Risk analysis
What this page is — the capability that lists the material risks a careful reviewer would flag before signing, read from whichever side you tell it to read, each one paired with the redline that would fix it.
What it is for — so the negotiation list is built from the document rather than from memory, and so you know what the other side will object to before they say it.
The problem it solves — risks are spotted from memory, so the ones outside the reviewer's experience go unraised until the other side relies on them.
Route: /org/papers/documents/<document>/ai → Negotiate → Risk analysis ·
Permission: Use AI drafting/extraction/Q&A for documents. ·
Utility: papers_risk_identifier · Cost: 450 credits estimated, 1,800 maximum.
1. What it is
Risk analysis reads the whole document and lists what a reviewer would flag: one-sided obligations, missing protections (liability caps, indemnities, cure periods, insurance), payment and auto-renewal traps, ambiguous wording, and compliance, IP or data-protection exposure.
The defining property is that it reads from a perspective you choose, and the perspective changes the answer rather than the wording of it:
| Perspective | The same indemnity clause is | |
|---|---|---|
| Our side | a liability we are giving | flagged |
| Counterparty | a benefit they are receiving | not flagged — but our protections become their risks |
| Neutral | an allocation between two parties | judged on even-handedness |
This is not a presentation setting. A clause that exposes you is a shield for them, so the risk list genuinely inverts. Results are cached per perspective, so running it three ways gives you three saved answers on the document rather than three overwrites.
Against its neighbours in Negotiate:
| Answers | |
|---|---|
| Risk analysis | "What in here could hurt us, and what do I ask for?" |
| Fairness / balance | "How one-sided is this overall?" — one score, not a list |
| Shadow redline | "What reads as harmless but is not?" — internal only |
| Missing clauses | "What is not here at all?" |
2. Why you would use it
Reviewing a contract for risk is a skill with a long tail. Most reviewers catch the uncapped liability. Fewer catch the auto-renewal with a 90-day notice window, and fewer still catch it on document forty of the quarter.
suggested_remediationturns a finding into an ask. Every risk arrives with the concrete redline that would mitigate it. That is the difference between "clause 11 is bad" and a comment you can send.- Running it as the counterparty is the trick worth knowing. It predicts their pushback list before the call. You go in knowing which three of your asks they will fight.
clause_refand cited wording make it checkable. The rationale quotes the document's actual language, so a claim can be verified rather than trusted.severitygives you a stopping point. Not every risk is worth a round. The ranked list tells you which two to spend goodwill on.
Build your negotiation list from our side. Then re-run as counterparty to anticipate what they will push back on. Because results are cached per perspective, both are kept on the document and neither overwrites the other.
3. What you provide
One input, and it is the whole capability.
| Input | Required | Values | Notes |
|---|---|---|---|
| Perspective | Optional — defaults to your own side | our_side, counterparty, neutral | Whose eyes the AI reads through |
| Choose | When |
|---|---|
| Our side | Building your own negotiation list. Flags every term that exposes your organisation |
| Counterparty | Anticipating their objections before a round |
| Neutral | An even-handed read of both sides' exposure — useful for an internal approver who is not on either side |
Leaving it blank defaults to your own organisation's side, which is the right default and the wrong one to rely on when you are reviewing a document you drafted.
4. What it reads automatically
| Read from the document | Used for |
|---|---|
| Document text — the full rendered body | The analysis |
| Title & family — e.g. "Master Services Agreement" | Which risks are expected in this kind of document |
| Parties — everyone named | Which party the chosen perspective maps to |
| Key field values — amounts, dates, terms | So severity can reason about scale — an uncapped liability on a £4m contract is not the same finding as on a £4k one |
5. What you get back
risks[], ordered highest severity first.
| Field | Type | Values | Means |
|---|---|---|---|
title | string | — | Short name for the risk |
severity | enum | high, medium, low | How exposed the chosen perspective is |
clause_ref | string | empty if unpinnable | The section or clause heading it arises from |
rationale | string | — | Why it is a risk for the chosen perspective, citing the document's actual wording |
suggested_remediation | string | — | The concrete redline or negotiation ask that would mitigate it |
An empty clause_ref is meaningful: the risk arises from the document as a whole, or from something
it fails to say, rather than from one clause.
6. Worked example
A vendor's contracts lead reviews a customer-supplied MSA before signature.
Input: perspective = our side.
Top entry of risks[]:
Uncapped liability severity:
highclause_ref: "11. Limitation of Liability" rationale: The clause caps the customer's liability at fees paid but leaves our liability uncapped, so a single breach could expose us far beyond the contract value. suggested_remediation: Add a mutual cap at 12 months' fees, with the usual carve-outs for confidentiality and IP infringement only.
What the lead does with it. The remediation is specific enough to send: mutual cap, 12 months' fees, named carve-outs. It goes into the redline as written.
Then they re-run as counterparty. That result does not contain the liability cap — from the
customer's seat the asymmetry is a feature — but it does flag the vendor-favourable IP assignment in
clause 14 as high. The lead now knows the trade before the call: they will concede narrowing on
clause 14 to win the mutual cap in clause 11. Both results stay on the document.
7. Running it
- Open the document in Orbit Papers.
- Open the AI Assistant drawer, or go to the document's AI workspace.
- Choose Risk analysis under Negotiate.
- Pick the Perspective, or leave it to default to your own side.
- The ranked list appears in a result tab and is saved to the document, per perspective.
Because caching is per perspective, Re-run refreshes only the perspective you are looking at. Switching perspective is not a re-run of the same result — it is a separate result, separately charged at 450 credits.
Risk analysis is available for auto-run on submit, round or finalize from the type's AI Config
tab, and on_round is where it earns most: every counterparty round gets a fresh risk read without
anyone remembering. See AI configuration.
8. The admin contract
| Must be true | Where | What happens if it is not |
|---|---|---|
| Your role holds Use AI drafting/extraction/Q&A for documents. | Role editor | The AI Assistant button does not appear |
The papers_risk_identifier utility is active | Orbit AI Flow → utilities | "This utility is currently disabled" |
| The utility is enabled for your organisation | /org/ai-utilities | Absent from Negotiate, with no error |
papers.ai_monthly_credit_cap not yet reached | System Config | "monthly AI credit cap reached: n of n credits used this month" |
| The parties are correctly recorded on the document | The document | The perspective cannot be mapped to a party, and the read silently defaults to a generic one |
That last row matters more here than anywhere else in the module: the perspective is only meaningful if the AI can tell which named party is you.
For a confidential document, auto-run is default-denied — a platform administrator must set
papers.ai_confidential_cloud to the literal allow, and the block appears only in the server log.
A manual press still works, and where a local model key is configured the run is forced on-prem and
audited on the timeline as ai_local_routed.
9. Don't confuse this with…
| Fairness / balance | A single score for the whole document. This is a ranked list of specific findings |
| Shadow redline | Internal-only. Finds liabilities hidden in wording that reads as harmless |
| Redline grade | Judges one counterparty edit against your playbook. This reads the whole document |
| Compliance & policy check | Breaches of your configured policy. This is commercial and legal risk generally |
10. Troubleshooting
| Symptom | Cause |
|---|---|
| The risk list looks like the counterparty's, not ours | The perspective defaulted, or the parties are recorded such that "our side" maps to the wrong one (§8) |
| Switching perspective showed an old result instantly | Results are cached per perspective — that is a previously saved run, not a new one |
A risk has no clause_ref | It arises from the document as a whole, or from an omission rather than a clause |
| The same risk appears at different severities across runs | Severity reasons about scale from the filled field values; if amounts changed, so does severity |
suggested_remediation is generic | The clause is ambiguous enough that no specific redline follows. Read the cited wording |
| It flagged nothing on a clearly one-sided document | Check the perspective — from the favoured side there may genuinely be little to flag |
| The capability is missing from Negotiate | Role lacks Use AI drafting/extraction/Q&A for documents., or the utility is off for the organisation (§8). The document type does not gate it — AI Config controls auto-run only |