Security questionnaires.
Answers you can trace.

One’s small crew of AI bots reads your policies and past answers, fills the questionnaire on its own computer, and cites the supporting passages. Missing or conflicting evidence comes back to you.

OneFableworks · Rae
Security review12 questions

Answered copy ready to review

MFA required?Yes · Sourced
Access reviews?Quarterly · Sourced
Insurance limit?Needs a person
Source · Access Control Policy §4.1

“All workforce accounts require single sign-on and multi-factor authentication.”

8 sourced · 3 need a person · 1 conflict

Fictional company · Illustrative workspace · Compressed replay

When the deal is blocked on security
  • The screenshot chase. Evidence in five different places.
  • Another security questionnaire. The same questions again.
  • Last year’s answer. This year’s policy.
  • The deal is ready. The security review isn’t.

37.3 assessment requests a month. Whistic’s 2025 report describes the average vendor workload; its survey covered 525 decision-makers at companies with 500+ employees. Read the research ↗

Start with the evidence.
Finish with a review.

Give Rae a clear instruction: answer from the Library, write the source beside each answer, and flag anything it cannot support.

TodaySearch folders, threads and old questionnaires.
With Search the policies and past answers you put in the Library.
TodayCopy the same answer into another spreadsheet.
With Let Rae write a filled copy on its computer, with a Source column.
TodayGuess which version of the policy is current.
With Compare conflicting passages in Library Review and choose which to keep.
TodayAsk the whole team to read the whole questionnaire.
With Start your review with the missing sources and disagreements Rae flags.

Give the questionnaire
a bot of its own.

An example crew. The Architect proposes yours around your work; you approve its changes.

Rae

Records & evidence

Drafts questionnaire answers from your policies. Leaves the source beside the answer and brings gaps back to you.

Alex

Vendor research

Reads a vendor’s public trust center and sub-processor list. Writes a review memo with links for you to check.

Architect

Your workspace partner

Proposes the bots, a Questionnaires table and review routines. You apply the changes you want.

Open the answer.
Check the evidence.

Choose a request. See Rae fill a copy, settle a conflicting answer, then open the file you would review.

Ready to review
OneFableworks RaeChat

Answer from our Library. Add a Source column. Flag gaps and disagreements; I’ll review and send the file.

Working with filesRae’s computer

Ready to prepare the answered copy.

Alder-answered.csvReview copy
Question / AnswerSource
Library · 8 sources

Files /

02 / The questions that need you

Rae’s assessment of this sample. A sourced draft still needs your review.

Lucid’s pre-automation baseline, reported by Conveyor. Illustrative manual effort; not time saved by One.

03 / Your review copy

Answered sheet

Fictional sample · Source column written by Rae. Missing and conflicting answers remain marked.

Review the passages, finish the gaps, then send the file yourself.

Download CSV

Keep the next review
from starting at zero.

Policy changes

Find answers that went stale

“We changed our SSO provider. Compare this note with our policies and saved answers.”

A list of affected passages and draft redlines for you to review.

Vendor review

Read before you approve a vendor

“Read this vendor’s public trust center and sub-processor list. Link what supports your memo.”

A one-page memo with source links, unanswered questions and a recommendation for you.

Access review

Prepare the list to check

“Compare these exported user lists with our leavers list. Flag accounts for my review.”

A comparison file. You decide which access to revoke in the original system.

Quarterly routine

Know which evidence is missing

“Each quarter, compare our policy set with this auditor request list. Leave a brief here.”

A brief in Rae’s chat, pointing to existing evidence and listing what you still need to supply.

The tools behind the answered file

Library: open the passage

Policies and past answers keep their source quotes. Open “Library · N sources” under a reply to see the passages it used.

Computer: work on the file

Rae can read XLSX, DOCX and PDF on its computer and write an answered copy with scripts. Download the result from Files.

Records: track the request

Confirm Rae’s proposed Questionnaires table. Use a Stage field: Received → Drafting → Needs a person → Sent.

Routines: re-check the policies

Schedule an instruction to review your policy set. The routine leaves its findings in the bot’s chat.

Library access: choose the readers

Limit a sensitive source to “Only these bots”. Export your Library when you need a copy.

Browser: fill a portal

Sign in with Take control, then let Rae fill the form. Instruct it to stop before Submit and ask you.

Connect the places
your evidence lives.

Documents, tickets, code and conversations. Choose an account, review its permissions, then give the bot a specific job.

One-click connect

Documents and knowledge · tickets and work tracking · code · chat · signatures · email and calendars

  • Google DriveOne-click connect

    Finds and reads shared files

  • Google DocsOne-click connect

    Reads and edits documents

  • Google SheetsOne-click connect

    Reads and updates spreadsheet rows

  • One-click connect

    Finds and works with workspace records

  • One-click connect

    Finds and works with workspace records

  • One-click connect

    Finds and works with workspace records

  • NotionOne-click connect

    Finds pages and updates databases

  • ConfluenceOne-click connect

    Finds and works with workspace records

  • BoxOne-click connect

    Finds and works with workspace records

  • DropboxOne-click connect

    Finds and works with workspace records

  • AirtableOne-click connect

    Finds and works with workspace records

  • JiraOne-click connect

    Reads and updates tasks

  • AsanaOne-click connect

    Reads and updates tasks

  • LinearOne-click connect

    Reads and updates tasks

  • ZendeskOne-click connect

    Reads and updates support records

  • monday.comOne-click connect

    Reads and updates tasks

  • ClickUpOne-click connect

    Reads and updates tasks

  • GitHubOne-click connect

    Reads issues and opens pull requests

    Also: Built into One. GitHub event triggers; configure a webhook.

  • GitLabOne-click connect

    Works with repository records

  • SlackOne-click connect

    Finds messages and posts updates

    Also: Built into One. Per-bot chat; ships with the next release.

    The separate per-bot chat connection ships with the next release.

  • One-click connect

    Reads schedules and meeting details

  • BoldSignOne-click connect

    Works with forms and signed documents

  • GmailOne-click connect

    Finds messages and drafts replies

  • One-click connect

    Reads mail and drafts replies

  • Google CalendarOne-click connect

    Reads availability and creates events

Connect with your key

Bring the API key for your account.

  • SafetyCultureConnect with your key

    Reads inspections and issues

  • PandaDocConnect with your key

    Works with forms and signed documents

  • SignWellConnect with your key

    Works with forms and signed documents

Needs a one-time setup

The operator must configure these before they work on the hosted service.

  • DocusignNeeds a one-time setup

    Works with envelopes and signatures

  • Dropbox SignNeeds a one-time setup

    Finds and works with workspace records

  • Needs a one-time setup

    Reads and updates support records

Bring your own MCP / OpenAPI

Add the vendor’s server or API description. Your vendor account and its permissions apply.

  • VantaBring your own MCP / OpenAPI

    Reads controls and compliance evidence

    Admin access required; regional endpoints available.

  • Bring your own MCP / OpenAPI

    Reviews controls, risks and evidence

    Regional endpoints available; actions follow your role and scopes.

  • SecureframeBring your own MCP / OpenAPI

    Reads and updates compliance records

    Choose the endpoint for your data region.

  • OneTrustBring your own MCP / OpenAPI

    Works with compliance automation records

    OpenAPI import for Compliance Automation; requires your tenant endpoint and credentials.

And more About 1,500 apps in the catalogue; some need a one-time setup.

App connections run through your workspace’s integration catalogue (Composio on the hosted service). Self-hosted availability may follow Pipedream instead.

These connection paths are documented; the listed accounts have not all been tested end to end in One.

Product names and logos are trademarks of their respective owners. Their use does not imply endorsement.

AWS, Okta and Jamf are not connected apps here today. These cloud, identity and device tools are reachable only through a suitable MCP server you add or the bot’s own signed-in browser, where that workflow is supported. One does not automatically collect their evidence.

Check the source.
Choose what needs your OK.

Bots act without asking by default. Set the controls that fit the work, and review the answers before you send them.

Sources and exceptions

Evidence must already exist.

One finds, organises and cites existing material. It must not manufacture evidence of an event or control.

Library · 1 source
“System owners review privileged access every quarter and record their decisions.”
Needs a person: the completed review record is missing.
Action confirmations

Ask before sending external email

Turn this on to review covered Gmail or Outlook sends. Example: a plain-text reply, without an attachment.

Review before gmail_send_email → security@alder.example

The review copy is ready for our team to check.

Allow onceAlways allow this toolDeny
Bot settings

Prepare drafts only

This removes every tool. The bot can write text drafts and checklists, but cannot search the Library, use its computer or reach connected apps.

Prepare drafts onlyOn
Library access

Choose who can read a source.

Set access per Library source. Credentials entered through One’s protected controls are never sent to the model.

Board policy.pdf
Only these bots
Rae
Check One’s own security and data practices ↗

Start with the review
on your desk.

  1. 01

    Bring one questionnaire

    Choose a real security review. Put its spreadsheet on the bot’s computer through Files.

  2. 02

    Add the policies behind it

    Put policies and past answers in the Library as PDF, DOCX, text or CSV. Facts from uploads are active immediately; review conflicts as they appear.

  3. 03

    Review the first draft

    Ask for a Source column and a list of gaps. Check the passages, finish the answers, then download and send the file yourself.

What a security lead
needs to know.

Does One make us compliant?

No. One prepares and organises work; it does not certify, attest or give legal advice. It has no built-in framework content. Your documents supply the requirements, and a qualified person reviews and signs.

Where do answers come from? What if there is no source?

Give the bot your policies and past answers in the Library and instruct it to answer only from those sources. Replies that use the Library show the passages. Ask it to write sources into the questionnaire and mark unsupported answers “Needs a person”. Conflicts can be resolved in Library Review. Check every answer before sending.

Can it fill our prospect’s procurement portal?

The bot can use its browser to fill a portal it can access. Use Take control to sign in; screen recording stops during your takeover. Tell the bot to stop before Submit and raise a question for you. Browse the web → Ask first is an additional computer permission, not a dedicated Submit lock.

Can it work with Vanta, Drata or another GRC platform?

Vanta, Drata and Secureframe publish remote MCP servers you can add. OneTrust offers an OpenAPI description for Compliance Automation. Your vendor account, permissions and service limits still apply. These are tools you connect, not built-in evidence collectors or a replacement for your GRC platform.

What does it connect to, and who can use the connections?

The connector list above covers documents, tickets, code, chat, signatures, email and calendars. Managed app connections need your deployment’s integration catalogue. Every one of your bots in that Space can use your connected apps. MCP servers added through the MCP servers screen can be switched on per bot.

Can we keep sensitive policies away from some bots?

Yes. Set a Library source to “Only these bots” and choose its readers. This is per-source Library access; it does not restrict access to a connected app that also holds the document. The Library reads PDF, DOCX, TXT, Markdown, CSV, JSON, HTML and public pages, but not XLSX or scanned-document OCR.

Is anything sent without us?

Bots act without asking by default. Turn on Ask before sending external email to review covered Gmail or Outlook sends on an approval card. Prepare drafts only removes all tools: no computer, Library search or connectors. In this example, Rae prepares a file and you download, review and send it yourself.

Can the crew answer questions in Slack?

Chat apps ship with the next release. The bot can reply to you or people you approve. It cannot send routine results proactively or handle approval cards in Slack; those stay in One.

Where does our data go?

It depends on your deployment and the model and connection providers you choose. Credentials are encrypted or held by the integration provider, and are never sent to the model. Review One’s Trust page and discuss the model and connector data paths when scoping an Enterprise deployment.
Read Trust ↗ · Discuss Enterprise ↗

More work your crew can prepare