Skip to content

Agent Operating Guide

Audit plugin

The Audit plugin: a Claude Code / Cowork plugin of generic AssureSwarm operator primitives (item, workflow, schema, query, and document operations) plus the SOX fieldwork engine and integration bridges. What it is, how to install it, where to download it, and a page for every skill.

Audit plugin is the official Claude Code / Cowork plugin for AssureSwarm. It gives an AI agent a library of skills, slash-command capabilities, for operating a AssureSwarm tenant: creating and linking items, running and authoring workflows, editing the schema, querying data, attaching documents, running SOX control testing, and syncing with external GRC systems.

The plugin is primitives-first. Its core is a set of generic, domain-neutral operator skills that work on any AssureSwarm tenant regardless of what it tracks: audits, risks, controls, incidents, or something entirely different. Higher-level domain content (audit, SOX, regulatory, GRC methodology) lives in workflow templates you import into your tenant, not in the plugin, so the plugin stays small and reusable. See Workflows and the workflow gallery at assureswarm.com/workflows.

The skills are organized into four families. Every skill carries its family as a name prefix: the prefix is organizational only, not a limit on where the skill works.

  • Coach primitives: the universal operator primitives every domain reuses: create, update, link, and export items of any admin-configured type; add item types and fields; attach, build, execute, assign, monitor, and export workflows; design, export, and validate the schema; run read-only queries; upload and link documents; build dashboards and forms; the redaction-gated outbound edge (render/package, notify, redact); and the plugin’s own setup, support, and Q&A.
  • SOX engine: the script-backed SOX 404 fieldwork engine: plan a control area’s testing, run deterministic tick-and-tie procedures, and turn screenshot, video, live-web, or mixed-folder evidence into reviewably annotated workpapers.
  • Integration bridges: bi-directional sync and provisioning with external GRC systems: Archer, AuditBoard, ServiceNow, and Workday.
  • Audit methodology: the auto-loaded control-testing methodology reference and the granular workpaper annotator.

These build directly on the AssureSwarm MCP tools: every write goes through the same suggest_change review flow a human sees, so an agent using the plugin never mutates your tenant without approval.

Each skill has its own page with what it does, when to use it, its inputs, an example, and related skills:

The plugin installs into Claude Code (or a Cowork session) as a plugin bundle.

  1. Download it: audit-artist-plugin.zip. This is the plugin’s final, frozen build; new plugin work continues in the Swarm plugin family at assureplugin.com.
  2. Install it into your Claude Code environment as a plugin (unzip into your plugins directory, or use your client’s “install plugin from zip” flow).
  3. Connect the plugin to your tenant by running the setup skill: it detects your AssureSwarm MCP server and records which tenant to operate on. See Connect an agent for the MCP connection itself.

The plugin degrades gracefully when no AssureSwarm MCP server is present, so it is safe to install ahead of connecting a tenant.

Audit plugin is open source (MIT). The download above is the current release bundle; it is rebuilt from source whenever the plugin changes.