WHAT ARE GRC AGENTS
Q: What are GRC Agents and how do they differ from LogicGate's existing AI capabilities?
In short: Our existing AI features (previously known as Spark AI) help you work faster at no additional cost. GRC Agents are an optional add-on that you delegate actual work to. They act, and you supervise.
- LogicGate's embedded layer of AI capabilities is included with every Risk Cloud subscription. Thoughtfully woven throughout the platform, these AI-powered features assist teams in drafting, summarizing, surfacing insights, and making suggestions.
- GRC Agents go a step further and take action on your behalf, performing the actual work inside your Risk Cloud applications. For example, an Agent doesn't just suggest that a vendor should be assessed, it can run the actual assessment.
Agents are most useful in high-volume, repeatable, language-based processes such as vendor onboarding, AI use case intake, and recurring enterprise risk assessments.Instead of waiting for a human to push data through a process step-by-step, GRC Agents operate as autonomous digital workers that execute complete, multi-step tasks entirely on their own.
Q: Are GRC Agents included for free, or a paid add-on?
GRC Agents are an optional add-on with their own cost, added to the application they run on. We currently price our GRC Agents at a flat fee per year based on size of organization.
Q: What's the value of GRC Agents?Agents can automate a large share of manual work so your team can focus on higher-value work, like actually mitigating risk. Two enterprise customers project their teams will:
- Save 1,800 hours a year assessing third-party vendors
- Review AI use case 75% faster and get through a backlog of 100 records
The impact isn't just time and money saved. GRC Agents shift your team’s focus from high-volume, low-risk work to the strategic priorities that move your GRC program forward.
Q: Are there usage limits? What counts as an Agent execution?
Yes, Agent plans include a fair-usage limit on yearly executions to cover scenarios and usage outside your allowance for the number of agent executions per year, sized to support normal day-to-day operation of your enabled workflows. An execution is counted each time an agent completes processing of a single record within a single workflow step. For example, an intake agent processing one submission is one execution; an assessment agent then scoring that same submission is an additional execution. Your LogicGate team can help you estimate the right level based on your volume.
WHAT TO EXPECT: AGENT DEPLOYMENT
Q: Which Risk Cloud Applications can I add GRC Agents to?
As of August 17, 2026, GRC Agents are available for the following applications:
- Third-Party Risk Management (TPRM)
- AI Governance
- Enterprise Risk Management (ERM)
- Business Continuity Management (BCM)
To add and enable agents for a given area, you need to be using that application. The application serves as the system of record and defines the workflows while Agents are the digital workers that help operate it for you. Applications also keep agents accountable since they act inside the governance, controls, and audit trail of the application you already run.
Q: None of the currently available agent-enabled applications are relevant to me. What other GRC Agents are on the roadmap?
We are prioritizing future Action Agent availability based on existing client feedback and demand. Please talk to your account team about your core Action Agent use cases. Our product team’s current focus areas include:
- Cyber Risk Management
- Incident Management
- Issues Management
- Policy & Procedure Management
- Controls Compliance
- Regulatory Compliance
- Internal Audit
Q: How are the agents deployed?
Our Forward Deployed Engineering team will partner with you to identify where in the process agents will add value, configure the agent, set-up testing and monitoring, and deploy the agent.
- Phase 1 Kickoff: Together we’ll review key success criteria, LogicGate project plan, and next steps.
- Phase 2 Deep-Dive: Together we’ll explore critical inputs and decision criteria required for strategic agent implementation.
- Phase 3 Implement: LogicGate develops prompt(s), selects AI skills, and works to refine outcomes within a test environment.
- Phase 4 Test & Refine: Together we’ll test and refine agent performance and precision during scheduled meetings.
- Phase 5 Go-Live: Begin using the agent to save time and resources
Longer term, we’re looking to provide a self-service agent configuration user interface to empower customers to maintain their own Agents in Risk Cloud.
Q: How long does it take to deploy agents in my application?
The average deployment of GRC Agents within a specific Application takes 20 hours over the course of 30 days. Below is a sample timeline but exact dates will depend on your application maturity, agent requirements, and testing complexity.
TRUST, CONTROL & OVERSIGHT
Q: Are GRC Agents governed?
Yes, Agents are governed like any user in the system. You can track which records an agent is working on, assign it permissions to read and write data, and review all agent outputs — which are labeled, logged, and surfaced in the HITL review panel, record audit trail, and agent execution log. Each agent can be enabled or disabled by an admin at any time.
Q: Is there a “human in the loop” with GRC Agents?
Yes, you decide when an agent acts on its own and when a person should review its work. Currently, every agent execution is followed by a review step where the record is routed to a designated reviewer who sees a summary of what the agent did and can confirm or correct it before anything becomes final.
Q: Where does my data go? Is it used to train AI models?
To perform agent actions, the relevant inputs and outputs are processed through OpenAI via API. That data may be retained for a short period (up to 30 days) for safety monitoring, but it is not used to train models.
Our 2026 roadmap includes migrating agent workloads to Amazon Bedrock, AWS's managed foundation-model service. This will ensure inputs and outputs are not shared with model providers and are not used to train or improve the underlying models. Your data will be encrypted in transit and at rest, and will be processed and stored within the AWS region you operate in. Bedrock is also in scope for SOC, ISO, CSA STAR Level 2, HIPAA, and GDPR compliance.
Q: What LLMs are we using to power GRC Agents?
The system to power GRC Agents leverages advanced large language models (LLMs), including variants of OpenAI’s GPT-4 and GPT-5 models.
Q: Can I select my own model provider of choice that I’d like LogicGate to use – e.g., OpenAI, Anthropic, Gemini?
No. GRC Agents are currently powered by OpenAI's models and cannot be substituted with a different model provider.