Import Controls
import_controlsImport existing security controls from JSON or free text into a threat model, auto-map them to COs and deduplicate, then confirm before saving as one undoable change.
Instructions
Import existing security controls into a threat model.
Accepts structured JSON or free-text. Controls are auto-mapped to COs and deduplicated against existing ones. The parse/map/dedup runs as a background job (polled for progress), then — because this mutates the model — you are asked to confirm before the controls are saved.
The saved controls are added to the model's current controls as one
change (undoable with undo_model_change); no model version is
created, and it is refused while a control build holds the model. Nothing
runs for them unprompted: the result's awaiting_judgement lists them,
and the mitigation groups they join credit nothing and read awaiting
judgement until judge_imported_controls is called (estimate first,
then confirm_estimate=True).
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| auto_map | No | Auto-map controls to COs using LLM (default: True). | |
| model_id | Yes | ID of the threat model. | |
| free_text | No | Free-text controls (narrative/CSV/bullets). | |
| source_label | No | Origin label (e.g., "ISO 27001"). | |
| controls_json | No | JSON array of {description, co_ids?, framework_refs?}. | |
| server_version | Yes |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
No arguments | |||