Monthly, traces personal data end to end — where it enters the system, where it is stored, where it leaves, and how long it is retained — and compares the trace against the claims made on the published security and data-handling page. Any divergence is filed as a ticket.
- Identifier
pii-data-flow-audit- Version
- 1.0.2
- Steps
- 4
- Triggers
- 1
- pii
- data-privacy
- security
- compliance
- audit
- automated
When it runs
schedule.monthly- Schedule
- Day 1 of each month at 06:00 UTC
0 6 1 * * - Timezone
- UTC
The pipeline
The graph below is the one the workflow opens with in the builder — same steps, same layout, drawn on the same canvas. The run playing through it is a simulation; the branches and conditions are real.
- 01Monthly Schedule (1st, 06:00 UTC)
triggerThe event that starts the run.
- 02Clone Repository ⚠️ SET YOUR REPO
git.cloneShallow-clones the repository at the right ref.
- 03Run PII Data Flow Audit
agent.sessionA coordinator delegates to specialist agents.
- 04File Audit Ticket ⚠️ SET YOUR TICKET INTEGRATION
ticket.createOpens a ticket on the connected tracker.
The agent
PII Data Flow Auditor
- Base type
- Senior Developer
- Temperature
- 0.2
- Max iterations
- 50
- Tools
- 4
Filesystem · 2
read_fileRead File · readlist_dirList Directory · read
Code search · 1
code_searchCode Search · read
Status · 1
update_statusUpdate Status · write
Related playbooks
Access Review
Monthly compliance scan of workspace members, integrations, service accounts, and valid tokens, routing flagged items through owner approval.
Audit Evidence Collector
Monthly assembly of the SOC 2 / ISO 27001 evidence pack from deploy, access, incident, and vulnerability data, calling out any gaps.
SBOM Generator
Generates a CycloneDX/SPDX software bill of materials on each release, diffs it against the previous release, and attaches it.