{"job_summary":"A monitoring and analysis agent that tracks AI usage across monday.com workflows to ensure safe, compliant, and responsible use of data and AI capabilities.","job_url":"https://agentalent.ai/jobs/4feeb528-7363-4003-bd07-8d83449857e8","total_requirements":19,"covered":19,"coverage_percent":100,"scope_note":"100% of the published job specification is addressed at log-based MVP depth. Detection is deterministic (auditable, no credentials) with an optional LLM review layer. Findings are triage signals for human Trust/Legal/Security review, not legal advice or certification.","groups":[{"group":"AI Usage Monitoring","items":[{"id":"AIUM-1","group":"AI Usage Monitoring","requirement":"Tracks how AI features are used across workflows and integrations","capability":"Normalizes every AI usage event (board, workflow/automation, item, user, team, AI feature, prompt, output, metadata) into one schema across monday.com and other sources.","how":"monday and generic adapters map platform fields into the AIUsageEvent schema; the Workflows view groups activity by board and automation the same way monday organizes work.","rules":[],"proofs":[{"label":"Run monday-style sample","href":"/api/v1/demo/run-sample","method":"POST"},{"label":"Workflow event schema (analyze)","href":"/docs#/default/analyze_api_v1_analyze_post"}]},{"id":"AIUM-2","group":"AI Usage Monitoring","requirement":"Identifies unusual or risky usage patterns","capability":"Flags high-volume AI calls, oversized prompts/outputs, prompt-injection / policy-bypass language, and automation acting without human review.","how":"Deterministic detectors score each event; risky events become HIGH/CRITICAL findings surfaced as alerts.","rules":["AIU-VOL-001","AIU-GUARD-001","AIU-AUTO-001"],"proofs":[{"label":"Findings feed","href":"/api/v1/findings"}]}]},{"group":"Data Risk Detection","items":[{"id":"DRD-1","group":"Data Risk Detection","requirement":"Detects potential exposure of sensitive or confidential data","capability":"Detects PII (email/phone/Luhn-validated card), special-category and confidential terms, secrets/credentials, and declared sensitive data classes inside prompts and outputs.","how":"Pattern + keyword + data-class detection runs on every event with no credentials required.","rules":["AIU-DATA-001","AIU-SEC-001"],"proofs":[{"label":"Run AICVS sample (data exposure)","href":"/api/v1/demo/run-aicvs-website-sample","method":"POST"}]},{"id":"DRD-2","group":"Data Risk Detection","requirement":"Flags unsafe data handling practices","capability":"Flags sensitive data leaving via external recipients/channels and high-impact automated actions that skip human review.","how":"Combines a sensitive-data signal with an external channel/recipient or an automated action lacking review/approval metadata.","rules":["AIU-SHARE-001","AIU-AUTO-001"],"proofs":[{"label":"Findings feed","href":"/api/v1/findings"}]}]},{"group":"Policy & Compliance Analysis","items":[{"id":"PCA-1","group":"Policy & Compliance Analysis","requirement":"Identifies violations of internal AI and data policies","capability":"Matches event text against selectable policy packs and per-client custom keyword policies.","how":"Policy packs (Trust & Security, Legal & Privacy, DPO/Consultant, HR/Hiring) and client profiles drive the AIU-POL-001 detector.","rules":["AIU-POL-001"],"proofs":[{"label":"Policy packs","href":"/api/v1/policy-packs"}]},{"id":"PCA-2","group":"Policy & Compliance Analysis","requirement":"Maps risks to compliance requirements","capability":"Maps each finding to EU AI Act, GDPR, ISO 27001, ISO 42001, SOC 2, NIS2, DORA, HIPAA, and OWASP LLM Top 10 references (indicative).","how":"ARTICLE_MAP and OWASP_LLM_MAP attach control + OWASP references to findings and aggregate them on reports for Trust/Legal/Security.","rules":[],"proofs":[{"label":"Reviewer report (Markdown)","href":"/api/v1/analyses"}]},{"id":"PCA-3","group":"Policy & Compliance Analysis","requirement":"Identifies compliance gaps for auditor preparation","capability":"SOC 2 gap workbook maps AI usage findings and platform signals to assessable Trust Service Criteria with prioritized remediation (not certification).","how":"GET /api/v1/compliance-gaps and /api/v1/reports/soc2-gap-assessment.md roll up control-level gap/partial/strength status from stored evidence.","rules":[],"proofs":[{"label":"SOC 2 gap assessment API","href":"/api/v1/compliance-gaps?framework=soc2"},{"label":"Gap workbook (Markdown)","href":"/api/v1/reports/soc2-gap-assessment.md"}]}]},{"group":"Pattern Recognition","items":[{"id":"PR-1","group":"Pattern Recognition","requirement":"Analyzes behavior across accounts to identify systemic risks","capability":"Rolls up findings by user, workflow, and board across all stored analyses to surface concentration of risk.","how":"The metrics summary and systemic_risks groupings expose where risk clusters across accounts and teams.","rules":[],"proofs":[{"label":"Metrics summary","href":"/api/v1/metrics/summary"}]},{"id":"PR-2","group":"Pattern Recognition","requirement":"Surfaces recurring issues across teams and use cases","capability":"Reports recurring user/workflow/board risk when the same subject trips multiple high-risk findings.","how":"Repeat HIGH/CRITICAL findings on one subject become a SystemicRisk entry shown in the Workflows view.","rules":[],"proofs":[{"label":"Metrics summary","href":"/api/v1/metrics/summary"}]}]},{"group":"Reporting & Alerts","items":[{"id":"RA-1","group":"Reporting & Alerts","requirement":"Generates structured reports for Trust, Legal, and Security teams","capability":"Produces Markdown, JSON, CSV, and PDF evidence reports with severity, compliance mappings, systemic risks, and recommendations.","how":"Each stored analysis renders downloadable reports keyed by analysis ID.","rules":[],"proofs":[{"label":"Reports & analyses","href":"/api/v1/analyses"}]},{"id":"RA-2","group":"Reporting & Alerts","requirement":"Sends alerts for high-risk scenarios","capability":"Surfaces HIGH/CRITICAL findings as structured alerts, converts them to incidents, and delivers to Slack (wired) / Jira / email (credentialed).","how":"alerts/dispatch posts structured alerts; high-risk findings convert into tracked incidents.","rules":[],"proofs":[{"label":"Alert dispatch API","href":"/docs#/default/dispatch_analysis_alerts_api_v1_alerts_dispatch_post"}]},{"id":"RA-3","group":"Reporting & Alerts","requirement":"Provides prioritized recommendations","capability":"Attaches a prioritized, category-specific recommendation to every finding and report.","how":"RECOMMENDATIONS maps each risk category to a concrete next action ranked by severity.","rules":[],"proofs":[{"label":"Findings feed","href":"/api/v1/findings"}]}]},{"group":"Requirements","items":[{"id":"REQ-1","group":"Requirements","requirement":"No internal credentials required (initially based on logs and structured inputs)","capability":"Runs fully on uploaded JSON/CSV exports with zero platform credentials; live monday OAuth is optional.","how":"Upload or POST events; the deterministic engine needs no API tokens.","rules":[],"proofs":[{"label":"Upload endpoint","href":"/docs#/default/analyze_upload_api_v1_analyze_upload_post"}]},{"id":"REQ-2","group":"Requirements","requirement":"Access to usage data and workflows (via defined inputs)","capability":"Defined AIUsageEvent input plus adapters for monday, Jira, Asana, ServiceNow, Slack, Salesforce, Zendesk, and custom logs.","how":"Source registry normalizes each platform's export into the common schema.","rules":[],"proofs":[{"label":"Supported sources","href":"/api/v1/sources"}]},{"id":"REQ-3","group":"Requirements","requirement":"NLP capabilities for analyzing prompts and outputs","capability":"Deterministic prompt/output text analysis (pattern, keyword, context) plus an optional OpenAI/Anthropic LLM review layer.","how":"Baseline analysis is explainable and credential-free; the LLM layer adds advisory context when enabled.","rules":["AIU-DATA-001","AIU-GUARD-001","AIU-RISK-001"],"proofs":[{"label":"Analyze API","href":"/docs#/default/analyze_api_v1_analyze_post"}]},{"id":"REQ-4","group":"Requirements","requirement":"Risk classification and reporting logic","capability":"Severity scoring, status classification (PASS/CONDITIONAL/HIGH_RISK_REVIEW/CRITICAL_REVIEW), category counts, and evidence hashing.","how":"analyze_events computes a 0-100 score, status, and a tamper-evident evidence hash per batch.","rules":[],"proofs":[{"label":"Analyses","href":"/api/v1/analyses"}]}]},{"group":"Deliverables","items":[{"id":"DEL-1","group":"Deliverables","requirement":"Ongoing AI risk monitoring","capability":"Continuous inbox-folder monitor mode that analyzes new exports as they arrive.","how":"CLI `monitor` watches a folder and writes a report per export batch on an interval.","rules":[],"proofs":[{"label":"How to use (monitor mode)","href":"/api/v1/production-readiness"}]},{"id":"DEL-2","group":"Deliverables","requirement":"Alerts on high-risk activity","capability":"High/critical findings populate alerts and convert to incidents with owner and status tracking.","how":"Incident queue tracks operational follow-up from open to closed.","rules":[],"proofs":[{"label":"Incidents","href":"/api/v1/incidents"}]},{"id":"DEL-3","group":"Deliverables","requirement":"Periodic compliance and usage reports","capability":"On-demand and monitor-mode reports in Markdown/JSON/CSV/PDF with compliance mappings and recommendations.","how":"Reports can be generated per analysis or per scheduled monitor batch.","rules":[],"proofs":[{"label":"Analyses & reports","href":"/api/v1/analyses"}]}]}],"items":[{"id":"AIUM-1","group":"AI Usage Monitoring","requirement":"Tracks how AI features are used across workflows and integrations","capability":"Normalizes every AI usage event (board, workflow/automation, item, user, team, AI feature, prompt, output, metadata) into one schema across monday.com and other sources.","how":"monday and generic adapters map platform fields into the AIUsageEvent schema; the Workflows view groups activity by board and automation the same way monday organizes work.","rules":[],"proofs":[{"label":"Run monday-style sample","href":"/api/v1/demo/run-sample","method":"POST"},{"label":"Workflow event schema (analyze)","href":"/docs#/default/analyze_api_v1_analyze_post"}]},{"id":"AIUM-2","group":"AI Usage Monitoring","requirement":"Identifies unusual or risky usage patterns","capability":"Flags high-volume AI calls, oversized prompts/outputs, prompt-injection / policy-bypass language, and automation acting without human review.","how":"Deterministic detectors score each event; risky events become HIGH/CRITICAL findings surfaced as alerts.","rules":["AIU-VOL-001","AIU-GUARD-001","AIU-AUTO-001"],"proofs":[{"label":"Findings feed","href":"/api/v1/findings"}]},{"id":"DRD-1","group":"Data Risk Detection","requirement":"Detects potential exposure of sensitive or confidential data","capability":"Detects PII (email/phone/Luhn-validated card), special-category and confidential terms, secrets/credentials, and declared sensitive data classes inside prompts and outputs.","how":"Pattern + keyword + data-class detection runs on every event with no credentials required.","rules":["AIU-DATA-001","AIU-SEC-001"],"proofs":[{"label":"Run AICVS sample (data exposure)","href":"/api/v1/demo/run-aicvs-website-sample","method":"POST"}]},{"id":"DRD-2","group":"Data Risk Detection","requirement":"Flags unsafe data handling practices","capability":"Flags sensitive data leaving via external recipients/channels and high-impact automated actions that skip human review.","how":"Combines a sensitive-data signal with an external channel/recipient or an automated action lacking review/approval metadata.","rules":["AIU-SHARE-001","AIU-AUTO-001"],"proofs":[{"label":"Findings feed","href":"/api/v1/findings"}]},{"id":"PCA-1","group":"Policy & Compliance Analysis","requirement":"Identifies violations of internal AI and data policies","capability":"Matches event text against selectable policy packs and per-client custom keyword policies.","how":"Policy packs (Trust & Security, Legal & Privacy, DPO/Consultant, HR/Hiring) and client profiles drive the AIU-POL-001 detector.","rules":["AIU-POL-001"],"proofs":[{"label":"Policy packs","href":"/api/v1/policy-packs"}]},{"id":"PCA-2","group":"Policy & Compliance Analysis","requirement":"Maps risks to compliance requirements","capability":"Maps each finding to EU AI Act, GDPR, ISO 27001, ISO 42001, SOC 2, NIS2, DORA, HIPAA, and OWASP LLM Top 10 references (indicative).","how":"ARTICLE_MAP and OWASP_LLM_MAP attach control + OWASP references to findings and aggregate them on reports for Trust/Legal/Security.","rules":[],"proofs":[{"label":"Reviewer report (Markdown)","href":"/api/v1/analyses"}]},{"id":"PCA-3","group":"Policy & Compliance Analysis","requirement":"Identifies compliance gaps for auditor preparation","capability":"SOC 2 gap workbook maps AI usage findings and platform signals to assessable Trust Service Criteria with prioritized remediation (not certification).","how":"GET /api/v1/compliance-gaps and /api/v1/reports/soc2-gap-assessment.md roll up control-level gap/partial/strength status from stored evidence.","rules":[],"proofs":[{"label":"SOC 2 gap assessment API","href":"/api/v1/compliance-gaps?framework=soc2"},{"label":"Gap workbook (Markdown)","href":"/api/v1/reports/soc2-gap-assessment.md"}]},{"id":"PR-1","group":"Pattern Recognition","requirement":"Analyzes behavior across accounts to identify systemic risks","capability":"Rolls up findings by user, workflow, and board across all stored analyses to surface concentration of risk.","how":"The metrics summary and systemic_risks groupings expose where risk clusters across accounts and teams.","rules":[],"proofs":[{"label":"Metrics summary","href":"/api/v1/metrics/summary"}]},{"id":"PR-2","group":"Pattern Recognition","requirement":"Surfaces recurring issues across teams and use cases","capability":"Reports recurring user/workflow/board risk when the same subject trips multiple high-risk findings.","how":"Repeat HIGH/CRITICAL findings on one subject become a SystemicRisk entry shown in the Workflows view.","rules":[],"proofs":[{"label":"Metrics summary","href":"/api/v1/metrics/summary"}]},{"id":"RA-1","group":"Reporting & Alerts","requirement":"Generates structured reports for Trust, Legal, and Security teams","capability":"Produces Markdown, JSON, CSV, and PDF evidence reports with severity, compliance mappings, systemic risks, and recommendations.","how":"Each stored analysis renders downloadable reports keyed by analysis ID.","rules":[],"proofs":[{"label":"Reports & analyses","href":"/api/v1/analyses"}]},{"id":"RA-2","group":"Reporting & Alerts","requirement":"Sends alerts for high-risk scenarios","capability":"Surfaces HIGH/CRITICAL findings as structured alerts, converts them to incidents, and delivers to Slack (wired) / Jira / email (credentialed).","how":"alerts/dispatch posts structured alerts; high-risk findings convert into tracked incidents.","rules":[],"proofs":[{"label":"Alert dispatch API","href":"/docs#/default/dispatch_analysis_alerts_api_v1_alerts_dispatch_post"}]},{"id":"RA-3","group":"Reporting & Alerts","requirement":"Provides prioritized recommendations","capability":"Attaches a prioritized, category-specific recommendation to every finding and report.","how":"RECOMMENDATIONS maps each risk category to a concrete next action ranked by severity.","rules":[],"proofs":[{"label":"Findings feed","href":"/api/v1/findings"}]},{"id":"REQ-1","group":"Requirements","requirement":"No internal credentials required (initially based on logs and structured inputs)","capability":"Runs fully on uploaded JSON/CSV exports with zero platform credentials; live monday OAuth is optional.","how":"Upload or POST events; the deterministic engine needs no API tokens.","rules":[],"proofs":[{"label":"Upload endpoint","href":"/docs#/default/analyze_upload_api_v1_analyze_upload_post"}]},{"id":"REQ-2","group":"Requirements","requirement":"Access to usage data and workflows (via defined inputs)","capability":"Defined AIUsageEvent input plus adapters for monday, Jira, Asana, ServiceNow, Slack, Salesforce, Zendesk, and custom logs.","how":"Source registry normalizes each platform's export into the common schema.","rules":[],"proofs":[{"label":"Supported sources","href":"/api/v1/sources"}]},{"id":"REQ-3","group":"Requirements","requirement":"NLP capabilities for analyzing prompts and outputs","capability":"Deterministic prompt/output text analysis (pattern, keyword, context) plus an optional OpenAI/Anthropic LLM review layer.","how":"Baseline analysis is explainable and credential-free; the LLM layer adds advisory context when enabled.","rules":["AIU-DATA-001","AIU-GUARD-001","AIU-RISK-001"],"proofs":[{"label":"Analyze API","href":"/docs#/default/analyze_api_v1_analyze_post"}]},{"id":"REQ-4","group":"Requirements","requirement":"Risk classification and reporting logic","capability":"Severity scoring, status classification (PASS/CONDITIONAL/HIGH_RISK_REVIEW/CRITICAL_REVIEW), category counts, and evidence hashing.","how":"analyze_events computes a 0-100 score, status, and a tamper-evident evidence hash per batch.","rules":[],"proofs":[{"label":"Analyses","href":"/api/v1/analyses"}]},{"id":"DEL-1","group":"Deliverables","requirement":"Ongoing AI risk monitoring","capability":"Continuous inbox-folder monitor mode that analyzes new exports as they arrive.","how":"CLI `monitor` watches a folder and writes a report per export batch on an interval.","rules":[],"proofs":[{"label":"How to use (monitor mode)","href":"/api/v1/production-readiness"}]},{"id":"DEL-2","group":"Deliverables","requirement":"Alerts on high-risk activity","capability":"High/critical findings populate alerts and convert to incidents with owner and status tracking.","how":"Incident queue tracks operational follow-up from open to closed.","rules":[],"proofs":[{"label":"Incidents","href":"/api/v1/incidents"}]},{"id":"DEL-3","group":"Deliverables","requirement":"Periodic compliance and usage reports","capability":"On-demand and monitor-mode reports in Markdown/JSON/CSV/PDF with compliance mappings and recommendations.","how":"Reports can be generated per analysis or per scheduled monitor batch.","rules":[],"proofs":[{"label":"Analyses & reports","href":"/api/v1/analyses"}]}]}