> ## Documentation Index
> Fetch the complete documentation index at: https://docs.visotrust.com/llms.txt
> Use this file to discover all available pages before exploring further.

# What You Can Ask

> Example VISO Chat Agent queries for portfolio insights, vendor lookups, assessment status, advisory triage, and other third-party risk program tasks.

VISO Chat Agent can answer questions about your program data, surface insights across your vendor portfolio, and initiate actions — all through natural language. Here's a breakdown of what you can do, with examples.

## Portfolio Insights

Ask broad questions about the state of your vendor program:

| Example question                                                                 | What you get                                                 |
| -------------------------------------------------------------------------------- | ------------------------------------------------------------ |
| "Which vendors have a High or Extreme residual risk?"                            | A filtered list of high-risk relationships with their scores |
| "How many assessments are waiting for risk review?"                              | A count and list of assessments in Review Risk status        |
| "Show me vendors that haven't been assessed in the last 12 months"               | Relationships with no recent completed assessment            |
| "Which vendors in the Engineering business unit have open remediation requests?" | Filtered list scoped to a specific business unit             |
| "What's our average residual risk across all onboarded vendors?"                 | A portfolio-level metric from Risk Insights                  |
| "Which vendors have expiring artifacts in the next 30 days?"                     | Upcoming artifact expirations across your portfolio          |

## Vendor-Specific Questions

On any relationship, open VISO Chat Agent to ask questions about that specific vendor, answered using their analyzed artifacts and assessment findings:

| Example question                                                    | What you get                                                |
| ------------------------------------------------------------------- | ----------------------------------------------------------- |
| "Does this vendor have a SOC 2 Type II report?"                     | Yes/no with the detection reference from their artifacts    |
| "What's the vendor's incident response process?"                    | A summary extracted from their submitted documentation      |
| "Are there any exceptions or qualifications in their audit report?" | Findings from the auditor review of the artifact            |
| "Does the vendor use subprocessors, and who are they?"              | Sub-processor information extracted from their DPA or SOC 2 |
| "What controls are currently unvalidated for this vendor?"          | Control gaps based on the latest assessment                 |
| "How has this vendor's risk score changed over the past year?"      | Historical risk trend for the relationship                  |

## Risk Advisories and Monitoring

Ask about emerging threats and their impact on your portfolio:

| Example question                                                 | What you get                                          |
| ---------------------------------------------------------------- | ----------------------------------------------------- |
| "Which of my vendors are affected by the latest Okta advisory?"  | Relationships with Okta as a vendor or nth-party      |
| "Summarize the impact of the MOVEit vulnerability on my program" | An impact summary scoped to your vendor relationships |
| "Which vendors haven't responded to my advisory outreach?"       | Status of pending vendor response requests            |
| "Are any of my vendors on the affected list for this CVE?"       | Exposure check across your portfolio                  |

## Assessments and Actions

Initiate workflows and get status updates:

| Example question                                                           | What you get                                         |
| -------------------------------------------------------------------------- | ---------------------------------------------------- |
| "Start a new assessment for Salesforce"                                    | Guided assessment initiation                         |
| "Send a follow-up questionnaire to the vendor with gaps in access control" | Drafts and initiates the follow-up                   |
| "Which assessments are in the 'Follow-up Recommended' stage?"              | List of assessments awaiting follow-up decision      |
| "Draft questions to ask a vendor impacted by a recent breach"              | Context-specific questions based on advisory details |
| "Who is the business owner for the Workday relationship?"                  | Relationship contact information                     |

## Trust Profile Q\&A

From your Trust Profile (**Trust → Artifact Intelligence**), ask questions answered using your organization's own Trust Profile artifacts — useful for reviewing what evidence you have on file before it's requested by a customer:

| Example question                                                    | What you get                                     |
| ------------------------------------------------------------------- | ------------------------------------------------ |
| "Do we have a current SOC 2 Type II on file?"                       | Status based on your Trust Profile artifacts     |
| "What does our DPA say about subprocessors?"                        | Extracted language from your uploaded DPA        |
| "Which security controls are covered by our current documentation?" | Control coverage summary from your Trust Profile |
| "Is our penetration test report still within its validity period?"  | Validity check on the artifact                   |

***

<Tip>
  VISO Chat Agent answers are grounded in your actual program data and artifact detections, with references to the source evidence. If an answer seems off, check the supporting references — they'll tell you exactly where the information came from.
</Tip>
