Skip to content

User Guide

Last updated: July 22, 2026

This guide walks a workspace owner or governance contributor through the standard CompliAffirmAI workflow.

Before you begin

Prepare the following outside the platform:

  • a list of AI systems and embedded AI features in use or under evaluation;
  • an accountable owner for each system;
  • approved hosting and data-flow facts;
  • the organization's boundary decision;
  • applicable framework packs;
  • non-regulated evidence files or HTTPS references; and
  • reviewers authorized to approve governance statements.

Do not prepare or upload CUI, PHI, payment-card data, credentials, customer production records, raw prompts/outputs, source code, or secrets.

1. Create and secure your account

  1. Open compliaffirmai.app.
  2. Select Create account and enter the requested identity details.
  3. Open the confirmation email and complete the confirmation flow.
  4. Sign in.
  5. Open Account -> Multi-factor authentication.
  6. Enroll a TOTP authenticator and verify the current code.
  7. Save recovery information according to your organization's password and recovery policy.

Owner and administrator tenant access requires AAL2 MFA. Never share a session, password, recovery code, or TOTP seed.

2. Select a plan and framework access

Open Billing.

  • Solo supports one system and requires one framework choice in addition to Core.
  • Professional supports up to three systems and includes Core, CMMC, TRAIGA, and HIPAA packs.
  • Partner is sales-assisted and is intended for advisors managing client organizations.

Initial self-service Checkout requires the confirmed workspace owner. Entitlements become active only after the signed billing event is processed. If the browser returns from Checkout before access updates, wait briefly and refresh Billing; do not purchase a second subscription.

3. Register an AI system

Open Register AI system and complete:

  1. System name: the recognizable product, feature, or internal system name.
  2. Vendor: third party or internal team responsible for the system.
  3. Model family: optional technical family or classifier name.
  4. Business owner: accountable person or role.
  5. Hosting: Public SaaS, Commercial API, Private cloud VPC, GovCloud, On premise, or Unknown.
  6. Boundary designation: Inside assessed boundary, Outside boundary, Prohibited from CUI, or Not applicable.
  7. Data classes touched: choose only data the approved workflow is permitted to access. "None sensitive" cannot be combined with another class.
  8. Framework packs: Core is always included. Add CMMC, TRAIGA, or HIPAA only when applicable and entitled.
  9. Purpose statement: at least 200 characters covering business purpose, users, inputs, outputs, decision role, prohibited data, and required human review.

Example purpose pattern:

The system supports [approved business purpose] for [authorized users]. Inputs are limited to [approved non-regulated categories], and outputs are used for [advisory/draft/classification purpose]. It may not receive [prohibited data]. A human owner reviews [specified decisions or external outputs] before use.

Use this structure, but replace the brackets with accurate governance metadata. Do not paste sample customer data.

Select Create registry record. The new system opens in AI Systems.

4. Answer mapped questions

  1. Open AI Systems and select the system.
  2. Review each question's category, help text, and mapped control codes.
  3. Select the answer that reflects the approved current state, not the desired future state.
  4. Add metadata-only explanation where the question permits free text.
  5. Save the answer.
  6. Review any rule finding and remediation options.

Understanding coverage

  • Not assessed: no current answer.
  • Attested: an answer exists, but qualifying evidence is not linked.
  • Partially evidenced: some support exists, but the mapped requirement is incomplete.
  • Evidenced: the answer and linked support satisfy the deterministic evidence rule.
  • Gap: the answer, support, or required condition does not meet the mapped rule.

These are workflow states, not audit findings or legal conclusions.

5. Attach evidence

File evidence

  1. Save the mapped answer first.
  2. Open Evidence upload.
  3. Choose the system and saved answer the evidence supports.
  4. Select an approved file: PDF, CSV, XLS, XLSX, DOC, DOCX, PNG, JPG, or JPEG, no larger than 25 MB.
  5. Select Upload and scan.
  6. Wait for upload, SHA-256 verification, malware scanning, and sealing to finish.
  7. Confirm Scan passed before relying on the evidence.

If the result is pending, failed, or quarantined, the file is not approved for use in the workflow. Follow the Troubleshooting Guide.

HTTPS reference evidence

Where a question accepts a reference, use an approved HTTPS URL that points reviewers to the authoritative source. Do not use a URL that bypasses access controls or publicly exposes restricted material.

Evidence quality tips

A strong evidence reference identifies:

  • the exact control or statement supported;
  • the owner and review date;
  • the applicable system and environment;
  • the version or effective period; and
  • how a reviewer can verify authenticity.

Avoid generic evidence attached to every question without a clear relationship.

6. Review governance readiness

For a TRAIGA-enabled system, open the NIST AI RMF + TRAIGA panel on the system page.

  1. Review the summary counts and the GOVERN, MAP, MEASURE, and MANAGE grouping.
  2. Open each mapping to see question status, controls, evidence, and source links.
  3. Resolve incorrect answers or missing evidence at the source question.
  4. Do not change an answer solely to improve the score; the record must reflect the approved current state.

The panel is designed to prepare a review record. It does not state that the organization substantially complies with NIST, qualifies for a TRAIGA protection, or has completed legal analysis.

7. Record an internal review

In the readiness panel, use Record internal review:

  1. enter the review date;
  2. describe the metadata-only scope;
  3. summarize findings;
  4. select remediation status;
  5. describe remediation and policy changes, if any;
  6. add an approved artifact or HTTPS evidence reference; and
  7. if a suspected violation was discovered, select the checkbox and provide the required discovery summary.

Records are append-only. If a conclusion changes later, add a new review rather than rewriting history.

8. Record internal testing or red-team activity

Use Record internal test:

  1. enter the test date;
  2. describe scope and method without sensitive payloads or exploit material;
  3. summarize findings and remediation;
  4. link approved evidence; and
  5. record whether a suspected violation was discovered.

Store detailed restricted test material in your approved security repository and place only the authorized reference and summary in CompliAffirmAI.

9. Generate an artifact

Open Artifacts.

  1. Select the artifact type.
  2. Select the applicable system.
  3. Review the manifest preview, audience, template version, and ledger head.
  4. Select Generate artifact.
  5. Wait for the new record to appear under Recent exports.
  6. Download the available JSON or PDF. A TRAIGA Cure Binder also supports ZIP.

Before external sharing:

  • verify the system and organization identifiers;
  • review attested, evidenced, and gap items;
  • confirm evidence references are authorized for the recipient;
  • verify the ledger and manifest hashes when required;
  • remove or correct inaccurate source records through the documented workflow; and
  • obtain the appropriate security, compliance, management, and legal review.

10. Review a TRAIGA Cure Binder

The ZIP contains:

  • registry/system.json;
  • assessment/readiness.json;
  • evidence/evidence-index.json;
  • reviews/internal-reviews.json;
  • testing/testing-log.json;
  • sources/framework-sources.json;
  • LEGAL_NOTICE.txt; and
  • manifest.json.

The manifest lists SHA-256 and size for the seven package members other than the manifest itself. Verify these hashes before relying on a transferred package. The binder indexes evidence; it does not automatically place every private evidence binary inside the ZIP.

11. Verify the ledger

Open Ledger verify.

  1. Load the current organization events.
  2. Start verification.
  3. Confirm the result reports a clean chain, or preserve the first divergence report.

A clean result means the event sequence and recorded hashes are internally consistent. It does not prove that an attestation was correct or approved.

12. Use the dashboard and training center

  • Use Dashboard for current system and artifact status.
  • Use Training for guided workflow lessons and reminders about metadata-only use.
  • Use Settings to review membership, billing, notification, and security paths.
  • Partner-entitled users can use Partner console for client-organization workflow entry points.

13. Manage billing and account security

Billing

Owners and administrators can open the Customer Portal after completing MFA. Subscription changes are reflected after signed provider events update the workspace entitlement.

Account

Use Account to:

  • verify your role and organization;
  • enroll or verify MFA;
  • reset your password;
  • open Billing or Settings;
  • submit support requests;
  • request a workspace export; and
  • submit a deletion request.

Workspace export requires Owner/Admin access. Deletion requests require owner verification and retention review; an append-only ledger or other legal obligation may require selected records to be retained.

14. Request support

Open Support and choose the category that best matches the issue. Provide metadata-only details, affected page, approximate time, and visible identifiers. Review Support history before resubmitting.

For urgent suspected security issues, email security@compliaffirmai.app. For normal product help, email support@compliaffirmai.app.

Golden-path completion checklist

  • [ ] Account confirmed and MFA verified.
  • [ ] Correct plan and framework entitlement active.
  • [ ] AI system registered with an accountable owner and approved purpose.
  • [ ] Applicable mapped questions answered accurately.
  • [ ] Evidence attached only to the answers it supports.
  • [ ] Evidence scan status is clean before use.
  • [ ] Readiness gaps reviewed and assigned.
  • [ ] Internal review and testing records appended where applicable.
  • [ ] Artifact generated from the correct system and ledger head.
  • [ ] Export reviewed by authorized stakeholders before sharing.
  • [ ] No CUI, PHI, credentials, or prohibited customer content entered into the platform.

Back to Client Documentation

Governance documentation and review support. Not legal advice or certification.