Each workspace member connects their own provider and API key. Conversations are scoped to the member who created them and are not shared with other workspace members.
Key concepts
Agent modes
The mode selector in the chat UI chooses how the assistant behaves. The assistant works in two ways: Answer mode (quick questions) and Agent mode (it runs multi-step analysis for you).Answer mode
Answer mode — conversational Q&A over your workspace data. The assistant answers questions about your attack surface using the data already collected in your workspace, such as assets, vulnerabilities, targets, and scan results. Use Answer mode when you need a quick answer:- “How many assets are publicly exposed?”
- “Which vulnerabilities are open and what is their severity?”
- “What technologies run on our public-facing servers?”
- “Summarize the latest scan results for our main domain”
Agent mode
Agent mode — autonomous multi-step analysis. The assistant plans and executes a sequence of analysis steps against your workspace, using tools and workspace memory to reach a conclusion. Use Agent mode when a task spans multiple steps:- Correlate findings across assets, vulnerabilities, and targets to identify exposure chains
- Drill into a suspected issue, gather supporting evidence, and summarize remediation guidance
- Produce an analysis report for a group of related findings
Choosing a mode
Connect a provider
Before the assistant can answer, connect an AI provider with your own API key.1
Open the Connect Provider form
In the console, navigate to Agents → Providers → Connect (console route /agents/providers/connect).
2
Fill in the provider details
The Connect Provider form contains three required fields:
- Provider* — one of OpenAI, Anthropic, or Custom
- API Key* — your provider API key (the field placeholder shows the key format)
- Model* — the default model to use for your conversations
3
Save the configuration
Click Save. The provider is now available to your conversations.
Provider configuration is per member: each member connects their own provider and key, and conversations are scoped to the member who created them. Your provider credentials are never shared with other workspace members.
Supported providers
Existing assistant configurations can be edited later from the assistant edit page.
Start a conversation
1
Create a new chat
From the console, go to Overview → New Chat (console route /agents). The chat UI opens with the prompt area “Need help with a security issue?”.
2
Configure mode and model
Use the mode selector to choose Answer or Agent mode, and the model selector to pick the model for this conversation. The model selector shows the models available for your connected provider.
3
Attach context (optional)
The chat input includes a file upload control. You can attach a file to give the assistant additional context for the conversation.
4
Send your first message
Type a question or pick a suggested prompt. Suggested prompts include:
- “Which network services are publicly accessible in my setup?”
- “What entry points need security hardening in my workspace?”
- “What endpoints lack proper rate limiting?”
Ask questions or let the assistant analyze
Once a conversation is open, the assistant answers in whichever mode you selected:- In Answer mode, ask a direct question about your workspace data and read the answer.
- In Agent mode, describe the analysis you want. The assistant plans the steps, executes them, and streams the results into the conversation.
Workspace memory
The assistant remembers context about your workspace across conversations. This workspace-scoped memory persists between sessions, so the assistant remembers prior findings, decisions, and analysis relevant to your workspace instead of starting from scratch each time.- Memory is scoped to the workspace, not to an individual conversation.
- It accumulates context as you use the assistant, improving answers over time.
Because workspace memory accumulates context, keep it focused: avoid storing secrets or provider API keys in conversation content (see Security).
Additional tools and data sources
The assistant can connect to additional tools and data sources, such as internal knowledge bases or external services. It uses MCP, a standard way for AI assistants to reach external tools and data. For the full story, including how external AI clients connect to your workspace, see MCP Server and Integrations.Review conversation history
Every conversation is saved automatically.- The chat UI shows your Recent conversations.
- Select View all conversations → (console route /agents/conversations) to open the full conversation list and reopen any past session.
- You can review the full message history, including tool executions and results, at any time.
Security
Never paste a provider API key into a chat message. Chat content — including workspace memory — is part of your workspace data and is not a secure channel for credentials.
- Provider API keys are encrypted and masked in storage. They are sent only to your chosen provider to fulfill model requests.
- Keep your provider key private to your own member account; each member connects their own key.
- If you suspect a key was exposed, rotate it at the provider and update your connection in Agents → Providers.
- Workspace API keys used by MCP and automation are separate from provider keys — see API keys.
Best practices
- Use Answer mode for quick, direct questions; use Agent mode for multi-step analysis that needs planning and tool use.
- Keep API keys per-member private — never share them in prompts or conversation content.
- Let workspace memory accumulate context; revisit past conversations instead of re-running the same analysis.
- Review conversation history regularly to keep a record of what the assistant found and what actions followed.
- Pair the chat assistant with the vulnerability Analyze action for a consistent view of your findings — see Vulnerability.
Related resources
Vulnerability
Run the per-vulnerability Analyze action powered by the same AI configuration
MCP Server
Connect external AI assistants to your workspace data over the Model Context Protocol
API keys
Manage workspace API keys used by workers, MCP, and automation
Integrations
See how the chat assistant and MCP fit into the wider OASM ecosystem
