AI AGENTS
SOC2 GitHub Access-Control Evidence Collector
On a monthly schedule, pulls every GitHub org member, their role, and 2FA status.
How it runs
The automated pipeline, trigger to output.
- TriggerMonthly schedule fires
- ActionList GitHub org members, roles, and 2FA statusGitHub
- LogicFlag members missing 2FA or excess owners
- ActionWrite dated evidence record to controls registerAirtable
- OutputPost roster summary and exceptions to SlackSlack
What it does
Produces auditor-ready evidence for SOC2 logical-access controls (CC6.1, CC6.2) by snapshotting who has access to your GitHub organization, at what privilege level, and whether two-factor authentication is enforced. Each run becomes a dated, immutable evidence artifact in your controls register.
When to use it
Run it on the first of every month so that when an auditor asks "show me your access list for Q2," you already have twelve dated snapshots instead of scrambling to reconstruct history. Useful for any team that gates production via GitHub.
How it works
- 1A scheduled trigger fires at the start of each month.
- 2The flow calls the GitHub org API to list all members, their team memberships, and admin/write/read roles.
- 3A logic step flags members without 2FA enabled and any owners beyond an approved threshold.
- 4It writes a new dated row to the Airtable evidence register with the full roster and the flagged exceptions attached.
- 5A Slack message summarizes the headcount, exception count, and a link to the evidence record for the control owner to review.
Set it up
What you configure once, before turning it on.
- 1Connect GitHubRepos, issues, pull requests, actions.
- 2Connect AirtableBases, tables, views, automations.
- 3Connect SlackChannels, DMs, threads, mentions.
- 4Set each agent's modelWe leave models unset so you pick the tier — fast + cheap, or top-quality.
- 5Tune it to your dataEdit the prompts, filters, and field mappings so it matches how your team works.
- 6Test, then turn it onRun once against a sample, confirm the output, then enable the trigger.
More AI Agents workflows
Custom Metrics Cardinality Spike Pager
A webhook from a Datadog monitor fires when custom-metric cardinality jumps; an agent pinpoints the offending metric and tag, estimates the added cost.
Sentry-to-Confluence Runbook Updater
When a Sentry issue is resolved, the agent finds the matching Confluence runbook page and proposes an inline update with the verified fix.
Stale Doc-PR Chaser for Runbook Gaps
On a daily schedule the agent finds runbook doc PRs that were opened from resolved incidents but never reviewed, summarizes what each one fixes.
Resolved Incident to Public Troubleshooting Doc
For customer-facing errors resolved in Sentry, the agent drafts a sanitized troubleshooting entry and opens a PR to your ReadMe documentation.
On-Call Runbook Gap Closer: Resolved Sentry Issues to Doc PRs
An agent reads each newly resolved Sentry issue, compares the actual fix against your existing runbook, and opens a GitHub PR adding the missing remediation steps.
Weekly On-Call Doc-Gap Digest
Each week the agent reviews every Sentry issue resolved in the last 7 days, ranks the ones whose runbook coverage is missing or thin.
Run it inside a business
This workflow drops into a full company template. Import the org, and this is one of the playbooks its agents run.

Run this workflow in your colony.
14-day trial. No DevOps. No Sales call. Provisioned in under a minute.
