concept Updated 2026-10-06

Proactive Checklist

Prompts for what is still unknown — how the engine turns near-misses into questions.

Reactive vs. proactive

Matching is reactive: it answers questions about what you have already recorded. The proactive checklist is the other half: it asks what is still unknown.

For every asset, the engine generates prompts from playbook requirements that are not yet confirmed. Each item is a question about the target:

Does this asset expose a password-reset flow?

Where prompts come from

A prompt exists because a playbook is a near-miss: some of its required components are present on the asset, but not all. The engine is telling you "this playbook is one confirmation away" — the missing required components become the prompts, ordered by how close they are to unlocking something.

Required CLQs are the most common source: a condition that is necessary for an attack to be applicable, and easy to forget to check — "does the server extract uploaded archives?" — is exactly the sort of thing worth a standing question.

Visual needed
Proactive checklist on an asset
Screenshot: asset Suggestions → Checklists with 3–4 open prompts

Resolving a prompt

Three honest answers, three different mechanics:

  • Yes — link the missing component to the asset. The prompt disappears on its own — satisfied requirements don't linger — and the playbook fires immediately if nothing else is missing. No history entry is created for a prompt that resolved itself.
  • No — only after tracing the full surface. Record the answer as a manual check; the prompt moves to the asset's history and won't be suggested again unless you remove it there. A wrong negative silently suppresses every playbook behind it.
  • Endpoint — if confirming the capability revealed where it lives, record the endpoint on the link.

Prompts that ask about a component with probes carry a probe-count badge — the context menu's View probes shows exactly how to check for it without leaving the asset.

What happens after you resolve

The engine re-evaluates the asset immediately: new suggestions appear, others disappear, and the checklist shrinks. Every resolution either unlocks a playbook or prunes the search space — which is why working the checklist is the fastest way to make the vault smarter.

Resolutions land in the asset's History → Checklists → Proactive Checks, alongside the reactive checks.

Checklist vs. coverage

The checklist is the open work for one asset; coverage measures how much of what could apply you have confirmed. Both live on the asset, and both move when you resolve prompts with evidence. See Dashboard Metrics.

What's next