audit-log-completeness-checker
02:00 UTC · dailyVerifies every privileged action across the platform lands in the canonical audit_logs table. The agent that feeds the Sprinto Q3 2026 evidence binder.
Sixteen scheduled autonomous agents run TagDrishti. Three feed the SOC 2 Type II evidence binder directly. Four watch revenue health (MRR, overage, churn, trial-conversion). Five guard product reliability (deploy regressions, dependency CVEs, cron-race bugs, marketing-copy drift, tier-gating drift). Two run competitive and regulatory intel. Two more shepherd customer onboarding. The same engineering discipline you’re buying when you monitor your tags with us.
Each number below is a production agent — code committed, schedule wired, output reviewed every week. Not a roadmap deck.
Every cron is listed. Mondays at 06:00 UTC are the busy slot — four reliability agents run together. We monitor agent_runs latency on Monday mornings; we’d stagger if it ever spiked.
| When (UTC) | Agent | Domain |
|---|---|---|
| 02:00 UTC · daily | audit-log-completeness-checker | Compliance & SOC 2 evidence |
| 03:30 UTC · daily | churn-signal-detector | Revenue & billing |
| 03:30 UTC · daily | customer-onboarding-watcher | Customer success |
| 04:00 UTC · daily | overage-billing-watcher | Revenue & billing |
| 05:00 UTC · daily | backup-verification | Compliance & SOC 2 evidence |
| 06:00 UTC · Mondays | mfa-and-access-review | Compliance & SOC 2 evidence |
| 06:00 UTC · Mondays | dependency-watcher | Product reliability |
| 06:00 UTC · Mondays | cron-race-sniffer | Product reliability |
| 06:00 UTC · Mondays | marketing-drift | Product reliability |
| 06:00 UTC · Mondays | tier-drift | Product reliability |
| 06:00 UTC · Thursdays | industry-trend | Competitive & market intel |
| 06:00 UTC · Wednesdays | competitor-signal | Competitive & market intel |
| 06:30 UTC · Mondays | activation-funnel-tracker | Customer success |
| 06:30 UTC · Mondays | feature-usage-tracker | Feature usage |
| 07:00 UTC · daily | mrr-tracker | Revenue & billing |
| 09:00 UTC · daily | trial-conversion-predictor | Revenue & billing |
| after deploy · or manual | deploy-sentinel | Product reliability |
For each agent: what it watches, when it runs, what it does on a finding. We expose this because enterprise prospects ask — and because transparency is the only honest answer to “who’s watching the watcher.”
Three agents directly feed the Sprinto / Vanta / Drata audit binder. The evidence pipeline runs without a human in the loop.
Verifies every privileged action across the platform lands in the canonical audit_logs table. The agent that feeds the Sprinto Q3 2026 evidence binder.
Verifies every Clerk superadmin has MFA, every GCP service account role matches inventory, every GitHub collaborator is active within 90 days, every Vercel team member has 2FA.
Verifies every expected backup ran within the last 30 hours, with tolerance. Daily SOC 2 control CC7.1.
MRR, overage, churn, trial-conversion. The continuous founder dashboard, routed through Slack.
Signed-up / cancelled / refunded / upgrade-delta MRR from Paddle, with trend-line context. No page unless something material moved.
Chronic overages flag upsell candidates. Spikes are usually a customer bug. Downgrade-then-spike is denial-of-service abuse and pages immediately.
Scores trial tenants in their final 7 days. High-intent cohort gets warm outreach. At-risk gets a retention offer suggestion. M5 will add the LLM classifier.
Weighted churn-risk score: event drop 30%+ in 7d, stale login 14d+, recent downgrade 7d. Surfaces the at-risk account before it cancels.
Activation-funnel and onboarding-watch agents. Stuck signups get the right intervention at the right hour-bucket.
Weekly scan of 7–30 day-old signups. Detects cohorts that didn't cross the activation threshold (1K events in first 7d, site connected in 14d, first alert rule in 14d).
Detects stuck onboarding: no events sent, no second login, no workspace created. Buckets by hours-since-signup so the right intervention runs at the right time.
Deploy sentinel, dependency health, cron-race detection, marketing-copy drift, tier-gating drift. The platform watches its own seams.
Post-deploy regression watcher. Validates the deploy didn't break the four production regions before the next push lands.
Weekly `npm audit` + `npm outdated` sweep. Ignores allowlisted pins, evaluates upgrades, runs tests, proposes the PR.
Catches backend cron callbacks missing the `isControlPlaneRegion()` gate. Prevents the bug class where four regions all fire the same cron and produce duplicate Paddle charges.
Blocks shipping false ads. The agent that should have caught the $49 → $99 pricing drift before it shipped.
Prevents a Starter-tier user from accessing a Pro-tier feature because a developer forgot the auth gate. Static analysis, not runtime.
Competitor pricing changes and regulatory shifts surface within hours of publication.
Content-hash monitor on seven competitor pricing + changelog pages. We know when ObservePoint changes a tier before our sales team does.
Tracks the regulatory floor under the product. DPDP Act updates land in Slack the same week the gazette publishes them.
Zero-usage features get sunset; over-indexed features get tier-elevated. The product self-curates.
Surfaces which features nobody uses (kill candidates) and which features get disproportionate usage from a lower tier than expected (tier-elevation candidates).
The M3 milestone moves selected agents from GitHub Actions cron to Cloud Run, with a continuous-listening surface for customer signals. ETAs are next quarter; design specs live in docs/superpowers/specs/.
Every 5 minutes: /health on all four production regions, latency baseline tracking, version drift detection. Cloud Run, not cron.
M3Daily 02:00 UTC: region-by-region uptime, p95 latency vs SLAs, ingest backlog depth. Feeds the public status page.
M3Slack webhook → Cloud Run. Aggregates customer complaints, LLM-categorises, cross-tenant pattern detection. Stops a Magecart-tier issue from being a one-off ticket.
M3Hourly Sentry fingerprint clustering. ≥3 customers affected = P0. New error class = P2. The agent that catches the bug before three customer-success threads do.
M3Weekly Friday 18:00 UTC. Meta-agent: reads every other agent’s findings + recent merges, proposes inventory updates via PR comments.
M3Two specialised watchers under design review. Public spec drops alongside each launch. The roadmap target is a 25-agent fleet by Q4 2026.
M3A trust page that pretends agents replace everything reads as marketing. Three places they don’t.
A first-time-seen failure pattern requires human judgement. Agents triage, group, and surface; an engineer still owns the decision. The on-call rotation is real.
human-in-the-loopAn at-risk tenant flagged by churn-signal-detector still gets a human outreach email, not an LLM-drafted one. The agent surfaces; the founder writes the message.
human-in-the-loopaudit-log-completeness-checker generates evidence. It doesn’t decide which controls matter. The actual control design comes from the security review with the auditor.
human-in-the-loopSixteen agents run TagDrishti. The same engineering discipline ships in the product that monitors your tags. 30-day free trial, no credit card. Starter from $99/mo.