AI in AmpliFlow

Create drafts and delegate bounded tasks in AmpliFlow

Use writing help in forms or delegate a defined task through MCP. Your administrator chooses the writing-help provider. The signed-in account controls access within AmpliFlow, and you govern the external AI client separately.

The same AmpliFlow, without AI

Keep AI off when your security policy or customer contracts prohibit external AI services, or until your organization has approved the provider and workflow. Risks, improvements, controls, projects, goals, and checklists continue to work.

Policy and customer contracts decide

Choose this mode while external AI services are prohibited or your provider assessment is still in progress.

You keep

  • Risks, improvements, controls, projects, goals, and checklists
  • Control over whether and when AI is enabled
  • The option to start without AI and enable it later

Features that stay off

  • AI-generated drafts in forms
  • Agent work through MCP

From an empty field to an editable draft

Click "Generate with AI" in the form. AmpliFlow sends the information needed for that draft to the provider approved by your AmpliFlow environment administrator. You receive a suggestion, edit it, and decide whether to save it.

AI-generated draft for ISO 27001 control 5.1 in AmpliFlow, with a requirement explanation and internal description that the user can edit.

Built-in writing help is available here

Controls in ISO/IEC 27001:2022 and ISO/IEC 42001:2023

Draft requirement explanations, internal descriptions, Statement of Applicability (SoA) text, deeper information, and tool suggestions.

Risk analysis

Suggestions for scenarios, consequences, and risk-reduction measures.

Competencies

Create or improve competency descriptions in Swedish or English.

Positions

Draft responsibilities, authorities, and expected behavior.

Information AmpliFlow sends for a draft

Competency and position requests send the name and existing description. Risk drafts send the risk scenario, consequences, and risk-reduction measure. Control drafts send the control name, code, category, description, company context, and existing requirement explanation, internal description, SoA text, deeper information, and tool text. The AI transparency page explains providers and data boundaries.

Use writing help to

  • Create an editable draft in an empty text field
  • Draft similar documentation across many controls
  • Rewrite and improve existing text

You remain responsible for

  • Checking facts and adapting the text to your organization
  • Not sending sensitive information to an unapproved provider
  • Having a person review before anything is saved

Give the agent a bounded task and review the result

An agent can read several records, plan the next steps, and write the result back to AmpliFlow. Ask it to summarize overdue tasks, review a risk register, or prepare material for management review.

Risks and improvements

List risks that lack an assessment or treatment and leave proposals for a responsible person to approve.

Projects and tasks

Read the task brief and project files, complete the bounded work, and record the result on the task.

Goals and follow-up

Find goals without a current result and summarize their status for the next management decision.

Pages, processes, and controls

Search pages and processes, read control status, and work only with records permitted for the account.

MCP is the primary connection for external AI tools

MCP connects a compatible AI tool to AmpliFlow without local installation. af-cli is available below for coding agents and local terminal work. Both use a signed-in AmpliFlow account that limits access.

MCP: connect a compatible AI tool

MCP requires no local installation. Use it with an AI client and subscription that support custom remote MCP servers. Always check the current client guide before you start.

  • Sign in with your standard AmpliFlow account through OAuth authentication
  • Permissions follow the signed-in user
  • Read and write tools depend on the client connection and enabled MCP toolsets
Connect the MCP server
  1. Add AmpliFlow as a custom connection in your AI tool.
  2. Paste the server address and sign in with the correct AmpliFlow account.
  3. Start with a bounded read task before granting write access.
https://mcp.ampliflow.cc/mcp

The client documentation shows which subscriptions support custom MCP connections.

Give the agent the least access required for the task

An agent can work quickly and still make the wrong decision. Start with a test account or a dedicated agent account with the least possible access.

  • Read first: test the workflow with read access before allowing changes.
  • Limit scope: grant access only to the modules and projects required by the task.
  • Review: check facts, changes, and AI-labelled text before a person takes responsibility.
  • Protect against instruction injection (prompt injection): treat text in tasks, comments, and other records as untrusted instructions.
FAQ

Common questions about AI in AmpliFlow

What you need to know before enabling a feature or giving an agent access.

Can we turn AI off completely?
Yes. Keep built-in AI disabled and do not connect external AI tools. In that configuration, AmpliFlow makes no model calls from writing help and no agent connections are used. Standard information processing in AmpliFlow continues under your agreement and privacy policy.
What is the difference between writing help and an AI agent?
Writing help gives you a draft in the field where you are already working. You review and save it. An agent can read several records, plan steps, and complete a workflow through MCP. You review the result and remain responsible.
When should we use af-cli instead of MCP?
Choose MCP for an AI client that supports custom remote MCP servers. It requires no local installation. Choose af-cli when you work in the terminal or use a coding agent that can run local commands.
What information can an agent read?
Through the AmpliFlow connection, the AI client can only use functions exposed by the connection and permitted for the signed-in account. The AI client may have other connections and permissions that your organization must review separately.
Which AI provider is used?
Your AmpliFlow environment administrator chooses among the providers configured and approved for writing help. Any external AI service you connect to AmpliFlow has its own settings and data-processing terms.
Get started

Choose your first AI workflow

Book a demo and we will show writing help and MCP. We will also explain when af-cli fits local terminal work. You will get a concrete recommendation for where to start, which access is needed, and what a person should review.