The GRC Vibe Coder's Playbook · Lesson 01 of 06
What should I build first?
Choose something small enough to finish.
All six lessons · Jump to a lesson
Start with a real problem and one person who needs it.
Our running example is a vendor risk assessment tool for a small GRC team.
Version one accepts a few vendor answers and returns a reviewable risk summary.
It is not a replacement for professional risk judgment.
A useful first version might ask whether a vendor uses customer data to train AI, supports data deletion, and documents incident notification.
The output should show each answer and why it affected the score.
Leave user accounts, dashboards, integrations, and automated approvals for later.

Put it into practice
Write down who will use your project, the problem it solves, and what the first working version must do.
Before you move on
Read the AI output critically. Does it match your project goal and the instructions in the prompt? Can you explain the recommendation or change in your own words? If not, ask for clarification or a smaller next step.
Save useful decisions and results in your project notes or GitHub repository. Do not treat a confident answer, generated code, or a passing check as a substitute for your own review.