG Risk Checklist · Agentic AI Control Checklist · System Card · AI Testing and Evaluation Plan · AI Incident Report Form · External Incident Communication Plan
FICTIONAL OPERATING ENTITY
SAAS ENTITYHelix Advisory CloudBase training lab: Helix Advisory Group
Threat-model the RAG and agent architecture, define security controls and decide whether the pilot is safe to release.

Helix Advisory Cloud plans a multi-tenant AI assistant that retrieves customer documents, drafts answers and prepares CRM tasks after user confirmation. It uses a hosted proprietary language model, embeddings and role-filtered retrieval.

IN SIMPLE TERMS

The software company wants an AI assistant that can search each customer's private files, draft work and prepare actions. Users confirm actions, but weak permissions or malicious instructions could expose data or trigger the wrong task.

KNOWN FACTS
  • The assistant retrieves documents from separate customer tenants
  • A hosted proprietary model generates answers and draft actions
  • Role permissions should filter retrieval before content reaches the model
  • Users must confirm CRM or email actions
  • Tenant-isolation, prompt-injection and rollback testing are incomplete
COMMERCIAL SIMULATION FILE

Inspect the evidence before you advise

The documents contain incomplete, conflicting and potentially unreliable evidence. Treat each claim according to its source.

OPERATING CONTEXT

A fast-growing software provider is embedding third-party AI into a multi-tenant product. Enterprise customers expect security, reliability and contractual clarity.

COMMERCIAL PRESSURE

Sales has promised the capability to two strategic customers, but engineering has only one sprint left before the announced release.

EXPECTED EVIDENCE
  • Tenant-isolation and prompt-injection tests
  • Supplier change and incident terms
  • Release, rollback and customer-notification plan
STEERING MEETING BRIEF

Conflicting demands, limited time, unclear ownership

Decision deadline
The steering committee meets in 10 working days. The launch slot will be lost if the decision is deferred beyond this meeting.
Budget constraint
Only GBP 28,000 remains in the assurance budget. Full independent testing was quoted at GBP 46,000, so the team must prioritise risk-based work.
Ownership gap
Product, Risk and Operations each believe another function owns final residual-risk acceptance. The governance charter is silent.
Executive sponsor

Approve now with post-launch monitoring; delay threatens the business case.

Risk partner

Do not approve until critical evidence gaps and the unnamed risk owner are resolved.

Operations lead

The existing manual process is already failing service targets and creates its own harm.

Supplier account director

The product is proven in comparable organisations, but bespoke evidence requires a paid assurance package.

OwnerChief Product OfficerClassificationInternal

Shows the reporting lines and decision rights relevant to the proposed AI use.

Executive sponsor
Chief Product Officer owns the business outcome and has requested the team to threat-model the rag and agent architecture, define security controls and decide whether the pilot is safe to release. The decision must be judged against tenant-isolation and prompt-injection tests.
Delivery chain
Chief Product Officer -> Product Director -> AI Product Owner -> Data Science Lead -> Operations Manager. Procurement manages the supplier; Information Security and Data Protection are consulted.
Approval ambiguity
The Product Director believes Risk accepts residual risk. Risk states that the accountable business executive must accept it. No committee terms of reference name the final approver.
Three lines
First line operates the system; second line sets policy and challenges risk; Internal Audit has not included the system in its current plan.
YOUR REVIEWER

AI security review board

Can the RAG or agent system resist untrusted content and prevent unauthorised actions?

Start with evidence, not assumptions.

Record unknowns explicitly. Do not convert a supplier claim into a fact merely because it appears in the business case.