Skip to content

Documents and the canvas

The canvas is the document editor that sits beside the chat. You write in it, the agent writes in it, and you both see the same text. This is where most of the real work in Colleag happens.

Every document is a plain Markdown file in your product's Git repository. What you see in the canvas is that file, formatted.

Open the canvas

Any of these opens it:

  • Click Documents at the top of the chat, or press Ctrl+Shift+D.
  • Ask an agent to open or change a document — the canvas opens by itself.
  • Click a document in the Execution plan.

Close it with the × at the top left of the canvas. The chat widens back out.

Find a document

The panel on the left of the canvas is headed PRODUCT DOCUMENTS. At the top sit Import documents, + New and the Switch product selector. Products that belong to a family are grouped in the selector: the family first, as EverTag Station · platform, then its members indented below it, as ↳ 232011 EverTag Station bat US.

Below the selector come the sections. Each has a ▶ toggle, a count and an ⓘ button that explains what the section holds.

Section What is in it
Engineering documents The product's own documents as a folder tree: product-level/ with one folder per discipline and assemblies/ with one folder per assembly.
Shared documents · family name Only on a member product. The family's documents, read through. Opening one switches the workspace to the family product — that is where the file lives. Rows carry a shared chip.
Family members Only on a family product. Its member products; click one to switch to it.
Expected documents The documents Colleag expects for this product's type and phase — the document model. A missing one is a placeholder with two ways out: Create it from the built-in template, or mark it N/A with a reason. A document that exists but has not reached the status its procedure requires — a draft where approval is required — is listed under Not yet at required status.
Imported originals The source files under imported/ — PDF, Word, Excel, STEP, drawings — kept for provenance. Download to open; they are not edited in the canvas. Their extracted text is searchable.
ERP assemblies The structure your ERP holds for the linked article. Only shown when the organisation has an ERP connector. See ERP assemblies.

What the workspace is for

Not every workspace is a product you develop. A workspace created for an ERP article starts as what the ERP says the article is, and the list of expected documents follows:

Kind What is expected
Product we develop The full list: requirements, design, verification, regulatory, production, customer documents. The default, and what a workspace made without an ERP article is.
Purchased article The supplier's datasheet or specification, the supplier approval, material compliance declarations (RoHS, REACH), the safety data sheet and UN 38.3 documentation when it contains batteries, and an incoming inspection instruction.
Subcontracted part The part specification or drawing, the supplier approval, a supplier quality agreement, incoming inspection and change notices.
Structure level (fictitious) or service Nothing.

The Kind selector at the top of Expected documents shows which list the workspace follows, and ERP: purchased beside it says what the ERP calls the article. When the two disagree — a product you developed that is linked to an article the ERP calls purchased — a notice says so and offers the switch. Nothing switches on its own, and switching never touches a document: only what is expected of the workspace changes.

Product properties. Yes-or-no facts about the product — contains batteries, has a radio, sold in the EU — that add the conditional documents to the list. For a purchased article only Contains batteries matters: it adds the safety data sheet and UN 38.3. The others govern documents that exist only in the product list.

Cybersecurity (CRA)

With the CRA monitoring module, a product sold in the EU with a data connection has a Cybersecurity (CRA) row above its document tree. It opens the product's page under Security in the rail, not a document: the product's technical file at a glance, and the one place for the SBOM upload and the check. The documents themselves stay in the tree under product-level/security/; opening one from the page brings you back to the chat with that document beside it. A member product shows its family's overview, where the SBOMs, the log and the reports are kept, with a link to the family.

Security in the rail opens on all your products in scope: how many matches wait for a verdict, how many are exploited, each product's state, the module's routines and the status reports. Status report there writes one CRA status report for the products you pick and files it as a draft among the company documents; tick Repeat every Monday to make it a routine of the regulatory colleague.

The overview opens with three numbers: how many matches wait for your verdict, how many are exploited, and how many SBOMs there are. Below them is one card each for the following. Rows with a chevron open to show more, and they start closed every time.

Every title, number and row has a small (i) next to it. Hover it to read what that piece is for — what the regulation asks — and how Colleag meets it. The same text is the first thing an opened row shows, and the documents under an obligation carry the description from the document model. Manual next to the page title opens this section.

  • Obligations — the risk assessment, the SBOM per firmware image, vulnerability handling, security information for users, and the EU declaration of conformity. Open a row to see the documents that carry it, each judged against the status its procedure requires. A missing one has Draft with the colleague, which creates the document from its outline and hands it to the discipline's agent.
  • Vulnerabilities — how many matches wait for your verdict and on what evidence. Compiled code by subsystem opens the matches in code your build compiles, grouped by subsystem. Review with the colleague opens the log and asks the firmware agent to go through the matches with you. Every row's status stays proposed until you change it, or until you press Confirm N. That marks every match proposed as not affected (the advisory's file is not in your build) as not affected in one step, and writes your name and the date into each row. A row that a later release reopened is left for you to look at.
  • SBOMs — one row per firmware image and release. Open a row to see what it runs on, when it was imported and whether the build's compiled-file list is stored. To add one, press Upload SBOM:
  • choose the file your build writes (CycloneDX JSON, SPDX JSON or SPDX 3 JSON-LD);
  • name the image and its version;
  • optionally, name the member products that run it;
  • add the build's compile_commands.json when you have it. The check uses it as evidence.

The original is kept under imported/security/sbom/ and a summary page under product-level/security/sbom/. Publish both from the commit panel. - Firmware colleague — the colleague's last nightly runs. - Regulation — what applies and when. The RED cybersecurity rules apply to radio products, CRA reporting has applied since 11 September 2026, and the full CRA applies from 11 December 2027. Open a step to see what it asks. - The art. 14 clock, when a match is one CISA lists as exploited. It shows the early-warning, notification and final-report deadlines, counted from when the check found the match, with the draft a click away. Nothing is sent: a person decides and submits on the ENISA platform.

Ask the colleague, at the top, asks in the chat what is missing, what waits for you, and what to do first; Colleag brings in the firmware colleague as needed.

Check now looks every component with a version and a CPE up in the US National Vulnerability Database. New matches are added to the vulnerability log as proposed rows, one per component, version and CVE. A match whose advisory names a source file your build never compiled is proposed as not affected, and says which file; the rest wait for your verdict. A row already in the log is never added again, so what you dismissed stays dismissed; a later release that ships the same component version is added to the row's Affected releases instead, with a note when that release compiles code the verdict said was absent.

The same check runs by itself every night for every product with an SBOM. Whoever uploaded the SBOM gets the firmware colleague's morning briefing as a notification — what was looked up, what is new, what waits for a verdict, or that the run failed — and clicking it opens the overview. A new exploited match also gets a draft early warning under product-level/security/reports/, with the Cyber Resilience Act deadlines filled in.

Further down, a COMPANY DOCUMENTS heading holds Standards (your purchased standards library), Processes (your procedures and SOPs) and General documents (other company documents). See Standards and SOPs.

Small markers in the tree tell you the state of each file:

Marker Meaning
Red dot Unsaved — you are editing right now
New Created but never published
Unpublished Saved but not yet published
Published Live in the published version
Deleted Removed, pending publish

Families and members

On a member product, the family's documents count for the member too, except the article-bound types — CE declaration of conformity, FCC filing, label artwork and sales datasheet — which each member must have itself. Which types are expected follows the member's own properties: an EU member with a data connection is expected to have the cybersecurity documents, a US-only member is not. The chat header shows a chip so you know where you are: family on a family product, member of … on a member. See Product families.

Opening a document from a different discipline switches the chat to that discipline's agent and picks up its most recent conversation, so the agent you are talking to always owns the document in front of you.

Editing and suggesting

The button at the top right of the canvas switches between two modes:

  • Editing — your changes go straight into the document.
  • Suggesting — your changes are marked as suggestions to accept or reject.

The same two modes apply to the agent. When an agent proposes a change you get an inline diff: removed text struck through in red, new text highlighted in blue. Accept or reject it. When an agent edits directly, the document simply updates and the canvas reloads.

Use Suggesting on anything approved

On a released or approved document, suggesting keeps the original intact until someone signs off on each change. On an early draft, editing is faster and perfectly safe.

Ask the agent about what you are reading

Select some text in the canvas and ask the agent about it. Your question goes to the chat together with the document path and the exact passage you highlighted, and the agent is told to change only that passage. This is the most precise way to get an edit — far better than describing where the problem is in prose.

The canvas toolbar

Control What it does
× Close the canvas
Title The document's name, with a Draft badge when it is unpublished and an orange dot when there are unsaved changes
ⓘ Show document properties — the structured fields such as owner, status and revision
‹ Version n of m › Step through earlier versions of the document
A− / A+ / 100% View zoom. Display only — it does not change what is saved or exported
Copy Copy the whole document to the clipboard
Download Download the file
Editing / Suggesting Switch edit mode

Document properties

Click ⓘ to open the properties panel. These are the structured fields kept at the top of the file — things like the owning discipline, status and revision — and they are what drives revision numbering when you publish. Editable fields can be changed directly here.

Importing existing documents

Click Import documents at the top of the PRODUCT DOCUMENTS panel to bring in Word, Excel, PDF and drawing files. Colleag reads each one, converts it to Markdown, proposes the discipline it belongs to and shows you a review screen before writing anything. The original file is kept under Imported originals so an answer can always be checked against the source.

You decide where the documents land:

  • Before you upload you can set Documents land in: an assembly (the article itself, an assembly from the ERP structure, or a folder that already exists) and a discipline. Choose the article and quality, for example, and everything lands under assemblies/<article>/quality/. Leave it on Let Colleag suggest and Colleag guesses per file, choosing among the product's own assemblies. The choice is remembered for the next import into the same product.
  • In the review every row's type, assembly and discipline can be changed, and the path beside it follows at once. Set for selected changes all the checked rows at once. The pencil next to the path lets you write it yourself. Rows you changed are marked changed.

What the path column shows is what is stored.

Standards in the canvas

Under COMPANY DOCUMENTS the canvas also shows a Standards tree with the standards your organisation has uploaded. Entries can carry warnings — for example that a document was read by OCR from a scan and should be checked against the original, or that the extraction hit a size limit and is incomplete. See Standards and SOPs.

Reports from the chat

An agent can also give you a Word, Excel, PDF or PowerPoint file to download. Saving that report into the product keeps the Markdown, not the Office binary. See Reports and downloads.

Saving and publishing

Saving is not publishing. Your edits are saved as you work, but the document stays a draft until you publish it. The sidebar's orange n drafts counter tells you how much is waiting. See Publishing and reviews.

Troubleshooting

Problem What to do
The canvas will not open You need a product selected. Commercial, Corporate and Quality System agents have no product documents.
An agent edited the wrong part of the document Select the exact text first, then ask. Without a selection the agent decides for itself what to change.
Your change disappeared Check the version stepper — you may be looking at an older version.
Text looks too small or too large That is the zoom. Click the percentage to reset to 100%. It never affects the saved file.