ISMS Copilot Docs

Delegate GRC work from your agent

What to hand to ISMS Copilot and what to keep in your agent, paste-ready routing rules for Claude Code, Codex, OpenCode, Grok and Cursor, and the patterns that keep delegated turns small.

Your coding agent is the harness: it owns your repository, your shell and your files. ISMS Copilot is the GRC specialist it can hand compliance work to over the account MCP. The two work together. This page covers when to delegate, how to tell your agent to do it, and how to keep each delegated turn small.

When your agent connects, the server already sends it a short routing note (the MCP instructions field) saying what to delegate and what to keep local. Agents do not always act on that note, so a routing rule in your project or user instructions makes the behaviour reliable.

What to delegate, what to keep local

Delegate to ISMS CopilotKeep in your agent
Framework interpretation: ISO 27001, ISO 27701, ISO 42001, SOC 2, GDPR, NIS 2, DORA, EU AI Act, HIPAA, PCI DSSCode, tests, refactors
Policy and procedure draftingGit, branches, pull requests
Control mapping and gap analysisReading and editing files, shell commands
Statement of Applicability justificationsGeneral questions unrelated to compliance
Risk register entries and treatment optionsDeciding what to change in your codebase
Audit preparation and evidence listsWriting the final deliverable to disk

A useful test: if the answer depends on what a standard or regulation says, delegate. If it depends on what your repository contains, keep it local, then send ISMS Copilot a short summary of the relevant facts rather than the files themselves.

Routing rules, per harness

Each rule below has the same content; only the file differs. Paste it into the file your harness reads. The rules assume the server is registered under the name ismscopilot, as in the setup guides.

Claude Code

Add to CLAUDE.md in the project root, or to ~/.claude/CLAUDE.md for every project:

## Compliance work: delegate to ISMS Copilot

For ISO 27001/27701/42001, SOC 2, GDPR, NIS 2, DORA, EU AI Act, HIPAA or PCI DSS
questions, policy drafting, control mapping, gap analysis, SoA justifications,
risk registers and audit prep, use the ismscopilot MCP server instead of answering
from memory. Keep code, git, files and shell work local.

- Send the question, not framework text: do not paste standards or large documents first.
- One conversation per deliverable: create_conversation, then send_message for follow-ups.
- Pass workspace_id when the work is for a specific client or company.
- Default mode fast; think for multi-step analysis; beyond only when I ask for it.
- Pass answer_format "brief" or "decision" unless I ask for the full text.
- If a call returns status "generating", poll get_reply until "complete".
- Write long deliverables to a file and give me the path, not the whole text in chat.

Setup: Connect ISMS Copilot to Claude Code.

Codex, OpenCode and Grok

These harnesses read AGENTS.md. Put the same rule in AGENTS.md at the project root, or in the harness's global instructions file (for example ~/.codex/AGENTS.md for Codex). Check your harness version's documentation for the exact global path.

## Compliance work: delegate to ISMS Copilot

For ISO 27001/27701/42001, SOC 2, GDPR, NIS 2, DORA, EU AI Act, HIPAA or PCI DSS
questions, policy drafting, control mapping, gap analysis, SoA justifications,
risk registers and audit prep, use the ismscopilot MCP server instead of answering
from memory. Keep code, git, files and shell work local.

- Send the question, not framework text: do not paste standards or large documents first.
- One conversation per deliverable: create_conversation, then send_message for follow-ups.
- Pass workspace_id when the work is for a specific client or company.
- Default mode fast; think for multi-step analysis; beyond only when I ask for it.
- Pass answer_format "brief" or "decision" unless I ask for the full text.
- If a call returns status "generating", poll get_reply until "complete".
- Write long deliverables to a file and give me the path, not the whole text in chat.

Setup: Connect Cursor and Codex, or Connect any MCP client for OpenCode and Grok.

Cursor

Create a project rule at .cursor/rules/ismscopilot.mdc:

---
description: Delegate compliance and GRC work to the ISMS Copilot MCP server
alwaysApply: true
---

For ISO 27001/27701/42001, SOC 2, GDPR, NIS 2, DORA, EU AI Act, HIPAA or PCI DSS
questions, policy drafting, control mapping, gap analysis, SoA justifications,
risk registers and audit prep, use the ismscopilot MCP server instead of answering
from memory. Keep code, git, files and shell work local.

- Send the question, not framework text: do not paste standards or large documents first.
- One conversation per deliverable: create_conversation, then send_message for follow-ups.
- Pass workspace_id when the work is for a specific client or company.
- Default mode fast; think for multi-step analysis; beyond only when I ask for it.
- Pass answer_format "brief" or "decision" unless I ask for the full text.
- If a call returns status "generating", poll get_reply until "complete".
- Write long deliverables to a file and give me the path, not the whole text in chat.

Setup: Connect Cursor and Codex.

claude.ai, Claude Desktop and ChatGPT

Not available yet. These apps connect to remote MCP servers through OAuth, and the account MCP authenticates with a personal access token (pat-isms-…) today. Until OAuth is supported, use a harness from the list above, or the chat app directly.

Patterns that work

One conversation per deliverable

Start each deliverable (an access control policy, a gap analysis, a batch of SoA justifications) with create_conversation, then refine it with send_message on the same conversation_id. The specialist keeps the thread's history on its side, so your agent does not need to resend earlier turns. Start a new conversation for an unrelated deliverable: long threads use more of your usage window per message.

Scope client and company work to a workspace

Pass workspace_id (from list_workspaces) when the work belongs to a specific client or company. On a workspace-scoped turn, ISMS Copilot reads that workspace's memories and files, so your agent does not have to restate them. Without workspace_id, the turn runs on your personal memories only.

Memories for durable facts

Facts that should apply to every future turn (the certification scope, the chosen risk methodology, the audit date) belong in a memory: create_memory, with workspace_id for a workspace memory or without it for a personal one. Memories are capped at 500 characters each. Use list_memories to check what is already there before adding a duplicate.

Company Context

set_company_context replaces the account's company profile (name, sector, size, country, privacy role, data types, hosting region, tech stack, notes), and get_company_context reads it. The chat app uses this profile as background. Conversations started over MCP do not load it today, so put the company facts your question depends on in the message itself or in a workspace memory.

Fast, Think or Beyond

modeUse it for
fast (default)Most questions and short drafts.
thinkMulti-step analysis: gap analysis across several controls, mapping between frameworks. Paid plans; on a free plan it falls back to fast.
beyondLong research-grade drafting only. Paid plans, capped at 10 runs per UTC day (50 on Unlimited), minutes-scale.

A beyond request that cannot run is answered through the normal flow, and the result says why in beyond_denied_reason: plan, adp, disabled, trivial, cap or cap_anthropic. A turn running on the over-cap overflow path also answers through the normal flow instead of Beyond. See Using Beyond mode.

Ask for a reply shaped for an agent

create_conversation and send_message take an optional answer_format:

answer_formatReply shape
briefThe shortest correct answer, about 150 words, framework references inline.
decisionRecommendation first, then why, risks and next steps as bullets, about 300 words.
full or omittedThe default chat style.

An explicitly requested full document is never cut short. Beyond runs ignore answer_format and say so with answer_format_applied: false.

Polling cadence

When a call returns status: "generating", call get_reply with the conversation_id and message_id until it returns complete:

  • Fast and Think turns: every 2-5 seconds.
  • Beyond runs: every 10-20 seconds. You can also pass the beyond_run_id the ticket returned.

Wait for a reply before sending the next message on the same conversation: a send while the previous turn is still generating is rejected.

Write long deliverables to files

When the specialist returns a policy or a full SoA, have your agent write it straight to a file and report the path. Repeating a long document back in chat puts it in your agent's context twice. See What delegation saves.

MCP or the Model API?

ISMS Copilot offers two ways in from a coding agent. They suit different jobs.

Account MCPModel API sub-agent
Credentialpat-isms-… personal access tokensk-isms-… API key
BillingYour chat subscription and its 4-hour usage windowPrepaid API credits
StateStateful: conversations, workspaces, memories, filesStateless: each completion stands alone
Tools in your agentYes, native MCP toolsNo: the endpoint is text in, text out, called from a script or step
Best forInteractive work where you and your agent refine a deliverable over several turnsFixed, repeatable compliance steps in scripts, CI or automation

For the Model API pattern, see Use the API in coding agents.

If a delegated turn hits your plan limit, the tool error carries the reset time and, where it applies, the upgrade link or the overflow option. See Connect any MCP client.

On this page