Auditober 2026

Auditober instructions

How to use your sandbox, from the first sign-in to submitting your entry. Each task has the steps in text and a short clip of the real screen.

Your sandbox has two parts. core.assureswarm.com is the AssureSwarm app, loaded with your team's copy of the Bluth Company audit data. demo.assureswarm.com is the Swarm agent, an AI assistant that works inside that app for you. Everything is mock data, so nothing from your organization goes in.

1. Start here

Set your password and sign in

  1. Open the invitation email from AssureSwarm and select the set-password link.
  2. Choose a password, type it again to confirm, and submit. You will see Your password is set.
  3. Go to core.assureswarm.com and sign in with your email address and the new password.

The link works for 72 hours after we send it, and only once. If it has expired, email support@assureswarm.com from the address you signed up with and we will send a new one.

Setting a password from the invitation link. Illustration

Your team

Everyone who signed up from the same company is on one team, and every member is an admin of it. You can see and change everything your teammates build. People who signed up with a personal email address each get a team of their own. To see who is on your team, click the Admin icon (the last one in the top bar), then User Permissions.

Your team is sealed off from every other team. Other entrants cannot see your work until you submit it, and then they see it without your name.

Admin, then User Permissions: everyone on your team.

Sign in to the Swarm agent

  1. Go to demo.assureswarm.com and choose Sign in with AssureSwarm.
  2. The agent sends you to core.assureswarm.com. Sign in there if you are not already, then check the Authorization Request and choose Authorize Access.
  3. You land back in the chat, signed in as yourself. The agent can only see and change what you can.
Signing in to the agent through core.assureswarm.com.

Your first ten minutes

  1. In the app, click the Dashboards icon (the first one in the top bar) and then Executive to see the Bluth Company's audit program at a glance.
  2. Open any risk from the Risks dashboard and look at the controls, processes and workflows linked to it.
  3. In the agent, type / and pick workflow-scan to see the workflow steps waiting on you.
  4. Ask the agent to do one of those steps. It drafts the result as a suggestion.
  5. Back in the app, open the Activity Hub with the bee logo, review the agent's draft and approve it, then approve the step.

That is the loop every entry builds on. The agent does the work and a person approves it.

Asking the agent what is waiting on you. Illustration

2. Find your way around

The app at core.assureswarm.com

The icons across the top take you to Dashboards, one page for each kind of record (risks, controls, issues, policies and the rest), My Items, Templates, Time and Admin. Hover over an icon to see its name. The bee logo at the top left opens the Activity Hub, where the agent's suggestions wait for you. Every record has its own page, and you can share any page's link with your team.

A tour of the top bar and the Activity Hub.

The agent at demo.assureswarm.com

  • Type a request in plain English, or type / to pick a skill such as item-create, workflow-build or query-data.
  • New chat clears the conversation. Feedback sends us an issue or an idea (see Report an issue or suggest an improvement).
  • The panel on the right shows the app (Canvas), a report or a dashboard next to the chat, so you can watch changes land.
  • The user menu at the top right has Dashboards (the dashboards you build with the agent), Submissions and Sign Out.

Conversations with the agent are recorded so we can improve the product, and the AssureSwarm team can read them. The chat shows a notice when recording is on.

The chat, the skills menu and the side panel.

My Work

My Work lists the workflow steps assigned to you and the ones ready to start. It is the first place to look when you come back to the sandbox.

Filtering My Work to the steps ready for you.

A record's page

Open any risk, control, issue or policy to see its fields, its linked records, its documents and the workflows that run on it. Click a title or a field to edit it in place.

A control's page: its workflows, all its fields and its linked items.

The Bluth Company data

Every team starts with the same fictional company, so entries can be compared fairly. Your copy holds 744 records: 200 risks, 200 controls, 129 compliance requirements, 53 processes, 47 policies, 28 issues, 18 remediations, 20 financial statement line items, 16 people, 14 systems, 10 models and 9 audits. They are joined by 2,223 links and worked on by 50 workflow templates with 236 runs in progress or complete.

Change anything you like. Your edits stay in your team.

The Bluth Company registers.

3. How AssureSwarm works

Eight ideas cover the whole product. Each one links to the full page on docs.assureswarm.com.

Items and item types

Every record is an item: a risk, a control, an issue, a policy, an audit. Each item type has its own fields, set by the team's admins. Because you are an admin, you can add a field or a new item type.

Read more about items

Item types and their fields.

Workflows

A workflow is a piece of audit work written down as steps, so agents and auditors run it the same way every time. You define it once as a template, then start a run of it on an item, such as a walkthrough on a process. Each step has instructions, a result that records what was done, and approvers who sign it off. An approved step locks.

A workflow template and its steps in the designer.

Forms

A step can send a form to someone who is not running the workflow, such as a control owner who has to answer three questions. Use a form only for information you cannot get any other way. The person running the step writes their work in the step result, and sign-off is the step's approval.

A step's form and the person it was sent to.

The Universe: your audit knowledge graph

The Universe dashboard draws every item and link as one graph. Pick an item to focus on it and see what sits one or two links away, such as every control, workflow and issue connected to one process.

The Universe graph of every record and link.

Dashboards

The app has 19 built-in dashboards, all filled from your team's data: Universe, Org Chart, Executive, Operational, My Work, AI Activity, Capacity Monitoring, Workflow Runs, Risks, Third-Party Risk, Policy Lifecycle, Policy Exceptions, Audit Plan, Model Inventory, Issues and Remediations, RCM, Compliance Requirements, SOX Program and Workflow Coverage.

To build a dashboard of your own, ask the agent, for example Build a dashboard of open issues by severity with a table. It appears in the agent under the user menu, then Dashboards.

Finding the Executive dashboard, then the Risks dashboard.

Suggestions and review

Agents never change your records directly. Everything an agent wants to do arrives as a suggestion in the Activity Hub, which opens from the bee logo at the top left. Click a suggestion to see each proposed change marked on the page, then approve or reject each change with the check or the X, or all of them at once. Nothing is saved until you do. The AI Activity dashboard shows every suggestion and what happened to it.

Finding a suggestion in the Activity Hub and reviewing its change on the record.

MCP

The Model Context Protocol (MCP) is the standard way an AI agent connects to an outside system. AssureSwarm is built on it. The Swarm agent uses MCP to work in your sandbox, and you can connect Claude, ChatGPT, Codex or Gemini the same way. Every agent has only the access of the person who signed it in, and its changes go through the same suggestion review.

Read the MCP reference

An agent reading your team's data through the MCP tools. Illustration

4. Do the work

You can do each task by hand in the app or ask the agent to do it. Switch between the two with the buttons on each task. When the agent does the work, every change comes back as a suggestion in the Activity Hub. Open it with the bee logo at the top left, then approve or reject the suggestion (see Suggestions and review).

Create or change a record

By hand

  1. In the top bar, click the icon for the kind of record, for example Risks. Hover over an icon to see its name.
  2. Click New Risk at the top right of the list.
  3. Fill in the fields on the Create Risk page and click Create.

To change a record, open it. Click the title to rename it, or click the description to edit it. Every other field is in the Details card on the right: click a field, change it, and click Save changes. Click All n fields to see the ones that are hidden.

Creating a risk from the Risks list.

With the agent

  1. Type /, pick item-create, and describe the record, for example a new risk that vendor invoices are paid twice.
  2. The agent asks for any required field it is missing, then sends a suggestion.
  3. The Activity Hub opens in the Canvas panel beside the chat, with the suggestion and a preview of the new record marked New risk.
  4. Approve it with the check, or reject it with the X.

To change a record, use item-update the same way. The fields it wants to change are marked Changed, and you can approve or reject each one on its own.

The agent drafts a risk; approving it in the Canvas panel.

Build a workflow template

By hand

  1. Click the Templates icon in the top bar, then Create Template.
  2. Give the workflow a name and a description, and choose the item type it runs on, for example Process.
  3. Click Add Step once for each step.
  4. Click a step to open Configure Step. Name it, write its Instructions, and click Save Changes.
  5. Click Save Template.
Adding and configuring steps in the template designer.

With the agent

  1. Pick workflow-build and describe the audit work, for example a vendor master data change review for the Accounts Payable process.
  2. The agent drafts the steps and their instructions. Ask for changes until it reads the way you would run the work.
  3. Open the suggestion from the Activity Hub. Each step is marked New step. Approve the template, or reject the steps you do not want.
workflow-build drafts a template and sends it for approval. Illustration

Strong workflows keep human sign-off to the points where it adds judgment. Add a form to a step only when someone outside the workflow has to supply information.

Run a workflow

By hand

  1. Open the record. In the Workflows card, click Add Workflow, tick the template, and confirm.
  2. Click View on the new workflow, then click a step to open it.
  3. Choose Add, then Approver. Pick who signs off and at which level, and click Save approvers. Add a due date the same way.
  4. On the Step Result card, click Edit, write what you did and found, and click Save.
  5. The approver clicks Approve. When every required approver has approved, the step locks. Remove Approval unlocks it.
Opening a record's workflow, writing a step result, approving the step.

With the agent

  1. Start a run with workflow-attach, for example run the walkthrough template on the Accounts Payable process.
  2. Set who signs off with workflow-assign.
  3. Ask the agent to do a step with workflow-execute. It reads the step, the linked records and their documents, and drafts the step result.
  4. Open the suggestion. The draft result is marked Changed. Edit it with the pencil if it needs work, then approve it.
  5. Approve the step yourself with Approve. The agent drafts the work, and only a person can sign it off.

autopilot drafts every step that is ready for you in one pass and reports what it drafted and what it still needs from you.

workflow-execute drafts a step result for your review. Illustration

Attach evidence

By hand

  1. Open the step. In Supporting Documents, click Add. If the section is missing, choose Add, then Supporting document, at the top of the step.
  2. Choose Upload File, or drag a file onto the section.
  3. To point to an online document instead, choose Link External URL, paste a OneDrive, SharePoint or Google Drive link, and click Link.

On a record, upload a file into any document field. Links to online documents go on steps only.

Linking an online document to a step's Supporting Documents.

With the agent

  1. Attach the file in the chat and pick document-upload, naming the step or record it belongs to.
  2. For an online document, pick document-link and paste the link.
  3. Approve the suggestion from the Activity Hub.

The agent reads uploaded documents when it drafts a step, so attach the evidence before you ask it to do the step.

document-link proposes linking an online document to a step. Illustration

Use mock files only. Nothing from your organization belongs in the sandbox.

Find what you need

By hand

  • Every list, such as Risks, has a search box, a Filter button for that record type's fields, and a sort by due date or creation date.
  • Click Select to pick records and download them.
  • On a dashboard, open Filter to narrow its scope and reporting range.

There is no search across all record types. Start from the list or dashboard closest to your question.

Searching and filtering the Risks list.

With the agent

Pick query-data and ask across any record types, for example how many high or critical residual risks do we have, by category? or list every overdue remediation with its owner. The agent answers from your team's records and can export the results. Questions only read data, so there is nothing to approve.

A question answered from the Bluth data. Illustration

5. Bring your own agent

You can connect the AI tool you already use to your sandbox. Every client uses the same address and signs you in through core.assureswarm.com.

MCP URL https://core.assureswarm.com/mcp

Claude Desktop (and claude.ai)

  1. Open Settings, then Connectors, and choose Add custom connector.
  2. Paste the MCP URL and add the connector.
  3. Sign in to AssureSwarm in the window Claude opens and approve access.
  4. In a new chat, turn the connector on and ask what is in my AssureSwarm workspace?

On a Claude Team or Enterprise plan, your workspace owner may have to allow custom connectors first.

Adding AssureSwarm as a custom connector in Claude Desktop. Illustration

ChatGPT

  1. In ChatGPT on the web, turn on Developer mode in the Apps settings.
  2. Choose Create, paste the MCP URL and pick OAuth.
  3. Choose Scan Tools, sign in to AssureSwarm and approve access, then create the app.
  4. Start a new chat and select the app from the tools menu.

In a company ChatGPT workspace, only an owner or admin can turn on Developer mode.

Creating an AssureSwarm app in ChatGPT. Illustration

Copilot

Microsoft Copilot Studio (you need maker rights in your organization's Copilot Studio):

  1. In your agent, open Tools, choose Add a tool, then New tool and Model Context Protocol.
  2. Enter a server name, paste the MCP URL as the Server URL, and choose OAuth 2.0 with dynamic discovery.
  3. Create the connection, sign in to AssureSwarm and choose Authorize Access, then add the tool to your agent and test it.

GitHub Copilot in VS Code: open the Command Palette, run MCP: Open User Configuration, and add a server under servers with the MCP URL. Start it and sign in when asked. The AssureSwarm plugin can also set this up for you.

Copilot Studio options that need a manually registered OAuth client are not available on the Auditober sandbox. Use dynamic discovery.

Adding AssureSwarm as a Model Context Protocol tool in Copilot Studio. Illustration

Claude Code, Codex CLI and Gemini CLI

Claude Code: add the server, then run /mcp in a new session, select it and choose Authenticate.

claude mcp add --transport http assureswarm https://core.assureswarm.com/mcp

Codex CLI: add the server, then sign in.

codex mcp add assureswarm --url https://core.assureswarm.com/mcp
codex mcp login assureswarm

Gemini CLI: add the server, then run /mcp auth assureswarm inside Gemini CLI.

gemini mcp add --transport http assureswarm https://core.assureswarm.com/mcp

If you already have a server called assureswarm pointing somewhere else, pick another name.

Connecting Claude Code and signing in. Illustration

The AssureSwarm plugin

The plugin gives Claude, Codex and GitHub Copilot the same audit skills the Swarm agent has. Download it from assureswarm.com/plugins, extract it, and run node setup.mjs (Node.js 20 or later). Enter the MCP URL above when it asks. Then start a new session and run coach-setup.

If the connection fails

  • It keeps asking you to sign in: remove the connector, add it again, and finish the sign-in in the same browser.
  • It connects but sees nothing: check you signed in with your Auditober email address, not another AssureSwarm account.
  • A change you approved did not appear: open the suggestion from the Activity Hub and check that you approved every change in it, not only some.

Still stuck? Report an issue and name the tool you were connecting.

6. Manage your team

Everyone on an Auditober team is an admin, so any of you can do the tasks below. Click the Admin icon, the last one in the top bar, to open User Permissions, Item Types and Data Management.

Add a teammate

  1. Open Admin, then User Permissions, and click Create User.
  2. Enter their Email and Full Name, and choose a Role: User or Admin.
  3. Leave Password blank and click Create User. An Invite link appears.
  4. Copy the setup link and send it to them yourself. AssureSwarm does not email it. The link works once and expires in 72 hours.

An email address can belong to only one team in the whole sandbox. If you see This email address is not available, that person already has an account on another team.

Change what a teammate can do

Select the person in User Permissions and open Page Access.

  • Turn Admin on or off. An admin can see and change everything.
  • For someone who is not an admin, set each record type to No access, View public, View all or Edit all, and switch Dashboards, Templates, Time Keeping and My Items on or off. Grant Default Pages gives the usual set.
  • If someone lost their invitation or password, choose Reset password link and send them the new link. It works once and expires in 24 hours.

Remove a teammate

Select the person, turn Admin off on Page Access, then choose Delete User and confirm Deactivate User. Their account is deactivated, not erased: creating a user with the same email later brings it back. You cannot deactivate yourself or remove your own admin access.

Add a record type or a field

  • A new record type: open Admin, then Item Types, and click Create Item Type. Give it a name, a plural name and a slug (the slug cannot be changed later), then click Create Item Type.
  • A new field: click Configure on a record type, then Add Field. Choose a field type (text, number, date, select, user, document and more), and whether it is required, shown in lists, filterable or searchable.
  • Drag a record type's handle to change its place in the top bar.

Fields marked System or Dashboard feed the built-in dashboards. You can rename them, but you cannot delete them or change their type.

Export, import and reset data

Open Admin, then Data Management.

  • Export Data saves the parts you tick (users, record types, records, workflow templates, links and more) as a JSON file. Passwords are never included.
  • Import Data loads a JSON file in the same format. Record types and lists that already exist are updated. Records are always added as new ones, so importing the same records twice gives you two copies.
  • Reset Data deletes every record, workflow run, time entry, suggestion and document in your team. It keeps record types, lists, dashboards, templates and users. It cannot be undone, and it affects your whole team, so agree it with your teammates first.

Your own settings

The menu under your initials, top right, has Settings (your name, language, and light or dark appearance) and AI Agent Setup (your MCP URL, setup steps for Claude, ChatGPT, Gemini and Copilot, and personal tokens for tools that cannot sign in with OAuth). A personal token is shown once and expires after 30 days. Treat it like a password.

7. Build and submit your entry

Choose what to build

You can enter a workflow, an agent skill, a plugin or a dashboard, in one of four categories: risk assessment, testing, operational audit, or most creative.

  • A workflow: build the template in the sandbox and show it running on the Bluth data.
  • A dashboard: ask the agent to build it, then refine it in the chat.
  • An agent skill or a plugin: write it for your own agent connected over MCP (see Bring your own agent), and show its result in the sandbox as a workflow run or a dashboard.

Start from our plugin and data

Two downloads give you something to change instead of a blank page.

  • The AssureSwarm plugin: the skills the Swarm agent uses, as editable files. Download the Audit plugin for audit work, or the Swarm plugin for the general operator skills. Each ZIP sets itself up for Claude, Codex and GitHub Copilot (see The AssureSwarm plugin). Copy a skill, change it, and run your version from your own agent. The plugins page lists every variant.
  • The Bluth Company data: the same data set every team starts with, as bluth-company-auditober.json (3.4 MB). You can import an edited copy from Admin, then Data Management. Records are always added as new ones, so first remove from the file any records your team already has.

Submit your entry

  1. A dashboard: open it from the agent's user menu, then Dashboards, and choose Submit to Auditober.
  2. A workflow: open Submissions from the agent's user menu, choose Submit a workflow, search for it, and pick it from the list.
  3. Give the entry a Title, choose its Category, write a short Write-up of what it does and how to use it, and choose Submit workflow.

Submitting freezes a copy, so later edits in your sandbox do not change what the judges see. Your team appears under an anonymous name, such as Amber Heron-42. You can withdraw or resubmit from Submissions until entries close on October 31.

Submitting a workflow to Auditober. Illustration

8. Get help and give feedback

Report an issue or suggest an improvement

  1. In the agent, choose Feedback at the top of the chat.
  2. Pick Report an issue or Suggest an improvement. The agent drafts a title and description from your conversation. Edit them freely.
  3. For an issue, set the severity. A screenshot of your screen is attached automatically; remove it or replace it if you want. Then choose Submit issue.

Say what you were trying to do, what you expected, and what happened. If your team's AI allowance has run out, you can still write and send feedback by hand.

Sending an issue report from the agent.

Your team's AI allowance

Each team shares a $50 AI allowance for the whole of Auditober, with a daily limit on top. The top of the agent shows what your team has used today, for example Team budget $0.00 / $25.00 today. The allowance covers the Swarm agent's chats, feedback drafting and document reading, and it does not reset each month. When it runs out, the agent tells you and stops making AI calls. The app, the dashboards and any agent you connect yourself keep working.