ENGINEERING
Weekly dependency blast-radius trend report from Snowflake
On a weekly schedule, aggregates every dependency-bump risk score logged that week from Snowflake, computes trend deltas by repo and severity.
How it runs
The automated pipeline, trigger to output.
- TriggerWeekly schedule fires
- ActionQuery trailing two weeks of risk scoresSnowflake
- LogicRoll up by repo/severity and compute deltas
- OutputPost trend digest to leadership SlackSlack
What it does
Turns per-PR risk scores into a weekly trend. It reads the score history your gate has been logging into Snowflake, rolls it up by repository and severity band, compares against the prior week, and delivers a readable digest with the biggest movers.
When to use it
Use it when leadership wants to know if supply-chain risk is trending up across the org, not just whether a single PR was safe. Good for weekly eng reviews and security reporting.
How it works
- 1A weekly schedule triggers the run.
- 2The flow queries Snowflake for all bump risk scores logged in the trailing seven days plus the prior week for comparison.
- 3An aggregation step groups by repo and severity band and computes week-over-week deltas.
- 4A logic step flags repos whose blast-radius score rose past a set jump.
- 5It formats a digest highlighting top risers, new critical exposures, and resolved ones.
- 6It posts the digest to the leadership Slack channel.
Set it up
What you configure once, before turning it on.
- 1Connect SnowflakeWarehouses, queries, shares.
- 2Connect SlackChannels, DMs, threads, mentions.
- 3Set each agent's modelWe leave models unset so you pick the tier — fast + cheap, or top-quality.
- 4Tune it to your dataEdit the prompts, filters, and field mappings so it matches how your team works.
- 5Test, then turn it onRun once against a sample, confirm the output, then enable the trigger.
More Engineering workflows
Gate breaking API PRs behind downstream consumer acknowledgement
When a PR introduces a breaking contract change, comments the impact summary back on the PR, applies a blocking label.
Publish a versioned API changelog to Confluence on each release tag
On a new semver release tag, gathers the contract changes since the last release and writes a clean.
Agent reviews model-license fit and suggests compliant swaps on the PR
When a PR adds a Hugging Face model, an agent reads the model card and license, judges fit against your commercial-use policy.
Upgrade Impact Router to Module Code Owners
Maps a dependency-bump PR's affected modules to their CODEOWNERS, then DMs each owner on Slack with only the changelog slice that touches code they own.
Re-Voice IVR Prompts on Phone-Tree Config Merge
When a phone-tree config change merges in GitHub, regenerates the ElevenLabs audio for any prompt whose script changed in the diff and opens a follow-up PR adding the new audio…
Upstream Release to Notion Upgrade Brief
When a watched package publishes a new release, fetches the release notes, maps them to the internal modules that depend on it.
Run it inside a business
This workflow drops into a full company template. Import the org, and this is one of the playbooks its agents run.

Run this workflow in your colony.
14-day trial. No DevOps. No Sales call. Provisioned in under a minute.
