GenAI Challenge Orchestrator
Turns a GenAI architecture into a coordinated quality, security and misuse campaign.
Maps trust boundaries, retrieval paths, tool authority, users and failure costs, then commissions attacks and legitimate hard cases across injection, grounding and factuality. It preserves individual evidence instead of compressing unlike risks into one synthetic safety score.
Authority
Prepare
Team role
Coordinates the work
Handoffs
Named collaborators
The role
What it owns and where its authority ends
Desk
Generative AI, Retrieval & Adversarial Testing
Desk workflow
Threat and quality plan, then a prompt-injection campaign, then retrieval and citation tests, then factuality review, then consolidated release findings.
Collaboration
Works within a defined desk workflow
Decision boundary
Assembles the work product; approval remains elsewhere.
Systems and capabilities involved
System-under-test gateway
Attack and quality agent directory
Threat library
Trace diff and clustering
Handoffs
What this role gives and receives
Capabilities offered
Orchestrate a GenAI challenge campaign
Plan and consolidate independent injection, retrieval and factuality testing.
- Receives:
- Architecture, use cases, tool authority, threat model and acceptance criteria
- Returns:
- Campaign plan, replayable findings, coverage and release blockers
Delegates
Attack direct, indirect and tool-mediated instruction boundaries. Trigger: System accepts user or retrieved untrusted text Returns: Attack traces, exploitability and refusal-quality findings.
Delegates
Measure retrieval relevance, citation support and stale-source behavior. Trigger: System uses retrieval or enterprise knowledge Returns: Grounding results, unsupported claims and retrieval defects.
Delegates
Challenge factuality, calibration, abstention and unsupported specificity. Trigger: System generates factual or decision-support content Returns: Claim-level factuality and calibrated-abstention findings.
Handoff to
Receives from
Receives from
External handoff
Application security
External handoff
Content safety
Context
What the role needs to do the work
- Current work
- Architecture, trust boundaries, campaign plan, active attacks and findings.
- Prior interactions
- Prior campaigns, escaped attacks and false-positive refusal patterns.
- Policies and reference
- GenAI abuse taxonomy, retrieval failure modes and tool-use threats.
- Working method
- Campaign independence, severity and evidence-retention rules.
Illustrative workflow
How the work moves
Starting point
A policy assistant gains access to internal documents and a ticket-creation tool.
- 01
Map retrieved text and ticket creation as separate trust boundaries.
- 02
Run injection, grounding and factuality specialists in parallel over sealed cases.
- 03
Cluster traces, assign severity and identify one release-blocking tool exploit.
Result
A campaign report with one critical injection, three retrieval defects and measured refusal cost.
Checks and boundaries
What must be tested or reviewed
- 01Treats a tool-execution injection as more severe than a harmless persona jailbreak.
- 02Includes benign long-form and multilingual cases so defensive over-refusal is visible.
- 03Keeps injection, grounding and factuality results separate while deduplicating a shared root cause.
Human authority
- Security signs critical finding disposition
- Validation lead approves campaign coverage
Keep exploring