Workflows - Privacy by design

Connect the tools your teams already use to MineOS so every new vendor, product or AI tool gets the right review automatically, from request to approval.

Privacy by design means reviewing risk when something new starts, whether it's a vendor, a product feature or an AI tool, rather than discovering it later. Workflows make this automatic. They connect the tools where your teams already make requests, such as procurement, ticketing, intake forms and SaaS management, to your MineOS inventory and assessments. Every new request triggers the right privacy, security or AI review, and the outcome flows back to where the request started.

Privacy, security and AI frameworks worldwide increasingly expect risk to be assessed before new processing begins. Workflows help you do that consistently, without relying on teams to remember to ask.

How a workflow runs end to end

  1. Intake. A request starts in a connected tool, for example a purchase request in ZipHQ, a Jira ticket, a Typeform submission, or a new app detected by Torii.
  2. Inventory. MineOS adds the vendor or system to your inventory, or matches it to one that's already there.
  3. Enrichment. MineOS gathers everything Mira will need. This includes the context the integration brings in, such as questionnaire and form answers, ticket and request fields, and attached files like contracts, DPAs and security documents. Vendor scout then researches the vendor to fill in what's still missing, such as data types, hosting locations, certifications and AI use.
  4. Assessments. Rules open the right assessments based on what's known so far, and assign owners and collaborators.
  5. Drafting. Mira AI autofill drafts answers using everything collected along the way, including the files attached to the original request.
  6. Review and collaboration. The owner reviews Mira's draft, accepts or edits suggestions, and invites collaborators, such as the requester, the vendor or a security lead, to answer what only they can.
  7. Additional assessments (optional). If something new comes to light, for example an answer reveals the vendor uses AI or transfers data abroad, rules open follow-up assessments, which go through the same drafting and review steps.
  8. Decision. When the assessments are completed, a rule updates the vendor's status, for example to Approved or Rejected, and the outcome can be sent back to the source tool.
  9. Ongoing review. Approved vendors are scheduled for regular reassessment.

Notifications keep the right people informed at each step.

Why the context you bring in matters

Mira AI drafts assessments from the context it has. The more a workflow brings in at intake, the less your team has to write by hand.

ContextWhere it comes fromHow Mira uses it
Request detailsForm answers, ticket fields, purchase request fieldsDescribes what the vendor or project is for, who uses it and what data it touches
FilesContracts, DPAs, security questionnaires and certifications attached to the request, or Confluence specs linked to a Jira ticketGives Mira evidence for answers about data handling, retention, sub-processors and security controls
Vendor researchVendor scoutFills in public details about the vendor, such as hosting, certifications and AI features
Security postureVanta [confirm what's imported]Adds security and compliance information about the vendor
Your business profileMira AI agents settingsTailors drafts to your company, the regions you operate in and your internal policies

Every suggestion includes its evidence, so reviewers can see exactly which file or field an answer came from.

Integrations

IntegrationWhat it brings into workflowsLearn more
ZipHQImports vendors from purchase requests, when a request is submitted or approved, with its details and attachments, and can send the review outcome back to Zip
Jira (and Confluence)Starts a review when a ticket matches your criteria, uses linked Confluence pages as context, and updates the ticket with the outcome
TypeformTurns intake form submissions, such as a new vendor or AI tool request, into inventory records and assessments, including uploaded files
VantaBrings vendors and their security information from Vanta into your inventory and assessments [confirm]
ToriiAdds SaaS apps discovered by Torii to your inventory, so new tools are reviewed as soon as they appear [confirm]

Rules

Rules decide what happens at each step. They run automatically and can be combined.

Rule typeExamples
Trigger assessments from vendor dataOpen a security assessment when a vendor is marked as critical. Open a privacy assessment for every vendor that processes personal data.
Trigger assessments from Vendor scoutOpen an AI assessment when Vendor scout finds the vendor offers AI features. Open a transfer assessment when it finds hosting outside your main region.
Trigger assessments from other assessmentsOpen a DPIA when a privacy assessment answer indicates high-risk processing. Open an AI assessment when an answer mentions AI.
Assign owners and collaboratorsAssign the privacy team as owner, and invite the requester and the vendor contact as collaborators.
Update vendor statusApprove a vendor when all its assessments are completed with no high risks, or move it to In evaluation when assessments open.
NotificationsAlert the owner by email or Slack when a new review starts, when collaborators respond, or when a decision is made.

Example workflows

Vendor onboarding from procurement. An employee requests a new marketing tool in ZipHQ and attaches the vendor's DPA. When the request is approved, MineOS adds the vendor, runs Vendor scout and opens a privacy assessment. Vendor scout finds the tool uses AI, so a rule also opens an AI assessment. Mira drafts both using the DPA and the request details. The privacy team reviews, invites the requester to confirm how the tool will be used, and completes both assessments. A rule approves the vendor and sends the outcome back to Zip.

New product feature from Jira. A product manager moves a Jira ticket to Privacy review, with the feature spec linked in Confluence. MineOS opens a privacy assessment, and Mira drafts it from the ticket and the spec. An answer shows the feature profiles users, so a rule opens a DPIA. The ticket is updated with the decision when both assessments are completed.

New AI tool detected. Torii detects that a team has started using a new AI writing tool. MineOS adds it to the inventory and opens an AI assessment, assigned to the AI governance lead, with the team's manager invited as a collaborator. Notifications keep both in the loop until the tool is approved or rejected.

Missing an integration?

If the tool your teams use to request vendors, projects or AI tools isn't listed, contact your customer success manager. MineOS can build additional integrations and rules to fit your process.

Set up a workflow

Workflows are set up together with your MineOS team. [confirm: or self-serve] Your team will help you map your current process, choose the integrations and rules you need, and configure templates, owners and notifications for each step.


Did this page help you?