Cortex

Cortex

Use Cortex to query your program context and speed up navigation, without losing review control.

Cortex

Cortex in the app is /cortex.

Use Cortex when you need fast answers grounded in your Noru data (controls, policies, risks, vendors, evidence) and you want to turn questions into specific next actions.

/cortex starts a conversation. /cortex/[id] loads a saved conversation and its working state. Cortex can use the active organization's framework overview and program records; it can also work with uploaded files within the conversation flow.

What Cortex is good for

  • Finding where you’re blocked (missing owners, stale evidence, unmapped items)
  • Summarizing what exists (e.g. “which controls have no evidence?”)
  • Helping route you to the right page (controls vs evidence vs vendors)

Conversations and generated work

Cortex can propose structured choices and, in supported workflows, draft or edit policy material. Generated policy work still follows the normal policy lifecycle: save, review, approve, version, and export. A chat response is not an approved policy, completed control, accepted risk, or validated evidence item.

When Cortex offers a mutation or generated artifact:

  1. Confirm the active organization and scope.
  2. Inspect the source records and assumptions it cites or summarizes.
  3. Review generated language for claims your organization cannot evidence.
  4. Save into the appropriate source register.
  5. Use normal approval and version history rather than treating the chat as the audit record.

Uploaded files may contain confidential, personal, or customer information. Upload only material authorized for the active organization and avoid secrets that are unnecessary for the question.

What to avoid

  • Don’t ask “how do I get SOC 2?” style questions. Ask about your current state:
    • “Which controls are missing an owner?”
    • “Which evidence items are outdated?”
    • “Which vendors process customer data but have no DPA attached?”

Limitations

Cortex answers depend on current Noru data and available context. It can miss systems outside connected sources, misunderstand ambiguous language, or produce plausible but unsupported recommendations. Verify legal interpretations with counsel and technical facts with system owners. Prefer narrow, state-based questions and ask it to identify the records behind an answer.