{
  "jimothyPipeline": 1,
  "name": "Security questionnaire answers",
  "description": "Answers a questionnaire from your answer library with sources, checks for overpromising, and saves it after you approve.",
  "icon": "rocket",
  "color": "#0284c7",
  "repo": {
    "mode": "inplace",
    "localPath": ""
  },
  "concurrency": 1,
  "variables": {
    "company": "Acme Inc.",
    "commitments": "SOC 2 Type II (renewed each March). Data hosted in AWS us-east-1 and eu-west-1. Encryption at rest (AES-256) and in transit (TLS 1.2+). SSO via SAML on Team and Enterprise. 99.9% uptime SLA on Enterprise only. No HIPAA, no FedRAMP."
  },
  "steps": [
    {
      "id": "answer",
      "name": "Answer from the library",
      "type": "agent",
      "description": "Answers each question from your library files and cites the file, or marks it NEEDS INPUT.",
      "harnessId": "claude-code",
      "model": "sonnet",
      "timeoutMinutes": 45,
      "prompt": "Answer this questionnaire for {{vars.company}} ({{issue.key}}: {{issue.title}}):\n\n{{issue.description}}\n\nThe current folder is our answer library. Search it (including subfolders and PDFs) for each question. Do not modify existing files.\n\nWhat we can commit to:\n{{vars.commitments}}\n\nRules: answer only from the library and the commitments above. Never claim a certification, feature or SLA that isn't there. When the library doesn't answer a question, write \"NEEDS INPUT: <who should answer, e.g. security, legal, engineering>\". Keep answers short and factual, in the questionnaire's own numbering.\n\nYour final answer is a Markdown table: #, Question, Answer, Source (file name). Then a list of the NEEDS INPUT questions.{{#if steps.review.output}}\n\nA reviewer checked your previous answers. Fix every problem it lists:\n{{steps.review.output}}{{/if}}{{#if steps.approve.output}}\n\nYour previous draft was rejected with this feedback. Rewrite it:\n{{steps.approve.output}}{{/if}}"
    },
    {
      "id": "review",
      "name": "Check for overpromising",
      "type": "agent",
      "description": "A second model checks every answer against your commitments and sends it back until it passes.",
      "harnessId": "anthropic-api",
      "model": "claude-opus-5",
      "dependsOn": [
        "answer"
      ],
      "timeoutMinutes": 10,
      "passPattern": "VERDICT:\\s*APPROVE",
      "loopBackTo": "answer",
      "maxLoops": 2,
      "prompt": "What the company can commit to:\n{{vars.commitments}}\n\nDraft answers:\n{{steps.answer.output}}\n\nList every answer that claims more than the commitments allow, answers without a source, or is vague where the question asks for specifics. Quote the question number. End with exactly one line: VERDICT: APPROVE or VERDICT: CHANGES_REQUESTED."
    },
    {
      "id": "approve",
      "name": "Approve answers",
      "type": "approval",
      "description": "Shows you the answers. Reject with corrections and they are redone.",
      "dependsOn": [
        "review"
      ],
      "loopBackTo": "answer",
      "maxLoops": 3,
      "approvalMessage": "Save these answers for {{issue.key}}? Questions marked NEEDS INPUT still need an owner.\n\n---\n\n{{steps.answer.output}}"
    },
    {
      "id": "save",
      "name": "Save answers",
      "type": "shell",
      "description": "Saves the approved answers in responses/, where future questionnaires can reuse them.",
      "dependsOn": [
        "approve"
      ],
      "timeoutMinutes": 1,
      "command": "mkdir -p responses && printf '%s\\n' {{steps.answer.output}} > responses/{{issue.key | slug}}.md && echo \"Saved $(pwd)/responses/{{issue.key | slug}}.md\""
    }
  ]
}