Skip to content

Commit f2a7548

Browse files
Add ai cop docs [LK-1746] (#2528)
* start docs on ai cop * add sections documentation * Update docs/organizations/ai-risk-hub.md Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com> * Update docs/organizations/ai-risk-hub.md Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com> * update dashboard img --------- Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
1 parent 9440595 commit f2a7548

File tree

7 files changed

+77
-0
lines changed

7 files changed

+77
-0
lines changed

docs/organizations/ai-risk-hub.md

Lines changed: 76 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,76 @@
1+
---
2+
description: The organization's AI Risk Hub dashboard provides an overview of all the AI issues detected in the repositories applied to the organization's AI Policy standard and your organization's risk level based on your AI practices.
3+
---
4+
5+
# AI Risk Hub
6+
7+
The **AI Risk Hub** dashboard provides an overview of all the AI issues detected in the repositories applied to the organization's AI Policy standard and your organization's risk level based on your AI practices. Here, you can navigate through the issues detected in your repositories and filter them by severity and category. You can also filter the issues by selecting specific repositories or using [the segments that you have set up](segments.md).
8+
9+
!!! important
10+
Currently this tab is a preview of a Business tier feature.
11+
12+
![AI Risk Hub dashboard](images/ai-risk-hub-dashboard.png)
13+
14+
To access the AI Risk Hub dashboard, select an organization from the top navigation bar and click on the **AI Risk Hub** tab at the top of the page.
15+
16+
The AI Risk Hub dashboard includes the following sections to help you monitor AI risk in your organization:
17+
18+
- [AI Policy Compliance](#ai-policy-compliance)
19+
- [Repositories with most AI issues](#repositories-with-most-ai-issues)
20+
- [Risk Level](#risk-level)
21+
- [AI Risk Checklist](#ai-risk-checklist)
22+
## AI Policy Compliance
23+
24+
Our AI Policy is a pre-defined, curated ruleset designed to prevent risks and vulnerabilities that are inherent to AI code from entering the codebase – which can be enforced immediately across all repositories and pull request checks.
25+
You can enable Codacy's AI Policy by clicking on the button on the right side of the section. This creates a coding standard that applies AI related patterns to your repositories, safeguarding them from AI risks.
26+
When the policy is enabled, you are able to view a real distribution of the AI issues found distributed by severity and AI category.
27+
When you already have the AI Policy enabled, you can see an edit button which allows you to edit the repositories that have this policy applied.
28+
29+
![AI Policy Compliance](images/ai-policy-compliance.png)
30+
31+
The AI Policy covers four groups of AI-specific risks:
32+
33+
### Unapproved model calls
34+
35+
Ensure no disallowed models are used in production and get visibility around any compliance misuses.
36+
37+
### AI Safety
38+
39+
Ensures safety practices are enforced and applied with the use of these new technologies.
40+
41+
### Hardcoded Secrets
42+
43+
Ensures anything created or used by AI is protected from misusage.
44+
45+
### Vulnerabilities (Insecure dependencies / SCA)
46+
47+
Ensures protection on all fronts, by integrating vulnerability detection through your entire organization.
48+
49+
50+
## Repositories with most AI issues
51+
52+
This list displays repositories in descending order based on the number of AI issues. Depending on the filters applied, the list will show repositories with the most AI open issues, grouped by severity or AI category.
53+
54+
55+
![Repositories with most AI issues](images/repositories-with-most-ai-issues.png)
56+
57+
## Risk Level
58+
59+
This panel shows the organizational AI Risk Level based on the implementation (or lack) of a range of essential AI safeguards that can be enabled in Codacy.
60+
The possible risk levels are: High, Medium, and Low, considering special control factors you can enable in Codacy.
61+
These control factors are specified in the **AI Risk Checklist**.
62+
63+
![Risk Level](images/risk-level.png)
64+
65+
## AI Risk Checklist
66+
67+
With most repositories today being subject to GenAI code contributions, the checklist covers essential source code controls that we recommend to enable across all projects within your organization:
68+
69+
- AI Policy enabled: Enable the AI Policy inside the AI Risk Hub tab.
70+
- Coverage enabled: Set up code coverage for your repositories. See how to [upload coverage data](../coverage-reporter/index.md) to Codacy.
71+
- Enforced gates: Add [gates to your repositories](../repositories-configure/adjusting-quality-gates.md), and preferentially [apply repositories to gate policies](./using-gate-policies.md).
72+
- Protected pull requests: Protect your pull requests by [enforcing quality gates](../getting-started/integrating-codacy-with-your-git-workflow.md#blocking-pull-requests).
73+
- Daily vulnerability scans: [Enable Proactive SCA](./managing-security-and-risk.md#dependencies-list) to protect your repositories from dependencies vulnerabilities.
74+
- Applications scanned: [Enable App scanning](./managing-security-and-risk.md#app-scanning) to scan Web Applications and APIs for security vulnerabilities.
75+
76+
![AI Risk Checklist](images/ai-risk-checklist.png)
34.2 KB
Loading
25 KB
Loading
244 KB
Loading
46.1 KB
Loading
19.1 KB
Loading

mkdocs.yml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -611,6 +611,7 @@ nav:
611611
- organizations/managing-repositories.md
612612
- organizations/segments.md
613613
- organizations/issues-metrics.md
614+
- organizations/ai-risk-hub.md
614615
- organizations/using-gate-policies.md
615616
- organizations/using-coding-standards.md
616617
- Managing integrations:

0 commit comments

Comments
 (0)