Audit plugin
The auditor build: ten internal-audit modules on the operator primitives, each paired with a workflow.
Workflows
Select a workflow from the library, then review its required roles, records and systems in your company instance. The plugin executes your installed tenant copy and preserves your customizations until you review an update.
- ITGC Change & Provisioning Testing
- Substantive Testing & Data Analytics
- Fraud Risk Assessment & JE Testing
- Continuous Monitoring & Agent Evaluation
Connecting the plugin uses your existing tenant permissions. Your company supplies its own system connections and approval assignments.
Skills
coach-Operator primitives30 skills
/coach-artifact-install
Use when the user asks to install, preview, or deploy a live artifact (HTML template plus manifest) shipped with the Audit plugin. Pre-flight validates the customer's Canvas schema has the item types and fields the artifact expects; installs to a local html file under the workspace artifacts folder for preview, or to Canvas as a live-artifact page via suggest_change for production. Templates ship immutable — this skill produces a customer-specific instance against their MCP connection.
/coach-ask
Use when the user asks how something in CoworkCanvas works or has a natural-language question about the platform; when they want a step-by-step numbered walkthrough of a task via --howto, such as add a custom field, create an item type, set up an OAuth client, import bulk data, or configure MCP; when they ask what a platform term means via --define, covering vocabulary like slug, isCore, isFilterable, tsvector, suggest_change, item type, custom list, MCP, Workflow, Step, FormAssignment, authority_source, cites_authority_sources, obligation, the shared-core item types, and deprecated pre-refactor terms; or when they paste an error message or describe a symptom that needs diagnosing via --diagnose. Grounded in the bundled docs snapshot, every answer cites the specific doc file and section, and works offline. Questions of the form show me the X dashboard or where do I see X belong to coach-dashboard-link; this skill explains how dashboards work and how to create one.
/coach-autopilot
Use when the user asks to run, or dry-run, an autopilot pass over their assigned-step queue — a headless, scheduled driver built to be fired by a schedule (Claude Cowork / Claude Code / ChatGPT Codex; /coach-setup registers it), running as the user. Scans via coach-workflow-scan, executes every ready step via coach-workflow-execute --headless (each drafts a suggestion for the user to review), posts a one-time ALL-UPPERCASE INPUT NEEDED placeholder suggestion on steps missing an input, re-checks those steps each run and drafts for real once the input arrives, skips already-handled steps, and emits one digest of what it drafted, what input it requested, what needs you, what is blocked, what awaits approval, and any rubber-stamp-approved placeholders to reopen. Never commits, never approves, never re-runs an already-handled step.
/coach-bulk-user-change
Use when the user asks to remove, reassign, or offboard a departing or transferring person across Canvas item assignments in bulk — or, with --report, to compile the handoff document for a person going on leave or transferring: every open work item they own with its state, next action, stakeholders, and outstanding workflow Steps. Change actions cover every audit, issue, risk, control, process, policy, and workflow Step the person is attached to, in one operation instead of clicking through each item, and always propose via suggest_change — admins approve the batch in Canvas. The report is read-only and shareable after redaction. Works on any instance with the shared core starter pack; run /coach-starter-pack first if pre-flight fails.
/coach-dashboard-create
Use whenever the user asks to create, build, design, author, or set up a dashboard, report view, or data visualization page. Gathers the dashboard name, visibility, the underlying GraphQL query that feeds the widgets, and the widget definitions (stat-row, table, chart, filter-bar), then submits a single suggest_change suggestion against the dashboard target that creates the dashboard.
/coach-dashboard-link
Use FIRST whenever the user says show me, let me see, where do I see, take me to, or open something in the product; asks to be sent a link to a dashboard with or without filters ('show me finance processes with no controls', 'link me to the RCM for the Q3 audit, pending only', 'everything within two hops of the Order-to-Cash process'); asks which dashboards exist; or asks a question a system dashboard answers (overdue issues, stuck workflows, owner workload, SOX status, audit coverage, AI suggestion outcomes, process coverage, what is connected to an item) and may want the number as well as the view. Resolves which dashboards this workspace surfaces with dashboardTypes, picks the right one from the 17-dashboard catalog, composes the canonical link or deep link (Processes, RCM, Universe full or focus mode), and when the ask exceeds the dashboard answers it with query_data. Read-only.
/coach-document-upload
Use when the user asks to upload, attach, or add a file, document, evidence, or supporting material to a workflow step; to link or reference an external document URL on a step — a Google Doc, SharePoint file, Confluence page, OneDrive link, or any public web link; or to attach, archive, or file a document against an ITEM — a control, policy, authority_source, or audit — rather than a specific step. Also use for uploading straight into an item's DOCUMENT field, and for populating a form file field with the returned document id.
/coach-export-package
Use when the user asks to export, download, archive, snapshot, or bundle Canvas content — one item with all its workflows and data, a curated set, or a full tenant. The plugin's single export entry point. Redacted modes run the /coach-redact redaction pass before anything is written for sharing — internal review notes and coaching comments never leave Canvas without explicit user confirmation; raw mode is the verbatim local archive of a single item (no redaction, local archival only). Covers the shared core item types plus attached Workflows, Steps, and StepDocuments. Run /coach-starter-pack first if pre-flight fails.
/coach-form-create
Use when the user asks to create, add, build, or design a workflow-step form for missing inputs from someone who is not executing the workflow or step. Executor work belongs in step results. Validates field definitions and proposes the schema through suggest_change; filling an existing form is coach-form-fill.
/coach-form-fill
Use whenever the user asks to populate, pre-fill, fill out, draft, or submit values for an existing step form. Proposes values via the submit_form action so the assignee sees the AI-suggested fill on the form page and can edit then submit in one click. Never use action update with form.values for fills — that lands the preview in the schema-diff UI on the step viewer instead of the form page.
/coach-item-create
Use whenever the user asks to create, add, draft, or open a new item of a known type (e.g., audit, risk, control, issue, policy, process). Works for any admin-configured item type: reads the type's schema via get_schema, gathers required fields interactively if not supplied, validates values against field definitions, and submits a single suggest_change action create suggestion for human approval.
/coach-item-update
Use whenever the user asks to update, change, edit, set, rename, correct, or archive an existing item (e.g., change a risk's owner, move the audit to fieldwork, archive a retired control). Works on any admin-configured item type: resolves the item by id or by type plus title search, shows the current values of the targeted fields, validates new values against the field definitions from get_schema, and submits a single suggest_change action update suggestion for human approval.
/coach-items-link
Use whenever the user asks to link, relate, connect, or tie one item to another (an audit to a risk, an issue to a control) — or to unlink one. Resolves each side by id or title, validates the kind (parent, child, sibling, related), and submits one itemrelationship suggestion via suggest_change for approval; --unlink mirrors the flow with a delete.
/coach-notify
Use whenever the user asks to notify, nudge, remind, or email a stakeholder about a Canvas item or Step, or to build a distribution list for a report, attestation, or committee. The generic outbound-comms primitive: dl mode assembles a deduplicated recipient roster from Canvas fields plus Workday/Outlook directory lookups (named sets like board or audit-committee, or explicit role lists); draft mode composes the stakeholder email with the Canvas link and due date. Every draft passes the /coach-redact redaction pass and lands as a DRAFT — Gmail/Outlook create_draft or a clipboard file — never auto-sent; the user hits send. Needs the shared core starter pack (run /coach-starter-pack first if pre-flight fails).
/coach-query-data
Execute a read-only GraphQL query against the Canvas tenant via the query_data MCP tool. Translates a natural-language data request into a valid GraphQL query against the platform's queryReference catalog, runs it, and presents the results in a clean format. Handles pagination, full-text search, structured filters, and csv/jsonl export for large results. Use whenever the user asks to find, list, search, count, look up, or export items, workflows, steps, users, or any other queryable resource in the tenant. If the user says show me, where do I see, or take me to, and a system dashboard covers the ask, coach-dashboard-link goes first; use this skill for the data itself or when no dashboard fits. Any ask that walks two or more links in one go — an item to its workflows, their steps, the items linked to those steps, the templates those items use, the runs of those templates — is a graph traversal: run it as ONE universeFocus path-mode query, never a chain of per-item reads.
/coach-redact
Use when the user asks to redact, scrub, or sanitize a staged directory of outbound content before export — the standalone entry point for ad-hoc redaction passes, and the plugin's single redaction engine: every skill that produces shareable output runs this same pass inline before anything leaves the workspace. Deterministic internal-only patterns are auto-removed, ambiguous ones surfaced for user confirmation, and a redact report written. Build-list rows 7, 30.
/coach-render-package
Use when an assembled document package leaves Canvas — board decks, regulator attestations, 302/906 certification packages, audit reports. Renders markdown to docx+pdf via pandoc, hard-gates through the /coach-redact redaction pass (halts on needs_user), packages the cleared artifacts, and hands distribution to /coach-notify. --cite binds claims to live Canvas records. Section composition lives in the covering assureswarm.com/workflows workflows.
/coach-schema-design
Use when the user asks to design, plan, or draft a Canvas schema — figuring out what item types and fields to set up for their domain; to add fields to an existing item type; to add a single new item type to an existing schema; to build the options for a SELECT or MULTISELECT field — an enum-style option list such as severity, status, frequency, regulators, regions, or audit-phase; or to export, back up, dump, or diff the current tenant's schema, or migrate it to another tenant. Five modes on one skill: the full design interview by default, plus --add-field, --add-type, --options, and --export for incremental changes.
/coach-schema-validate
Use when the user asks to validate, lint, or check a schema JSON file before pasting it into the Bulk Import admin page. Lints against the platform's bulk-import format — catching missing data wrapper, slug collisions, invalid field types (including the retired RELATION / RELATIONS), missing required keys, leftover relatedItemTypeSlug keys, and search-flag combinations rejected at import — and reports every issue with file path and field path.
/coach-security-report
Use when the user wants to report a security incident or vulnerability to CoworkCanvas (the vendor's security desk). Captures SOC 2 / ISO 27001 fields (detected_at, severity + rationale, affected systems/data, evidence), runs the /coach-redact redaction pass, then drafts via Gmail create_draft — drafts only, the user sends. Non-security helpdesk → /coach-ticket; to log the incident in your own tenant, create an issue item.
/coach-setup
Use when the user asks to set up, connect, configure, or initialize the Audit plugin in a workspace — or, with --verify, to verify, check, or confirm the tenant is set up properly before launch. Setup is one-time per workspace, idempotent and safe to re-run to refresh the schema snapshot or manage the autopilot schedule: detects available Canvas MCP servers, asks which company instance is theirs, probes the schema, writes .coworkcanvas/config.json plus a schema snapshot, and offers to register the recurring /coach-autopilot schedule. Verify runs the pre-launch readiness checklist and reports every gap with a specific remediation. Every other skill across the coach/sox/audit prefixes reads the config this writes.
/coach-starter-pack
Use when the user asks to apply, install, or bootstrap the starter pack — the canonical 7-item pack shared by every *canvas plugin (auditcanvas, soxcanvas, grccanvas, regcanvas): audit, issue, risk, control, process, policy, and authority_source item types. Optionally overlay audit, sox, reg, grc, or generic domain-specific seed data (sample authority_source items, regulator vocabularies). Produces a bulk-import JSON the admin pastes into the tenant's Bulk Import admin page; idempotent — re-running diffs the schema and emits only the delta.
/coach-ticket
Use when the user asks to open, file, or raise a support ticket with CoworkCanvas support because something is broken or blocking work; to reply to, follow up on, or update an existing support thread in Gmail; to check, list, or review the status of their support tickets and see which threads are waiting on them; or to send product feedback, a feature request, or an improvement idea for CoworkCanvas.
/coach-tour
Use when the user asks for a tour, orientation, or introduction to CoworkCanvas. Role-tailored: names the 3 skills to learn first, walks through the 7 shared-core item types (audit, issue, risk, control, process, policy, authority_source), and points to the right sibling plugins for the user's role; the onboarding checklist artifact tracks progress through the tour.
/coach-workflow-assign
Use whenever the user asks to assign, schedule, set deadlines, or pick approvers for the steps of a workflow. Sets approvers and due dates on a workflow instance via suggest_change against the step target — walking the steps, resolving users by name or email to user ids, and submitting one update suggestion per step that sets the approvers array and dueDate field.
/coach-workflow-attach
Use whenever the user asks to attach, instantiate, apply, or run a workflow on an item (e.g., attach the standard fieldwork workflow to this audit). Instantiates the workflow under the parent item via suggest_change against the workflow target — resolving the parent by id or title, picking a workflow template by name from the available templates, and submitting a single suggestion that creates the instance with its steps auto-generated from the template.
/coach-workflow-build
Use whenever the user wants to author a workflow's step nodes and edges from scratch — either a one-off workflow directly under a single item, or, with --as-template, a reusable workflow template, blueprint, or pattern for the tenant's template catalog. One suggest_change per call: the workflow target (itemId plus diagramNodes and diagramEdges) for an instance, or the workflowtemplate target (name, itemTypeId, nodes, edges) for a template. Distinct from coach-workflow-attach, which instantiates an existing template rather than authoring one.
/coach-workflow-execute
Execute a workflow step on the user's behalf. Reads the step via get_step_context, computes its direct upstream steps from the workflow's diagram edges, refuses to proceed until every upstream step is COMPLETED, performs the work the step's instructions describe, and submits the result via suggest_change for human approval. Use whenever the user asks to execute, run, work on, complete, or do a specific workflow step.
/coach-workflow-export
Use whenever the user asks to export, download, archive, snapshot, or bundle a workflow's data. Gathers the complete data of a workflow instance — every step's result, every form's submitted values, every uploaded or linked document — into a local directory: walks the workflow via query_data, downloads attached documents via download_document, and writes a structured local package the operator can archive or share. Read-only; never mutates the workflow.
/coach-workflow-scan
Use when the user asks what to work on, to triage a queue, as the scan phase of an autopilot run — or to check progress across a portfolio or cycle, find stalled or overdue work, see what is at risk, or name who to nudge. Read-only in both directions. Mine mode classifies the current user's assigned steps into four doer-states plus an awaiting-my-approval line; sweep mode is the lead/PMO view over every owner's steps across one workflow, an item's workflows, or a whole item-type portfolio, bucketing overdue, due-soon, stalled, awaiting-reviewer, and unblocked steps with a nudge target for each and an optional critical path. Never mutates; pairs with coach-autopilot (which acts on the ready ones) and coach-notify (which sends the nudges).
audit-Audit modules11 skills
/audit-continuous
Use when an auditor wants to run the continuous auditing and agent-evaluation capstone — define KRI thresholds and queries, build and approve the monitoring dashboard, run the recurring monitoring cycle and triage breaches, then sample and grade agent-drafted work from across the course and raise every agent-quality finding as an owned issue. Continuous Auditing, Monitoring & Agent Evaluations is module 10 (the capstone) of the Audit plugin audit course; runs on the canonical Studio schema and attaches the tenant’s Continuous Monitoring & Agent Evaluation workflow. Every write is a human-approved suggestion.
/audit-fraud-je
Use when an auditor wants to assess fraud risk and test journal entries for anomalies on the AssureSwarm platform — cover the fraud triangle and management override, map anti-fraud controls to the risks, profile and flag the journal-entry population, draw a reproducible sample, test the selected entries, and raise unsupported anomalies as issues. Module 7 of the Audit plugin audit course; runs on the canonical Studio schema and attaches the Fraud Risk Assessment & JE Testing template. Every write is a human-approved suggestion.
/audit-itgc
Use when an auditor wants to test IT general controls for change management and access provisioning on the AssureSwarm platform — validate the ticket populations, draw reproducible samples, test each ticket against the control's attributes, and conclude on design and operating effectiveness. Module 4 of the Audit plugin audit course, ITGC Testing: Change Management & Access Provisioning; runs on the canonical Studio schema and selects a pinned ITGC Change & Provisioning Testing release from Workflow Library. Every item, field, link, and workflow write is a human-approved suggestion.
/audit-narratives
Use when an auditor wants to document how a process actually runs — parse a narrative or interview transcript into steps, actors, systems, and control points, render the flowchart, reconcile control points against linked controls and systems, and raise every design deviation found in the walkthrough as an issue. Process Narratives & Flowcharting is module 2 of the Audit plugin audit course; runs on the canonical Studio schema and attaches the Process Narrative & Walkthrough workflow. Every item, field, link, and workflow write is a human-approved suggestion.
/audit-planning
Use when an auditor wants to plan an audit and assess risk on the AssureSwarm platform — open the engagement, score the audit universe (processes and financial statement line items), build the engagement risk and control matrix, record the scope rationale, and render the planning memo. Module 1 of the Audit plugin audit course; runs on the canonical Studio schema and attaches the Audit Planning & Scoping workflow. Every item, field, link, and workflow write is a human-approved suggestion.
/audit-remediation
Use when an auditor needs to drive open issues to closure — create the remediation actions issues need, attach delivery workflows, assign owners and dates, sweep for overdue and slipping actions, file closure evidence, and record control retest results on the AssureSwarm platform. Module 9 of the Audit plugin audit course: Issue Remediation. Runs on the canonical Studio schema and attaches the Remediation Delivery & Validation workflow. Every item, field, link, and workflow write is a human-approved suggestion.
/audit-reporting
Use when an auditor wants to write up findings, grade them against the CCCER rubric, grade severity and SOX deficiency, collect management responses, and issue the audit report — attaches Audit Fieldwork, Findings & Reporting on the audit and Issue Triage & Disposition per issue, drafts rewrites via the audit-workpaper-grader agent against rubrics/issue-writeup.md, and renders the report through coach-render-package --cite behind the redaction gate. Reporting & Issue Management is module 8 of the Audit plugin audit course; runs on the canonical Studio schema. Every write is a human-approved suggestion.
/audit-sampling
Use when an auditor wants to run Sampling, Data Analytics & Substantive Testing on the AssureSwarm platform — validate the test population, choose the sampling method and size, draw a reproducible sample, run whole-population analytics (duplicates, gaps, three-way match) across the extracts, evaluate and project exceptions, and conclude on the FSLI assertion. Module 6 of the Audit plugin audit course; runs on the canonical Studio schema and attaches the Substantive Testing & Data Analytics workflow. Every item, field, link, and workflow write is a human-approved suggestion.
audit-support auto-loaded
Auto-loaded internal-audit methodology reference the audit-* modules cite: sample sizes by risk and control frequency, the four selection methods, population and IPE validation, zero-occurrence and replacement rules, exception expansion, design versus operating effectiveness, evidence sufficiency and hierarchy, issue writing in the CCCER format, deficiency grading and aggregation, the control taxonomy, and the map of which module cites which section. Consulted by skills, not conversed with.
/audit-third-party
Use when an auditor wants to assess vendor and service-organization risk on the AssureSwarm platform — read vendor systems by tier, dispatch the SOC report reader against SOC reports, bridge letters, and contracts, map complementary user entity controls to controls, raise report exceptions and contract clause gaps as issues with remediation, and set reassessment dates. Module 5 of the Audit plugin audit course; runs on the canonical Studio schema and attaches the SOC Report, Subservice & CUEC Review and System & Third-Party Risk Review workflows. Every write is a human-approved suggestion.
/audit-uar
Use when an auditor wants to run periodic or privileged user access reviews (UARs) and test logical access on the AssureSwarm platform — validate the access-listing population, test management's own review against its five attributes (reviewer authority, timeliness, sign-off, listing completeness, flagged removals), reperform it by reconciling against the HR roster and the system of record, draw the sample, execute the UAR workflow per system, and raise every exception as a tracked issue. Module 3 of the Audit plugin audit course; runs on the canonical Studio schema and attaches the Periodic User Access Review and Privileged Access Review workflows. Every item, field, link, and workflow write is a human-approved suggestion.
Subagents

swarm-setup-helper
Background helper for /coach-setup. Probes available MCP servers, calls get_schema and get_current_context against a candidate, captures the schema snapshot, and returns structured status to the caller. Used proactively during setup; never interacts with the user directly — /coach-setup mediates all conversation.

coach-doc-searcher
Retrieves relevant sections from the bundled docs snapshot for /coach-ask, /coach-ask --howto, /coach-ask --diagnose, and /coach-ask --define. BM25-style search over docs-snapshot/ with header-aware scoring. Returns top sections with file paths, headings, and snippets. Read-only.
tools: Read, Glob, Grep
coach-ticket-drafter
Composes well-structured support email drafts and auto-gathers the context the CoworkCanvas support team needs (tenant subdomain, MCP setup, schema snapshot age, recent error trail). Used by /coach-ticket, /coach-ticket --feedback, and /coach-ticket --reply. Output is the email subject + body; the calling skill creates the Gmail draft via the Gmail MCP.
tools: Read, Edit, Glob, Grep
coach-troubleshooter
Diagnoses Canvas symptoms and error messages by matching against known causes in the docs snapshot. Returns likely cause, proposed fix, and a confidence rating. Used by /coach-ask --diagnose. Read-only — proposes fixes for the user or calling skill to execute.
tools: Read, Glob, Grep
audit-narrative-parser
Turns a narrative, procedure document, or interview transcript into a structured process map — steps, actors, systems, handoffs, and control points — plus a Mermaid flowchart, so the full document text never enters the calling module's context. Every control point quotes the source sentence it was drawn from. Used by internal-audit modules that start a walkthrough or process narrative from a written document.
tools: Read, Write, Bash
audit-soc-report-reader
Extracts the tested facts from a SOC report, bridge letter, or vendor contract into structured JSON — period, opinion, exceptions, subservice organizations, CUECs, or the five vendor-risk clauses depending on document_kind — so the full vendor document never enters the calling module's context. Every extracted item quotes the page or section it came from. Used by third-party and vendor-risk audit modules.
tools: Read, Write, Bash
audit-anomaly-scanner
Runs one canned analytics procedure (profile, sample, duplicates, gaps, benford, je-flags, reconcile, match) from audit_analytics.py over a csv extract so thousands of rows and the deterministic work stay out of the calling module's context. Returns the script's JSON plus a three-sentence summary. Used by /audit-uar, /audit-itgc, /audit-sampling, and /audit-fraud-je; never runs anything but that one script.
tools: Read, Write, Bash
audit-workpaper-grader
Scores a drafted artifact — an issue write-up, a workpaper's conclusion section, or an agent's suggestion or step result — against the approved rubric, so the artifact's full text never enters the calling module's context. Applies rubrics/issue-writeup.md for issue_writeup and workpaper mode, rubrics/agent-draft.md for agent_draft mode, and returns a weighted score, per-criterion notes, a verdict, and up to three top fixes.
tools: Read, Write