Template · Sales

Security questionnaire answers

Paste a questionnaire into an issue or post it to a webhook. Claude Code answers every question from your answer library (past questionnaires, policies, your SOC 2 summary), cites the file behind each answer, and writes NEEDS INPUT where the library doesn’t cover it. A reviewer model checks for overpromising before it reaches you, and the approved answers are saved next to the library.

Download .json

LinearSALES-402Northwind vendor security questionnaire (86 questions)questionnaire
Pipeline
  1. Answer from the library Claude Code · Sonnet
  2. Check for overpromising Claude API · Opus 5
  3. Approve answers You
  4. Save answers Shell
Fileresponses/SALES-402.md79 answered with sources, 7 marked NEEDS INPUTSaved
The pipeline

What each step does

  1. Answer from the library

    Claude Code · Sonnet

    Answers each question from your library files and cites the file, or marks it NEEDS INPUT.

  2. Check for overpromising

    Claude API · Opus 5

    A second model checks every answer against your commitments and sends it back until it passes.

    If it fails, goes back to Answer from the library, up to 2 times.

  3. Approve answers

    You

    Shows you the answers. Reject with corrections and they are redone.

  4. Save answers

    Shell

    Saves the approved answers in responses/, where future questionnaires can reuse them.

Set it up

From copy to first run

  1. Copy the pipeline JSON with the button above.
  2. In Jimothy, open Pipelines → New pipeline, paste it under “Or import a pipeline JSON” and click Import.
  3. Under Workspace, choose the folder that holds your answer library: past questionnaires, policies and security docs.
  4. Fill in the variables below under Pipeline settings → Variables.
  5. Triggers → Add trigger → Linear, Jira or GitHub, filtered to a questionnaire label, with the questions in the description. Or click Run and paste them.
Variables

What to fill in

The prompts and commands read these as {{vars.<name>}}. The examples are placeholders: replace them with your own.

VariableWhat to put in itExample
companyYour company name.Acme Inc.
commitmentsCertifications and commitments you can actually claim. Answers never go beyond them.SOC 2 Type II (renewed each March). Data hosted in AWS us-east-1 and eu-west-1. Encrypti…
Show the pipeline JSON
{
  "jimothyPipeline": 1,
  "name": "Security questionnaire answers",
  "description": "Answers a questionnaire from your answer library with sources, checks for overpromising, and saves it after you approve.",
  "icon": "rocket",
  "color": "#0284c7",
  "repo": {
    "mode": "inplace",
    "localPath": ""
  },
  "concurrency": 1,
  "variables": {
    "company": "Acme Inc.",
    "commitments": "SOC 2 Type II (renewed each March). Data hosted in AWS us-east-1 and eu-west-1. Encryption at rest (AES-256) and in transit (TLS 1.2+). SSO via SAML on Team and Enterprise. 99.9% uptime SLA on Enterprise only. No HIPAA, no FedRAMP."
  },
  "steps": [
    {
      "id": "answer",
      "name": "Answer from the library",
      "type": "agent",
      "description": "Answers each question from your library files and cites the file, or marks it NEEDS INPUT.",
      "harnessId": "claude-code",
      "model": "sonnet",
      "timeoutMinutes": 45,
      "prompt": "Answer this questionnaire for {{vars.company}} ({{issue.key}}: {{issue.title}}):\n\n{{issue.description}}\n\nThe current folder is our answer library. Search it (including subfolders and PDFs) for each question. Do not modify existing files.\n\nWhat we can commit to:\n{{vars.commitments}}\n\nRules: answer only from the library and the commitments above. Never claim a certification, feature or SLA that isn't there. When the library doesn't answer a question, write \"NEEDS INPUT: <who should answer, e.g. security, legal, engineering>\". Keep answers short and factual, in the questionnaire's own numbering.\n\nYour final answer is a Markdown table: #, Question, Answer, Source (file name). Then a list of the NEEDS INPUT questions.{{#if steps.review.output}}\n\nA reviewer checked your previous answers. Fix every problem it lists:\n{{steps.review.output}}{{/if}}{{#if steps.approve.output}}\n\nYour previous draft was rejected with this feedback. Rewrite it:\n{{steps.approve.output}}{{/if}}"
    },
    {
      "id": "review",
      "name": "Check for overpromising",
      "type": "agent",
      "description": "A second model checks every answer against your commitments and sends it back until it passes.",
      "harnessId": "anthropic-api",
      "model": "claude-opus-5",
      "dependsOn": [
        "answer"
      ],
      "timeoutMinutes": 10,
      "passPattern": "VERDICT:\\s*APPROVE",
      "loopBackTo": "answer",
      "maxLoops": 2,
      "prompt": "What the company can commit to:\n{{vars.commitments}}\n\nDraft answers:\n{{steps.answer.output}}\n\nList every answer that claims more than the commitments allow, answers without a source, or is vague where the question asks for specifics. Quote the question number. End with exactly one line: VERDICT: APPROVE or VERDICT: CHANGES_REQUESTED."
    },
    {
      "id": "approve",
      "name": "Approve answers",
      "type": "approval",
      "description": "Shows you the answers. Reject with corrections and they are redone.",
      "dependsOn": [
        "review"
      ],
      "loopBackTo": "answer",
      "maxLoops": 3,
      "approvalMessage": "Save these answers for {{issue.key}}? Questions marked NEEDS INPUT still need an owner.\n\n---\n\n{{steps.answer.output}}"
    },
    {
      "id": "save",
      "name": "Save answers",
      "type": "shell",
      "description": "Saves the approved answers in responses/, where future questionnaires can reuse them.",
      "dependsOn": [
        "approve"
      ],
      "timeoutMinutes": 1,
      "command": "mkdir -p responses && printf '%s\\n' {{steps.answer.output}} > responses/{{issue.key | slug}}.md && echo \"Saved $(pwd)/responses/{{issue.key | slug}}.md\""
    }
  ]
}