Risk Assessment Policy
Effective date: May 22, 2026
Last reviewed: May 22, 2026
Policy owner: Security and Privacy
Entity: Pacific Apps, Inc., provider of iDialogue
Contact: support@idialogue.app
Purpose
This policy establishes requirements for identifying, assessing, treating, owning, and reassessing security, privacy, AI, third-party, availability, financial, and operational risks affecting iDialogue and customer workflows.
Assessment events
A risk assessment is required when material changes or events could affect the security, privacy, availability, or appropriate use of iDialogue, including when:
- a material feature, agent capability, data class, provider, or public endpoint is introduced;
- Salesforce permissions, sharing, or integration identity change materially;
- a workflow introduces background execution, external sharing, public publishing, or consequential automated actions;
- a material vulnerability, incident, provider notice, or regulatory change occurs;
- customer requirements introduce higher-sensitivity data or higher-impact actions; or
- periodic review identifies changes in likelihood, impact, or control effectiveness.
Method
A risk assessment documents:
- the system, workflow, data, users, and business purpose in scope;
- credible threats, failure modes, and misuse scenarios;
- existing preventive, detective, and corrective controls;
- likelihood and impact, including customer and tenant effects;
- the treatment decision and resulting residual risk;
- the accountable owner and target review or completion date; and
- the evidence required to verify mitigation, closure, or formal acceptance.
AI and agent risk
AI and agent risk assessments consider applicable risks such as:
- prompt injection and adversarial input;
- excessive or inappropriate tool authority;
- over-broad Salesforce, file, or knowledge context;
- unintended data disclosure;
- inaccurate extraction or generated claims;
- model and provider dependency;
- retained conversation or provider state;
- inappropriate external sharing or public publishing; and
- consequential actions performed without appropriate review.
Controls may include reducing supplied context, limiting tools, using least-privileged Connections, validating structured output, preserving source references, requiring human approval, applying usage limits, monitoring activity, or using a deterministic non-AI workflow where appropriate.
Framework references
Pacific Apps uses the NIST Cybersecurity Framework (CSF) as an input to cybersecurity policy and risk management.
The NIST AI Risk Management Framework (AI RMF) and MITRE ATLAS inform AI-risk assessment and threat-modeling practices.
These references do not represent a completed framework mapping, certification, independent attestation, or government authorization.
Treatment and acceptance
Risks may be reduced, avoided, transferred, or accepted.
Material risk acceptance requires a documented rationale, accountable owner, applicable compensating controls, approval, and a review or expiration date.
Risks that could affect customer commitments, data protection, security obligations, or service availability must be escalated to the appropriate business and security owners.
Customer-specific risk reviews
Enterprise deployments may require assessment of the specific Salesforce configuration and workflow.
Customers can request a scoped review covering Salesforce identity and permissions, objects and fields, files, agent tools, processing providers, storage, sharing, retention, approvals, and available assurance evidence.
Contact support@idialogue.app.