---
isPublished: true
template: "page.peb"
title: "Risk Assessment Policy"
displayName: "Risk Assessment Policy"
description: "Public security, privacy, AI, provider, and operational risk assessment principles for iDialogue."
category: "trust"
contentType: "policy"
audience: "end-user"
tags: "trust,policy,risk-assessment,nist,ai-risk"
section: "trust"
effectiveDate: "2026-05-22"
lastReviewed: "2026-05-22"
owner: "Security and Privacy"
contact: "support@idialogue.app"
seoTitle: "iDialogue Risk Assessment Policy"
seoDescription: "Review how Pacific Apps identifies, evaluates, treats, owns, and reassesses security, privacy, AI, and operational risks."
---

## Risk Assessment Policy

**Effective date:** May 22, 2026  
**Last reviewed:** May 22, 2026  
**Policy owner:** Security and Privacy  
**Entity:** Pacific Apps, Inc., provider of iDialogue  
**Contact:** [support@idialogue.app](mailto:support@idialogue.app)

<h2 id="purpose">Purpose</h2>

This policy establishes requirements for identifying, assessing, treating, owning, and reassessing security, privacy, AI, third-party, availability, financial, and operational risks affecting iDialogue and customer workflows.

<h2 id="assessment-events">Assessment events</h2>

A risk assessment is required when material changes or events could affect the security, privacy, availability, or appropriate use of iDialogue, including when:

- a material feature, agent capability, data class, provider, or public endpoint is introduced;
- Salesforce permissions, sharing, or integration identity change materially;
- a workflow introduces background execution, external sharing, public publishing, or consequential automated actions;
- a material vulnerability, incident, provider notice, or regulatory change occurs;
- customer requirements introduce higher-sensitivity data or higher-impact actions; or
- periodic review identifies changes in likelihood, impact, or control effectiveness.

<h2 id="method">Method</h2>

A risk assessment documents:

1. the system, workflow, data, users, and business purpose in scope;
2. credible threats, failure modes, and misuse scenarios;
3. existing preventive, detective, and corrective controls;
4. likelihood and impact, including customer and tenant effects;
5. the treatment decision and resulting residual risk;
6. the accountable owner and target review or completion date; and
7. the evidence required to verify mitigation, closure, or formal acceptance.

<h2 id="ai-and-agent-risk">AI and agent risk</h2>

AI and agent risk assessments consider applicable risks such as:

- prompt injection and adversarial input;
- excessive or inappropriate tool authority;
- over-broad Salesforce, file, or knowledge context;
- unintended data disclosure;
- inaccurate extraction or generated claims;
- model and provider dependency;
- retained conversation or provider state;
- inappropriate external sharing or public publishing; and
- consequential actions performed without appropriate review.

Controls may include reducing supplied context, limiting tools, using least-privileged Connections, validating structured output, preserving source references, requiring human approval, applying usage limits, monitoring activity, or using a deterministic non-AI workflow where appropriate.

<h2 id="framework-mappings">Framework references</h2>

Pacific Apps uses the **NIST Cybersecurity Framework (CSF)** as an input to cybersecurity policy and risk management.

The **NIST AI Risk Management Framework (AI RMF)** and **MITRE ATLAS** inform AI-risk assessment and threat-modeling practices.

These references do not represent a completed framework mapping, certification, independent attestation, or government authorization.

<h2 id="treatment-and-acceptance">Treatment and acceptance</h2>

Risks may be reduced, avoided, transferred, or accepted.

Material risk acceptance requires a documented rationale, accountable owner, applicable compensating controls, approval, and a review or expiration date.

Risks that could affect customer commitments, data protection, security obligations, or service availability must be escalated to the appropriate business and security owners.

<h2 id="customer-specific-review">Customer-specific risk reviews</h2>

Enterprise deployments may require assessment of the specific Salesforce configuration and workflow.

Customers can request a scoped review covering Salesforce identity and permissions, objects and fields, files, agent tools, processing providers, storage, sharing, retention, approvals, and available assurance evidence.

Contact [support@idialogue.app](mailto:support@idialogue.app).

## Related information

- [AI &amp; Agent Governance](/trust/ai-agent-governance.html)
- [Vulnerability Management Policy](/trust/compliance/vulnerability-management.html)
- [Third-Party Security Policy](/trust/compliance/third-party-security.html)