Security questionnaire answers
Paste a questionnaire into an issue or post it to a webhook. Claude Code answers every question from your answer library (past questionnaires, policies, your SOC 2 summary), cites the file behind each answer, and writes NEEDS INPUT where the library doesn’t cover it. A reviewer model checks for overpromising before it reaches you, and the approved answers are saved next to the library.
- Answer from the library Claude Code · Sonnet
- Check for overpromising Claude API · Opus 5
- Approve answers You
- Save answers Shell
What each step does
Answer from the library
Claude Code · SonnetAnswers each question from your library files and cites the file, or marks it NEEDS INPUT.
Check for overpromising
Claude API · Opus 5A second model checks every answer against your commitments and sends it back until it passes.
Approve answers
YouShows you the answers. Reject with corrections and they are redone.
Save answers
ShellSaves the approved answers in responses/, where future questionnaires can reuse them.
From copy to first run
- Copy the pipeline JSON with the button above.
- In Jimothy, open Pipelines → New pipeline, paste it under “Or import a pipeline JSON” and click Import.
- Under Workspace, choose the folder that holds your answer library: past questionnaires, policies and security docs.
- Fill in the variables below under Pipeline settings → Variables.
- Triggers → Add trigger → Linear, Jira or GitHub, filtered to a questionnaire label, with the questions in the description. Or click Run and paste them.
What to fill in
The prompts and commands read these as {{vars.<name>}}. The examples are placeholders: replace them with your own.
| Variable | What to put in it | Example |
|---|---|---|
company | Your company name. | Acme Inc. |
commitments | Certifications and commitments you can actually claim. Answers never go beyond them. | SOC 2 Type II (renewed each March). Data hosted in AWS us-east-1 and eu-west-1. Encrypti… |
Show the pipeline JSON
{
"jimothyPipeline": 1,
"name": "Security questionnaire answers",
"description": "Answers a questionnaire from your answer library with sources, checks for overpromising, and saves it after you approve.",
"icon": "rocket",
"color": "#0284c7",
"repo": {
"mode": "inplace",
"localPath": ""
},
"concurrency": 1,
"variables": {
"company": "Acme Inc.",
"commitments": "SOC 2 Type II (renewed each March). Data hosted in AWS us-east-1 and eu-west-1. Encryption at rest (AES-256) and in transit (TLS 1.2+). SSO via SAML on Team and Enterprise. 99.9% uptime SLA on Enterprise only. No HIPAA, no FedRAMP."
},
"steps": [
{
"id": "answer",
"name": "Answer from the library",
"type": "agent",
"description": "Answers each question from your library files and cites the file, or marks it NEEDS INPUT.",
"harnessId": "claude-code",
"model": "sonnet",
"timeoutMinutes": 45,
"prompt": "Answer this questionnaire for {{vars.company}} ({{issue.key}}: {{issue.title}}):\n\n{{issue.description}}\n\nThe current folder is our answer library. Search it (including subfolders and PDFs) for each question. Do not modify existing files.\n\nWhat we can commit to:\n{{vars.commitments}}\n\nRules: answer only from the library and the commitments above. Never claim a certification, feature or SLA that isn't there. When the library doesn't answer a question, write \"NEEDS INPUT: <who should answer, e.g. security, legal, engineering>\". Keep answers short and factual, in the questionnaire's own numbering.\n\nYour final answer is a Markdown table: #, Question, Answer, Source (file name). Then a list of the NEEDS INPUT questions.{{#if steps.review.output}}\n\nA reviewer checked your previous answers. Fix every problem it lists:\n{{steps.review.output}}{{/if}}{{#if steps.approve.output}}\n\nYour previous draft was rejected with this feedback. Rewrite it:\n{{steps.approve.output}}{{/if}}"
},
{
"id": "review",
"name": "Check for overpromising",
"type": "agent",
"description": "A second model checks every answer against your commitments and sends it back until it passes.",
"harnessId": "anthropic-api",
"model": "claude-opus-5",
"dependsOn": [
"answer"
],
"timeoutMinutes": 10,
"passPattern": "VERDICT:\\s*APPROVE",
"loopBackTo": "answer",
"maxLoops": 2,
"prompt": "What the company can commit to:\n{{vars.commitments}}\n\nDraft answers:\n{{steps.answer.output}}\n\nList every answer that claims more than the commitments allow, answers without a source, or is vague where the question asks for specifics. Quote the question number. End with exactly one line: VERDICT: APPROVE or VERDICT: CHANGES_REQUESTED."
},
{
"id": "approve",
"name": "Approve answers",
"type": "approval",
"description": "Shows you the answers. Reject with corrections and they are redone.",
"dependsOn": [
"review"
],
"loopBackTo": "answer",
"maxLoops": 3,
"approvalMessage": "Save these answers for {{issue.key}}? Questions marked NEEDS INPUT still need an owner.\n\n---\n\n{{steps.answer.output}}"
},
{
"id": "save",
"name": "Save answers",
"type": "shell",
"description": "Saves the approved answers in responses/, where future questionnaires can reuse them.",
"dependsOn": [
"approve"
],
"timeoutMinutes": 1,
"command": "mkdir -p responses && printf '%s\\n' {{steps.answer.output}} > responses/{{issue.key | slug}}.md && echo \"Saved $(pwd)/responses/{{issue.key | slug}}.md\""
}
]
}More for sales, and beyond
Discovery call prep
When someone books a call, researches the company and the person and posts a one-page call brief to Slack before the meeting.
SalesCall notes → CRM and follow-up
Turns a call transcript into structured CRM fields and a follow-up email. You approve the email; both go to your CRM.
SalesClosed-lost debrief
When a deal is marked lost, works out why from the notes and emails, files the reason in your CRM and sets a date to try again.