Refine Control
refine_controlRefines a security control's description with an AI sufficiency check, rejecting changes that weaken mapped objectives and flagging assertions that no longer align.
Instructions
Refine a control's description with AI-gated CO sufficiency check.
Two modes:
Provide
description: proposes a new description directly.Provide
codebase_findings: the platform proposes a description based on existing code that may already satisfy the control.Both can be provided: the platform evaluates the proposed description with the codebase findings as context.
The AI evaluates whether the mitigation group still collectively satisfies all mapped control objectives. If rejected, returns {accepted: false, reason, per_co} with per-CO reasoning.
A refinement is rejected when the proposed description would reduce the
protection the control currently states for an objective it is mapped to;
per_co names each objective and explains why. This is a decision, not a
transient error — re-wording the same narrowing will not pass it, and it
applies however well-motivated the narrowing is. A control is a requirement
that must be met to cover its objectives, so evidence that the system does
not currently meet it means the control is UNMET, never that the control
should ask for less.
After an accepted refinement the control's assertions are kept
and judged again against the new description in the background: an
assertion that still fits keeps counting as evidence, and one that no
longer fits is flagged as not aligned with the control. Read
get_sufficiency once that re-judgement lands, and replace the
assertions it names. The refinement itself supersedes nothing; the
response's superseded_assertions is always 0.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| model_id | Yes | ID of the threat model. | |
| control_id | Yes | ID of the control to refine (e.g., "CTRL-03"). | |
| description | No | Proposed new control description (optional if codebase_findings provided). | |
| justification | No | Why this refinement is appropriate (10 to 2000 characters). | |
| server_version | Yes | ||
| codebase_findings | No | Description of existing code that may already satisfy this control's objective (optional). When provided without description, the platform proposes a description. |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
No arguments | |||