e-volv

Compliance playbook

SubprocessorScan

Monthly comparison of dependencies and integrations against the published subprocessor list, flagging new or removed third-party data processors.

Monthly, compares the current dependency and integration set against the subprocessor list published in the privacy policy and DPA. Any new dependency or integration that transmits customer data to a third party is flagged as a candidate subprocessor requiring disclosure, and listed subprocessors no longer in use are also flagged.

Identifier
subprocessor-scan
Version
1.0.1
Steps
4
Triggers
1
  • compliance
  • privacy
  • subprocessors
  • audit
  • automated

When it runs

Scheduleschedule.monthly
Schedule
Day 1 of each month at 06:00 UTC 0 6 1 * *
Timezone
UTC

The pipeline

The graph below is the one the workflow opens with in the builder — same steps, same layout, drawn on the same canvas. The run playing through it is a simulation; the branches and conditions are real.

  1. 01
    Monthly Schedule (1st, 06:00 UTC)trigger

    The event that starts the run.

  2. 02
    Clone Repository ⚠️ SET YOUR REPOgit.clone

    Shallow-clones the repository at the right ref.

  3. 03
    Run Subprocessor Scanagent.run

    One agent works the task with its toolkit.

  4. 04
    File Subprocessor Scan Ticket ⚠️ SET YOUR TICKET INTEGRATIONticket.create

    Opens a ticket on the connected tracker.

The agent

Subprocessor Auditor

Base type
Senior Developer
Temperature
0.2
Max iterations
50
Tools
5

Filesystem · 2

  • read_fileRead File · read
  • list_dirList Directory · read

Code search · 1

  • code_searchCode Search · read

Tickets · 1

  • create_ticketCreate Ticket · write

Status · 1

  • update_statusUpdate Status · write