AI mode includes preconfigured agentic workflows. Each workflow analyzes Bitsight data and returns a written summary of findings and recommended actions.
This article describes what each workflow does, what you select before running it, and what the output contains.
Before you begin
- Workflows that analyze a vendor require that the vendor is in your portfolio
How do I run a workflow?
- Open AI Mode.
- Select the workflow you want to run.
- If needed, make the required selection from the drop-down menu.
- Click Run Agent.
- Review the returned results.
- (Optional) To ask follow-up questions about the results, click Analyze further.
How do I continue the conversation after a workflow runs?
Every AI Mode workflow includes an Analyze further option. Use it to continue the conversation with the AI Mode agent after a workflow runs. The workflow output stays in the chat as an attachment, so the agent uses it as context when it answers your questions.
- Run a workflow and wait for the results to appear.
- In the top-right corner of the header, click Analyze further.
- Enter your question in the chat.
Example questions:
- Ask for more detail on a recommended action.
- Ask about a specific vendor or CVE listed in the results.
- Ask the agent to explain how it reached a finding.
What are the AI Mode workflows?
AI Mode workflows are preconfigured analyses. Each workflow uses Bitsight data to produce a summary of security issues, relevant context, and recommended actions.
After any workflow completes, you can click Analyze further to ask follow-up questions about the results.
How do I assess my vendor portfolio with Mythos Supply-Chain Readiness?
Workflow name: Mythos Supply-Chain Readiness
What it does: Assesses the readiness of your vendor portfolio against automated, AI-accelerated attacks.
What you select: A tier to assess from the drop-down menu.
What the output contains:
- An executive snapshot
- CVE priority matrix
- A list of top vendors to act on
- A watch list of vendors to monitor
- A tier-wide overview
How do I find out security issues to address first with a vendor?
Workflow name: What security issues should I address first with a vendor?
What it does: Summarizes the security risk posture of one vendor, lists top security issues identified for that vendor, and provides recommendations for addressing them.
What you select: A vendor from a drop-down menu, before you run the workflow.
What the output contains:
- An executive summary
- The vendor’s current rating
- The vendor’s peer position
- Risk vector highlights
- Recommended actions
How do I find out which security issues to address first in my organization?
Workflow name: What security issues should I address first in my organization?
What it does: Summaries the security risk posture of your own organization, lists the top security concerns identified, and provides recommendations for addressing them.
What you select: Your company from a drop-down menu, before you run the workflow
What the output contains:
- An executive summary
- Your company’s current rating
- Your company’s peer position
- You top critical issues
- Risk vector highlights
- Recommended actions
How do I measure the value of my third-party risk management program?
Workflow name: Analyze TPRM ROI and Impact
What it does: Analyzes your TPRM program and reports its business value, expressed as return on investment (ROI) and impact.
What the output contains:
- An executive summary including: number of vendor monitored, your portfolio mean rating, and number of EVAs sent
- Portfolio composition
- What the program did
- Risk outcomes
- Recommended actions
How do I assess the effect of a security event on a vendor?
Workflow name: Assess Emerging Security Events
What it does: Evaluates how a critical security event affects a vendor
What you select: A major security event from the drop-down menu
What the output contains:
- An event summary
- CVSS, DVE and EPSS scores
- Major security event detail
- Portfolio impact
- Top exposed vendors
- Recommended actions
How do I find CVEs that Bitsight recently detected on a portfolio company?
Workflow name: Assess Portfolio Emerging CVE Exposure
What it does: Finds each CVE that Bitsight first detected on the selected portfolio company in the last 90 days. It ranks the CVEs by priority and gives a recommended fix for each.
What you select: A company from a drop-down menu, before you run the workflow.
What the output contains:
- An executive summary
- A list of emerging CVEs
- Recommended actions
How do I find CVEs that Bitsight recently detected on my organization or a subsidiary?
Workflow name: Assess Subsidiaries Emerging CVE Exposure
What it does: Finds each CVE that Bitsight first detected on your organization or the selected subsidiary in the last 90 days. It ranks the CVEs by priority and gives a recommended fix for each one.
What you select: Your organization or one of its subsidiaries from the drop-down menu.
What the output contains:
- An executive summary
- A list of emerging CVEs
- Recommended actions
- October 7, 2026: Added Analyze further feature steps
- October 6, 2026: Published.
Comments
Please sign in to leave a comment.