September 2026
This page documents all customer-facing changes to the DataGrail application made in September 2026. Additional entries will be added every week on Friday.
Week of September 7β
π Features Addedβ
- Contacts in Settings > User Admin β you can now manage everyone who owns a system in DataGrail but doesn't need a login from one searchable, sortable page, right alongside Users and Invitations. Each contact shows which systems they own and whether they were synced from your identity provider (Okta, OneLogin, and others) or added manually, and deleting a contact tells you up front how many system assignments will go with it.
- Field Level Controls are now generally available for Access requests across 13 integrations, including Salesforce, Stripe, HubSpot, Shopify, and Klaviyo. If you have Super Admin or Connections Manager permissions, you can choose exactly which fields (or entire field categories) DataGrail retrieves for an Access request, directly within each connected integration, and review your changes before saving. No action is needed β the defaults match what DataGrail includes today.
- Box deletion β Box can now process deletion requests automatically through its API, so you no longer have to find and remove files by hand. DataGrail locates the files, folders, and web links tied to the data subject and deletes them. Two new connection settings let you control whether items are purged from the trash immediately for permanent erasure or left to Box's retention window, and how non-empty folders are handled.
- Show only my assignments on Risk Assessments β contributors and reviewers on long risk assessments can now turn on "Show only my assignments" to filter the form down to just the sections and questions assigned to them. It's opt-in, off by default, and works for both internal and external contributors.
- Explain automated workflows with Vera β a new "Explain with Vera" button on the workflow view opens a Vera chat that walks through a workflow from top to bottom, covering every branch, condition, and path in plain language. You can keep the conversation going to dig into specific logic or ask how a workflow could be improved.
- Upload documents to an assessment via API β you can now attach a document to an existing risk assessment through the v2 API, so external systems like a procurement integration can add supporting files directly. The upload is attributed to the right person by email and appears in the assessment's attachments just like an in-app upload.
π Changes Madeβ
- Assessment progress and status now appear in two separate, sortable columns in the assessments table. A new Progress column shows each assessment's completion as a readable percentage for the first time and is included in the CSV export, while Status stays a clear text label.
π Bugs Squashedβ
- Resolved an issue with how IAB TCF vendor data categories are synced from the Global Vendor List.
- Resolved an issue where custom systems you added yourself were left out of your RoPA export.
- Resolved an issue where the TSV viewer could hang your browser when opening large files.
- Resolved an issue where compound condition rules couldn't be edited in assessment templates.
- Resolved an issue where the Additional Info panel didn't load its saved title and description.
- Resolved an issue where a multibrand group wasn't copied to the inventory item when connecting an integration.
- Resolved an issue where deactivated users could still receive notification emails.
Week of August 31β
π Features Addedβ
- Custom system names β you can now rename inventory items in the Live Data Map to match your own internal naming (for example, calling Salesforce "CRM"), which is especially helpful when you have more than one item for the same system. Anyone with edit permissions can set a custom display name from the three-dot menu on an inventory row or system profile. The original catalog name is preserved, and search matches both the custom and original names.
- User job titles and a smarter contact picker β each user can now have an optional job title (like "DPO" or "Legal Counsel") set in Settings > User Admin, and the system contact picker now shows each person's email and title alongside their name, with a badge indicating whether they're a DataGrail user or an external contact.
- Risk source assessments β risks flagged by an assessment now show the source assessment's ID and name (like "RA-0042 Β· Q3 Vendor Review") in a new Assessment column and in the risk detail panel, so you can trace any risk back to where it was identified.
- Automatic High Risk (DPIA) detection β RoPA forms now fill in their own High Risk (DPIA) answers by reading what's already known about an activity and its linked systems, checking the boxes for AI use, biometric data, genetic data, and targeting of children or vulnerable individuals. Every auto-filled answer is traceable to its source, unchecks itself if the source changes, and never overwrites an answer you entered. This is live for all customers, including a backfill of in-progress RoPAs.
- Weekly assessment emails β a new personalized weekly email lists only the assessments where you still have work to do β sections or questions to complete, or an assessment awaiting your approval β with a link straight to each one, and it's skipped in weeks when you're all caught up. It joins the account-wide admin summary email, and both are opt-in per person under Settings > Notifications.
- Request Manager Agent 1.3.0 β the Request Manager Agent can now send custom headers on OAuth2 client-credentials token requests and extract fields from API responses using JMESPath, giving you more flexibility when connecting custom APIs through the agent.
π Changes Madeβ
- Salesforce Order Management PKCE support β the Salesforce Order Management OAuth flow now supports PKCE, so you can connect it even when your Salesforce org requires PKCE on its Connected App. The change is backward-compatible and needs no action for existing connections.
- Ada integration on v2 APIs β the Ada integration now uses Ada's Bulk End-User Deletion API for deletion requests, bringing more reliable deletion processing, clearer visibility into deletion progress, new deletion behavior configuration options, and a simpler setup with one less token to manage. No action is needed for existing connections.
- Assessments API β the v2 API now returns each assessment's identifier (like "RA-0042"), lets you assign and read an assessment's approver, and attributes API-created assessments to the correct creator and contributors by email.
- Email templates for Risk Assessments β email template settings are now available to Risk Assessments customers, so more teams can review and customize the emails DataGrail sends.
π Bugs Squashedβ
- Resolved an issue where an assessment creator couldn't approve it once an approver had been assigned.
- Resolved an issue where Adobe consent containers didn't appear in the picker across all projects.
- Resolved an issue where archived URLs still counted against your consent URL limit.









