AI AGENTS

SOC2 Audit-Window Evidence Package Assembler

On demand from a webhook, an agent gathers all control evidence for a named audit period from Airtable and GitHub, assembles a structured evidence package in Google Drive.

CategoryAI Agents
Enginepaperclip
Difficultyadvanced
Triggerwebhook
Steps6
Setup~25 min

How it runs

The automated pipeline, trigger to output.

  • TriggerWebhook supplies audit period datesHTTP webhook
  • ActionQuery evidence records for the windowAirtableAirtable
  • ActionAttach point-in-time GitHub PR historyGitHubGitHub
  • LogicCheck each control for coverage gaps
  • ActionBuild per-control folders and uploadGoogle DriveGoogle Drive
  • OutputSend audit lead the Drive link and gap listSlack

What it does

Collapses the worst week of every SOC2 audit into a single run. Given an audit period, it pulls the relevant evidence records, organizes them by Trust Services Criteria, and produces an auditor-ready folder so the team isn't hand-collecting screenshots the night before fieldwork.

When to use it

Trigger it when fieldwork is scheduled or when the auditor sends an evidence request list. It complements the collectors that gather evidence continuously by packaging that evidence into a deliverable.

How it works

  1. 1A webhook trigger supplies the audit period start and end dates.
  2. 2An agent queries Airtable for every evidence record dated within the window and groups it by control family.
  3. 3It calls GitHub to attach point-in-time artifacts like merged-PR review history for the window.
  4. 4A logic step checks each required control for at least one evidence item and flags coverage gaps.
  5. 5It creates a dated, per-control folder structure in Google Drive and uploads the artifacts.
  6. 6It messages the audit lead in Slack with the Drive link and the list of any controls still missing evidence.

Set it up

What you configure once, before turning it on.

  1. 1
    Connect AirtableBases, tables, views, automations.
  2. 2
    Connect GitHubRepos, issues, pull requests, actions.
  3. 3
    Connect Google DriveDocs, sheets, slides, files.
  4. 4
    Connect SlackChannels, DMs, threads, mentions.
  5. 5
    Connect HTTP webhookTrigger any URL on agent actions.
  6. 6
    Set each agent's modelWe leave models unset so you pick the tier — fast + cheap, or top-quality.
  7. 7
    Tune it to your dataEdit the prompts, filters, and field mappings so it matches how your team works.
  8. 8
    Test, then turn it onRun once against a sample, confirm the output, then enable the trigger.

Run this workflow in your colony.

14-day trial. No DevOps. No Sales call. Provisioned in under a minute.