Daedalus
HomeReviewsDesignBlueprintsHistorySettings
Northwind/Reviews/HR Policy Assistant
rv-2026-0401

HR Policy Assistant

Awaiting decision
Close out findings

Submitted by Tomas Berg of People Services Digital·11 Sept 2026·Google Cloud, scored under CIS Controls v8.1 and Northwind’s own standards·matched to Internal GenAI assistant with retrieval at 86%·read from hr-policy-assistant-lld-v1.2.pdf and hr-policy-assistant-architecture.png

12 of 37 safeguards fail1 contradiction with the document
Framework
Safeguards in scope37Everything that governs a design of this shape
Failing12To close or accept before approval
Closed with evidence0Nothing closed yet
Accepted as gaps0No gap accepted
Answered0%0 of 12
Failthe design does not show the safeguard is met, whether it contradicts it or is silent on itPassthe design shows it is met, and the register cites whereSafeguards that do not govern a design of this shape are not listed.
Maps to
CAT-2Conditional services are used on their termsVertex AI is used outside its conditions of useEstate fitEstate fitService catalogueHigh
Fail
Missing
1 cited, none proving it is built
Cyber Security11 Oct 2026
LLM01Prompt InjectionNothing screens the prompt or the retrieved chunks before they reach GeminiAISecurityOWASP LLM Top 10High
Fail
Missing
3 cited, none proving it is built
People Services Digital11 Oct 2026
LLM02Sensitive Information DisclosureConfidential manager guidance can be surfaced to any employee, and answers are not screenedAISecurityOWASP LLM Top 10High
Fail
Missing
4 cited, none proving it is built
People Services Digital11 Oct 2026
LLM08Vector and Embedding WeaknessesThe vector index carries no entitlements: every employee can retrieve every chunkAISecurityOWASP LLM Top 10High
Fail
Missing
4 cited, none proving it is built
People Services Digital11 Oct 2026
REL-1No single point of failure on the critical pathThe primary data store has no standbyReliabilityReliabilityGCP Architecture FrameworkHigh
Fail
Missing
People Services Digital11 Oct 2026
11.4Establish and Maintain an Isolated Instance of Recovery DataNo isolated copy of the conversation history is describedResilienceSecurityPR.DS-11Medium
Fail
Missing
2 cited, none proving it is built
Cloud Platform Engineering10 Nov 2026
AP-2Third party in the data pathThird party in the data path: HR Policy LibraryDesign patternReliabilityDesign patternsMedium
Fail
Missing
People Services Digital10 Nov 2026
COST-4Spend is visible and attributedNo budget, alert or cost attributionCostCostGCP Architecture FrameworkMedium
Fail
Missing
Cloud Platform Engineering10 Nov 2026
LLM10Unbounded ConsumptionNo per-user quota or budget alert on the inference pathAISecurityOWASP LLM Top 10Medium
Fail
Missing
3 cited, none proving it is built
People Services Digital10 Nov 2026
MBSS-1The design names the baselines it is built to5 baselines apply and none is named in the designEstate fitEstate fitMBSS baselinesMedium
Fail
Missing
Cyber Security10 Nov 2026
REL-5Dependencies fail without taking the application downA call to HR Policy Library has no stated failure behaviourReliabilityReliabilityGCP Architecture FrameworkMedium
Fail
Missing
People Services Digital10 Nov 2026
OPS-4Runbooks exist for the likely failuresNo runbooks are referencedOperationsOperationsGCP Architecture FrameworkLow
Fail
Missing
Cloud Platform Engineering10 Dec 2026
3.10Encrypt Sensitive Data in TransitEvery hop uses TLS, including the Graph connection and the private Vector Search endpointDataSecurityPR.DS-02Low
Pass
Data Platform Engineering—
3.11Encrypt Sensitive Data at RestData at rest uses Google default encryption, which the standard accepts for Confidential dataDataSecurityPR.DS-01Low
Pass
Data Platform Engineering—
3.12Segment Data Processing and Storage Based on SensitivityThe index and the conversation store sit inside a VPC Service Controls perimeterDataSecurityPR.IR-01 · PR.DS-01Low
Pass
Data Platform Engineering—
6.3Require MFA for Externally-Exposed ApplicationsIdentity-Aware Proxy enforces corporate sign-in and MFA before requests reach the applicationIdentitySecurityPR.AA-03Low
Pass
Identity Engineering—
6.5Require MFA for Administrative AccessProject administrators use 2-Step Verification with security keysIdentitySecurityPR.AA-03 · PR.AA-05Low
Pass
Identity Engineering—
8.9Centralize Audit LogsAudit logs leave the project through the organisation-level sinkLoggingSecurityPR.PS-04Low
Pass
Cyber Security—
12.2Establish and Maintain a Secure Network ArchitecturePrivate egress, Private Google Access and a single allow-listed external destinationNetworkSecurityPR.IR-01Low
Pass
Network Engineering—
13.10Perform Application Layer FilteringCloud Armor with the OWASP rule set is attached to both backend servicesNetworkSecurityPR.IR-01 · DE.CM-01Low
Pass
Network Engineering—
16.10Apply Secure Design Principles in Application ArchitecturesOne least-privilege service account per workload, no basic rolesApplicationSecurityPR.PS-06Low
Pass
People Services Digital—
AP-1Shared databaseNo shared databaseDesign patternReliabilityDesign patternsLow
Pass
Not assessedPeople Services Digital—
AP-4Snowflake environmentThe environment is reproducibleDesign patternOperationsDesign patternsLow
Pass
Cloud Platform Engineering—
CAT-1Every service is in the catalogue and permittedAll 11 services are in the catalogue and permittedEstate fitEstate fitService catalogueLow
Pass
Not assessedCyber Security—
CAT-3Nothing depends on a service that is going awayNothing in the design is retiring or unassessedEstate fitEstate fitService catalogueLow
Pass
Not assessedCyber Security—
CAT-4Data is held only where its class is permittedEvery store is assessed for the class it holdsEstate fitEstate fitService catalogueLow
Pass
Not assessedCyber Security—
COST-1Capacity follows demandNothing runs when nothing is happeningCostCostGCP Architecture FrameworkLow
Pass
Not assessedCloud Platform Engineering—
COST-3Traffic that leaves is accounted forTraffic leaving the estate is accounted forCostCostGCP Architecture FrameworkLow
Pass
Cloud Platform Engineering—
LLM05Improper Output HandlingAnswers are rendered as Markdown with raw HTML disabled and links restrictedAISecurityOWASP LLM Top 10Low
Pass
People Services Digital—
LLM06Excessive AgencyThe model has no tools and cannot actAISecurityOWASP LLM Top 10Low
Pass
People Services Digital—
LLM07System Prompt LeakageThe system prompt holds instructions only; the one secret lives in Secret ManagerAISecurityOWASP LLM Top 10Low
Pass
People Services Digital—
OPS-1Infrastructure is defined as codeThe environment is defined as codeOperationsOperationsGCP Architecture FrameworkLow
Pass
Cloud Platform Engineering—
OPS-2Releases are staged and reversibleReleases are staged and can be withdrawnOperationsOperationsGCP Architecture FrameworkLow
Pass
Cloud Platform Engineering—
OPS-3Monitoring reaches a personAlerts reach a named rotaOperationsOperationsGCP Architecture FrameworkLow
Pass
Cloud Platform Engineering—
PERF-1Latency and throughput targets are statedThe design states what it is built to servePerformancePerformanceGCP Architecture FrameworkLow
Pass
People Services Digital—
PERF-4Scaling bounds are definedScaling bounds are setPerformancePerformanceGCP Architecture FrameworkLow
Pass
People Services Digital—
REL-2Recovery objectives are statedRecovery objectives are statedReliabilityReliabilityGCP Architecture FrameworkLow
Pass
People Services Digital—
37 of 37 rows · scored under CIS Controls v8.1A target date runs from the submission: 30 days for high, 60 for medium, 90 for low.
Ask about this reviewAnswers cite the record; click a citation to see it.
Try