> ## Documentation Index
> Fetch the complete documentation index at: https://docs.opal.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Write OpalScript with AI

> Describe an automation in plain language and let the OpalScript assistant write, validate, and dry-run the script for you.

The OpalScript AI assistant writes and edits scripts from a plain-language description. Tell it what the automation should do, and it drafts the script, checks it against OpalScript's built-ins, dry-runs it, and proposes the result as a diff you can accept or discard. You can also ask it questions about the script you have open.

<Note>
  Only Opal Admins can use the assistant. Read-only Admins can open the editor but not the assistant.
</Note>

## Write a script with the assistant

1. Navigate to **Admin** > **OpalScript** > **Editor**, open a script, then select **Assistant** at the top right of the editor.

   <img src="https://mintcdn.com/opalsecurity/dCo4knZa2daZEqCz/images/docs/opalscript-editor-9.png?fit=max&auto=format&n=dCo4knZa2daZEqCz&q=85&s=8099da7cad4f19b36661c1766ad2fdd9" alt="The OpalScript editor with the OpalScript assistant panel open on the right. The script &#x22;AI Assistant Demo&#x22; holds only the placeholder comment. The panel reads &#x22;Describe the script you want and I'll write it, checking the built-ins and validating as I go.&#x22; above three suggested prompts: Auto-approve low risk, Require justification, and Time-box access. A message box at the bottom reads &#x22;Describe the script you want…&#x22;." width="3440" height="1992" data-path="images/docs/opalscript-editor-9.png" />

2. Describe what you want, or pick one of the suggested prompts. For example: "Deny requests with no reason given."

3. When the assistant changes the script, the editor shows a **Proposed change** diff. Select **Accept** to load the change into the editor, or **Discard** to drop it.

   <img src="https://mintcdn.com/opalsecurity/dCo4knZa2daZEqCz/images/docs/opalscript-editor-10.png?fit=max&auto=format&n=dCo4knZa2daZEqCz&q=85&s=622c90e6598c76de1b0f14c1ab8dc880" alt="The editor showing a Proposed change diff with Discard and Accept buttons. The placeholder comment is removed, and the added lines read the request's reason and call actions.deny when the reason is missing or blank. In the assistant panel, the prompt &#x22;Deny requests with no reason given.&#x22; is followed by &#x22;Validated script · no issues&#x22;, &#x22;Ran a dry run · 0 context items&#x22;, a Proposed script card with a Review changes link, and a summary of what the script does." width="3440" height="1992" data-path="images/docs/opalscript-editor-10.png" />

4. Accepting doesn't save. [Test the script](/docs/opalscript-editor#test-a-script-before-you-use-it), then select **Save**.

Keep refining in the same conversation, for example: "Also allow requests under 2 hours without a reason."

## What the assistant does while it works

The assistant doesn't just generate text. As it works, it uses tools against your organization and shows each step in the panel:

| Step | What it does |
| - | - |
| **Validate** | Runs the same checks the editor runs on save, and fixes any errors before proposing the script. You see "Validated script · no issues" when it passes. |
| **Dry run** | Executes the draft against a sample request without taking any action, to catch runtime errors. |
| **Look up entities** | Finds the users, resources, and groups you mention, so the script uses their real IDs instead of placeholders. |
| **Look up tags** | Lists the tag keys on your resources and groups, so tag-based conditions match what you actually use. |
| **Search the web** | When a script calls an outside API, finds that API's documentation. |

## Suggested prompts

The prompts the assistant offers depend on the type of script you have open:

| Script type | Suggested prompts |
| - | - |
| Request review | **Auto-approve low risk**, **Require justification**, **Time-box access** |
| Delegation condition | **Delegate to manager**, **Delegate by team** |
| Paladin context <Badge color="orange" size="sm">Beta</Badge> | **Device posture** (Jamf Pro), **Endpoint detections** (CrowdStrike), **Sign-in risk** (Okta) |

## Conversations

Each conversation belongs to one script and one user. It picks up where you left off, even on another device. To start over, select the trash icon (**Clear conversation**) at the top of the assistant panel.

You can resize the assistant panel by dragging its edge. The editor remembers whether you left it open.

## Tips for good results

* **Say what should happen in every branch.** "Approve if X, deny if Y, otherwise leave it for a human" produces a more predictable script than "approve if X."
* **Name real things.** Mention the resource, group, tag, or user by name, and the assistant looks up its ID for you.
* **Mention outside systems and secrets.** If the script should call an API, name the service and the [secret](/docs/opalscript-utilitymodules#secrets-module) that holds its credential. The host must be on the [egress allowlist](/docs/opalscript-utilitymodules#egress-allowlist).
* **Always review and test.** The assistant validates and dry-runs its work, but you own the script. Read the diff, then use a [test run](/docs/opalscript-editor#test-a-script-before-you-use-it) before you save.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.