Carbide Analyst is our AI assistant, built directly into the Carbide platform. It helps you get answers, take action, and move faster on your compliance and security program, all without leaving Carbide or exporting your data to a separate tool.
This page explains, in plain terms, how it works and how we’ve designed it to keep your data safe.
What Carbide Analyst Does
Instead of digging through menus or exporting data to analyze it elsewhere, you can simply ask Carbide Analyst. It can:
- Answer questions about your organization’s policies, controls, risk assessments, tasks, vendors, and assets
- Draft and update records directly in Carbide, for example creating a task, updating a risk assessment, or assigning an owner
- Help prepare reports and documentation for audits and reviews
- Read files you attach so it can reference them in the conversation
Because it’s connected to your live Carbide data, you get answers grounded in your actual environment, not generic guesses.
How It’s Built
Carbide Analyst is powered by OpenAI’s models, running under Carbide’s own OpenAI organization account. Your conversations and data are processed under our enterprise agreement with OpenAI, not a personal or third-party account.
The assistant connects to Carbide through a set of secure, purpose-built tools (using the Model Context Protocol, or MCP). Rather than giving the AI unrestricted access to a database, we give it a defined set of actions it’s allowed to take, like “look up a policy” or “create a task”, each scoped to what’s appropriate for your account and your role.
This means the assistant can be genuinely useful, reading and writing real data on your behalf, while staying inside guardrails your organization controls.
Human Control, Every Step
You stay in charge of what the assistant actually does:
- Action approval: Before Carbide Analyst makes a change (like creating or updating a record), you approve it, either one action at a time or for the rest of a conversation if you’d prefer fewer interruptions.
- Stop anytime: You can cancel a response or an in-progress action at any time.
- Full visibility: Organization admins can review assistant activity, including which tools were used and what changed, giving your team an audit trail of AI-assisted work.
Access and Permissions
Access to Carbide Analyst’s capabilities is controlled through scoped tokens tied to user roles:
- The assistant only has access to the data and actions your role is already permitted to use in Carbide. It doesn’t grant new privileges.
- Admins can issue, limit, or revoke access tokens at any time, including for external use (for example, connecting your own AI tools to Carbide via API).
- Each organization’s data is isolated; the assistant only ever works within your organization’s account.
Your Data
Conversations and actions taken through Carbide Analyst are tied to your organization’s account and subject to the same data handling and confidentiality commitments as the rest of the Carbide platform. Because Carbide Analyst runs on our enterprise OpenAI account, your data is covered by that agreement’s business data protections. It is not used by OpenAI to train their models, and it isn’t shared with or visible to other Carbide customers.