What’s in This Release
- A Remediation Coworker that generates a phased, prioritized plan with rationale
- A Risk Coworker that recalibrates scores and proposes a treatment for every untreated risk
- A Findings Coworker that reconciles scan results against task status
- A Policy Coworker that drafts client-specific policies and refines them in chat
The Remediation Coworker Builds a Phased, Prioritized Plan
Building a remediation plan requires bringing together several parts of the client context: what is open, what the risk scores say, where compliance coverage is thin, and which framework matters most to this account. The Remediation Coworker reads that directly from Cynomi, covering tasks, risk scores, security posture, compliance coverage, and framework priorities, then asks a short set of planning questions.
What comes back is a phased, prioritized remediation plan with a clear rationale for each task, not an undifferentiated list. Approve it and the plan is applied straight to the task list in Cynomi. The analysis you would have done in a document becomes structured execution inside security program management, without requiring the plan to be re-entered manually.
The Risk Coworker Keeps the Risk Register Current
Risk registers can become outdated over time. Residual scores stop reflecting the controls a client has actually deployed, untreated risks sit untreated because deciding on each one takes a meeting, and the register slowly becomes a document you present rather than a tool you use. The Risk Coworker works through that in focused flows.
It recalibrates residual scores against the controls deployed for that client, proposes a treatment decision for every untreated risk, which is Mitigate, Accept, Transfer, or Avoid, and recommends which risks to flag as key. Each proposal carries documented, defensible reasoning. Approved changes are written back to the register, which keeps risk management a live reflection of what is actually deployed, and a downloadable review report captures every decision for the client’s leadership.
Why this matters
The review report is what makes this usable in a governance meeting. A risk decision your client can read the reasoning behind is a decision they can sign off on, which makes the reasoning behind the register easier to review and discuss with the client.
The Findings Coworker Reconciles Scan Results with Task Status
Scanner findings and task status can fall out of sync. A scan shows an issue is resolved while the task is still open, or a task is marked Done while the scanner still reports the finding, and reconciling the two manually adds recurring work. The Findings Coworker compares scan findings against Cynomi task status and proposes a validated status update wherever they disagree.
It can also enrich the task notes and evidence with scan-based context, so the reason for a status change travels with the task. Approve the proposals and the statuses and notes are updated directly on the tasks. Separately, it produces a client-ready Vulnerability Management brief, working through the volume of findings that comes out of the connected integrations and generating a health brief report, which turns a data set too large to read into something you can share.
The Policy Coworker Writes Client-Specific Policies
Policy work requires ongoing customization for each client. The Policy Coworker produces a domain-based policy, a consolidated policy, or an ISMS policy, built from the client’s existing policies, frameworks, control mappings in compliance management, and task context, so the document reads as the client’s own. When it is ready, save it to the platform or attach it directly to the relevant policy record.
Before it leaves the platform, you shape it in an open-ended chat rather than starting over. You can rewrite, expand, or insert sections, fill governance placeholders, translate the document into another language, ask questions about what was generated, or ask for guidance on a refinement. A clear request is applied directly; an unclear one is confirmed with you first. Nothing is finalized until you say so, which keeps the documentation you hand over under your control.
How Every Coworker Works, and Where You Stay in Control
All four share one flow. A Coworker opens within the client account, loads what is already in Cynomi, and guides you through a short, focused set of questions instead of presenting a blank page. It generates its proposals, whether a plan, a set of risk decisions, status updates, or a policy, and presents them for review. You adjust or deselect, then confirm. Nothing changes until you approve, and once you do, the Coworker writes the change into Cynomi rather than handing you something to copy across.
Four principles hold across all of them:
- Grounded in real data – recommendations are grounded in client data already in Cynomi and the context you provide
- Guided, not blank-page – each Coworker walks you through the inputs that shape its output
- Review, then apply – proposals are presented for approval before anything is written back
- Client-ready outputs – plans, reports, and policies come out structured and presentable, ready to share or export in DOCX format
One availability note: the AI Coworkers are available to Service Provider Admin users, through the AI space.
What This Changes for Your Practice
The Coworkers extend CISO Intelligence into the execution layer, where a significant portion of delivery time is spent. Remediation planning, register maintenance, findings reconciliation, and policy drafting are the four jobs that scale worst as a client base grows, because each one demands senior judgment applied to a large amount of client detail. Starting each from a grounded draft means your senior people spend their time on the judgment rather than on the assembly, and the work still carries their approval before a client sees it.