How to Use Bobby
Bobby is the Cert-IX AI assistant. It answers questions in plain language, grounds its answers in the Cert-IX documentation, and links back to the pages it drew from. This guide explains where Bobby lives, how to phrase questions so you get precise answers, and — importantly — what each version of Bobby can and cannot do.
There are two Bobby surfaces, and they behave differently. The documentation search assistant is read-only and answers from the docs. The in-platform assistant runs inside the dashboard, understands your in-platform context, and can carry out a change after you explicitly confirm it. Knowing which one you're talking to sets the right expectations for the answer you'll get.
Where Bobby Lives
| Documentation search assistant | In-platform assistant | |
|---|---|---|
| Where | Docs site and the Cert-IX website, bottom-right | Dashboard at app.cert-ix.com, bottom-right |
| Session | Anonymous — no sign-in required | Your authenticated session |
| Answers from Cert-IX docs, with source links | Yes | Yes |
| Understands your in-platform context | No | Yes |
| Reads your account data | No | Within your role's permissions |
| Can carry out a change for you | No — guidance only | Yes — it proposes the change and runs it only after you confirm |
| Can delete your data | No | No |
| Live external data (news, threat feeds, web) | No | No |
Both versions are powered by Claude and answer in the languages the Cert-IX site supports, so you can ask in whichever language you're most comfortable with.
Documentation search assistant
Open the Cert-IX documentation or website, type your question into the Bobby search box, and press Enter. Bobby returns an answer along with links to the documentation pages it used, so you can jump straight to the source. Sessions are anonymous and don't require an account, which makes this the fastest way to look something up while you're evaluating Cert-IX or reading the docs.
In-platform assistant
Inside the dashboard, click the Bobby icon in the bottom-right corner to open the chat panel. Because it runs in your signed-in session, this assistant understands the context you're working in and can help you act on it — not just explain it. When you ask it to make a change, it proposes what it's about to do and waits for your confirmation before running anything.
Bobby never makes a change silently. It describes the action, and nothing happens until you confirm. It will not delete data, and every action is bounded by your role's permissions and your plan — if a capability isn't available to you, Bobby will say so rather than attempt it.
Asking Effective Questions
Bobby works best with clear, focused questions. The three habits below make the biggest difference to answer quality.
Be specific
Precise questions get precise answers. Name the feature, the framework, or the component you mean.
❌ "How does security work?"
✅ "How do I set up vulnerability scanning for my production servers?"
❌ "Tell me about compliance"
✅ "What steps should I take to prepare for an ISO 27001 assessment?"
Provide context
Include the details that matter — numbers, before/after states, and where you saw the problem.
❌ "Why is my score low?"
✅ "My security score dropped from 85 to 72 this week. What could have caused this?"
❌ "How do I fix this?"
✅ "I have 15 critical vulnerabilities on my production servers. What's the fastest way to prioritize and fix them?"
Ask one thing at a time
Bundling several tasks into one question produces a shallow answer to each. Split them, and let each answer inform the next.
❌ "How do I set up scanning, create policies, and prepare for an audit?"
✅ Start with: "How do I set up vulnerability scanning?"
Then: "How do I create a security policy?"
Then: "How do I prepare for a compliance audit?"
Types of Questions
Bobby handles several kinds of questions well. Use these patterns as starting points.
How-to questions
Ask Bobby how to perform a task:
- "How do I add a new device to asset management?"
- "How do I submit a scan through the Scan API?"
- "How do I deploy the Bitscanner agent on my internal network?"
Explanation questions
Understand a concept or feature:
- "How is the security score calculated?"
- "What's the difference between the Bitcollector and Bitscanner agents?"
- "What does a Critical vulnerability severity mean?"
Troubleshooting questions
Get help when something isn't working:
- "Why isn't my scan completing?"
- "My dashboard isn't showing recent data. What should I check?"
- "I'm getting a 401 error from the Scan API. How do I resolve it?"
Recommendation questions
Ask for guidance and priorities:
- "What's the best way to improve my security score?"
- "Which vulnerabilities should I fix first?"
- "Which compliance framework should I start with?"
Navigation questions
Find your way around the platform:
- "Where do I find my vulnerability findings?"
- "Where do I download the scanner agents?"
- "Where do I find my Tenant ID?"
Conversation Tips
Bobby keeps track of the conversation, so you can refine an answer instead of starting over.
Follow up
- "Can you explain that in more detail?"
- "What's the next step after that?"
- "How does that apply to my setup?"
Redirect
If the first answer misses the mark, say so and add the missing detail:
- "That's not quite what I meant — I'm asking about the Scan API, not the scanner agents."
- "Can you focus on the compliance side of this?"
- "I need this specifically for AWS resources."
Ask for examples
- "Can you give me an example?"
- "What would that look like in practice?"
- "Show me a sample request."
What Each Bobby Can and Can't Do
The two surfaces differ most in what they're allowed to touch. Matching your request to the right version saves time.
The documentation search assistant
This Bobby is a read-only guide. It explains features and points you to the right docs, but it has no access to your account and no live data.
- ❌ "Show me my vulnerabilities" → ✅ "How do I view my vulnerabilities?"
- ❌ "What's my current security score?" → ✅ "How is the security score calculated?"
- ❌ "Delete my old assets" → ✅ "How do I archive old assets?"
The in-platform assistant
This Bobby understands your session and can act on your behalf — but only within guardrails. It proposes each change and runs it only after you confirm, it never deletes data, and it stays inside your role's permissions and your plan. For anything outside those bounds, it will explain how to do it rather than doing it.
Neither version of Bobby has real-time information from outside Cert-IX. It won't fetch live news, external threat feeds, or the public web. Questions like "What's the latest CVE in the news?" are better answered by the platform's own Vulnerability Management, which is built on real scan findings.
Getting Better Answers
Bobby improves when you tell it how it's doing.
- Rate responses. Where a rating control is shown, mark answers helpful or unhelpful. The signal helps improve future answers.
- Report inaccuracies. If Bobby gives an answer that looks wrong, note the question and the response and report it through the feedback options. Bobby's docs answers cite their sources, so you can always check an answer against the linked page.
Privacy and the AI Notice
Bobby is an AI assistant, and Cert-IX surfaces an AI/GDPR notice where you interact with it. A few things worth knowing:
- The documentation search assistant runs anonymous sessions and doesn't require an account.
- Don't paste secrets — passwords, API keys, or tokens — into the chat. Ask Bobby how to rotate or configure a credential instead of sharing the credential itself.
- Cert-IX is EU-hosted and uses a small number of sub-processors (including for the underlying AI model) under Standard Contractual Clauses. See the privacy notice for how data is handled.
Learn More
- Bobby Overview — what Bobby is and where it appears.
- Bobby's Capabilities — the topics Bobby can help with.
- Vulnerability Management — the feature behind most "which should I fix first?" questions.
- Scan API — Getting Started — for the scan and automation questions Bobby often points to.
War diese Seite hilfreich?