Skip to content

Agent Operating Guide

Integration bridges

The Audit plugin's bridges to external GRC systems: bi-directional sync with Archer and ServiceNow, one-shot AuditBoard migration, and Workday user provisioning.

The bridge family connects a AssureSwarm tenant to the external GRC systems a program already runs on. Changes that flow into Canvas arrive as suggestions a human approves: a bridge never writes to your tenant unreviewed.

Skill What it does
/bridge-archer-sync Bi-directional sync with Archer: Canvas issue and remediation-task updates push out, Archer-owned changes return as suggestions.
/bridge-snow-sync The same bi-directional sync for ServiceNow.
/bridge-workday-provision Provision and deprovision Canvas users from Workday joins, transfers, and leaves.
/bridge-auditboard-migrate One-shot import of an AuditBoard tenant: workpapers, issues, controls, audits, remediation tasks.
/bridge-mapping-edit Interactive editor for a bridge’s field mapping; configure it once, then syncs are mapping-driven.
/bridge-conflict-resolve Analyze a same-field-both-sides conflict and propose a resolution (read-only; the sync applies it).
/bridge-sync-status Read-only operational view: sync log, conflict queue, and last pull/push time per bridge.

The two bi-directional syncs, Archer and ServiceNow, share one shape. You define the field mapping once with /bridge-mapping-edit; every sync afterward is mapping-driven and idempotent. When the same field changed on both sides since the last sync, the sync calls /bridge-conflict-resolve to propose a resolution (keep Canvas, keep external, merge, or surface to a person) rather than overwriting silently. /bridge-sync-status is the operational view over all of it: what synced, what conflicts are open, and when each bridge last succeeded. The one-shot AuditBoard migration and Workday provisioning reuse the same mapping-driven, validation-gated approach for their one-directional flows.