Help center
How your next step is recommended.
The recommendation is computed from your own recorded data. No model decides it.
Kanonik shows you a single recommended next step, and sometimes a suggested prompt to paste into your own AI. This page explains where those come from. It is written to be read by your security team, so it is precise about what does the work, what data is used, and what is deliberately not done.
The short version: the recommendation is computed by Kanonik from your own recorded data. No AI model decides your next step, and no model is called to produce the recommendation. When a suggested prompt is offered, it is a pre-written template. Any reasoning on top of it happens in your own AI, under your control.
How the next step is chosen
Kanonik looks at the state of your compliance record and picks the single highest-value action for where you are right now. It answers questions like: have you selected a framework, is your company profile complete, has your AI connected yet, is anything waiting for your approval, and which requirements are not yet covered. Each of these is a plain fact already present in your workspace.
From those facts, Kanonik follows a fixed order of priorities and returns exactly one step. Onboarding steps come first, then anything waiting for your approval, then closing coverage gaps, then producing your audit evidence, and finally a calm steady state when nothing needs you. The first unmet item in that order is what you see.
Because this is a fixed set of rules over your own data, the same situation always produces the same recommendation. There is no guesswork and no model opinion involved. When you finish a step, the recommendation moves on by itself and never asks you to repeat something you have already done.
What the suggested prompts are
For some steps, Kanonik offers a suggested prompt: a short, ready-made message you can copy and paste into your own AI to get moving. These prompts are written in advance by Kanonik. They are plain language, they never state a compliance conclusion for you, and they always ask your AI to propose each change for you to approve one at a time.
A suggested prompt is a starting point, not an instruction that runs on its own. You paste it into your AI when you are ready, and nothing happens until you do.
Who does the reasoning, and who pays
You bring your own AI. When you paste a suggested prompt, the thinking is done by your own AI provider, using the model you have chosen. Kanonik does not run that model and does not pay for it. This keeps you in control of which model handles your compliance work and of what it costs.
Kanonik supplies the structure and the safe starting prompt. Your AI supplies the reasoning. Your recorded data supplies the context. Each part has a clear owner.
What this means for your data
Producing the recommendation does not send your data to any AI model. The recommendation is built by reading a few facts from your own workspace and applying a fixed set of rules. There is no model call when the guidance appears on your screen, so there is no per-page cost and no exposure of your data to an outside model just to tell you what to do next.
Your data is used by an AI model only when you choose to act, by pasting a prompt into your own AI. At that point your AI reads the context it needs through its own connection to Kanonik, under your agreement with your AI provider.
The limits we hold ourselves to
The recommended next step follows firm rules that protect you:
- It never tells your AI to skip your approval. Every change your AI proposes still comes back to a person to approve before it is recorded.
- It never tells your AI to bypass the safety check that reviews each change.
- It respects your role. If you are not allowed to approve changes, it asks you to reach the right approver on your team rather than telling you to approve.
- It stays inside your active workspace and speaks only about your own record.
- It shows one step at a time, so you are never handed a long list with no clear place to start.
What it will and will not do
It will point you to the most useful next action, name what is missing when there is a coverage gap, and hand you a safe prompt to move forward with your own AI.
It will not make a decision for you, act on your behalf, or record anything without your approval. The recommendation guides the work. You and your AI do the work, and you approve every change.
More help
Browse every article in the Help center, where you can also ask the Kanonik assistant directly. For anything else, email [email protected] and a person who works on the product answers.