Skip to main content

September 2026

This page documents all customer-facing changes to the DataGrail application made in September 2026. Additional entries will be added every week on Friday.

Week of September 21โ€‹

๐Ÿš€ Features Addedโ€‹

  • IP allowlisting now covers every major way into your environment โ€” user sign-in, API keys, Agents, and external MCP clients like Claude Desktop and Cursor โ€” each with its own set of approved IP ranges. Enforcement is continuous and every allowlist is off by default, so nothing changes until an admin turns one on.
  • Talon.One is now available as a Request Manager integration, so you can automate Access and Deletion requests against Talon.One instead of handling them by hand.

๐Ÿ›  Changes Madeโ€‹

  • Assessment contributions โ€” any assessment member can now submit their own contribution, including someone who both created an assessment and is a contributor on it. Approval authority is unchanged, so who can contribute stays separate from who can approve.
  • Auth0 connections now accept private-cloud tenant domains, not just standard .auth0.com domains, so customers on private Auth0 instances can connect.
  • You can now send a test email for DataGrail-hosted mailer senders directly from the integration's edit page, and the sender's status updates immediately after the test instead of waiting for the next health check.

๐Ÿ› Bugs Squashedโ€‹

  • Resolved an issue where the Demandbase integration could fail to authenticate, so connections and token refreshes now work reliably.
  • Resolved an issue where Greenhouse deletion requests didn't fully anonymize the configured candidate fields.
  • Resolved an issue where the Apollo integration could stop authenticating after Apollo changed how API keys must be sent.
  • Resolved an issue where SMS identity verification codes weren't sent for phone numbers entered without a country code.
  • Resolved an issue where authorized-agent requests could stay stuck in "Awaiting Verification" instead of advancing as soon as the verification link was selected.
  • Resolved an issue where a data broker deletion status upload could get stuck partway through after an interrupted deploy.
  • Resolved an issue where the 45-day data broker deletion compliance deadline could be measured from the upload time instead of from when the list was accessed.

Week of September 14โ€‹

๐Ÿš€ Features Addedโ€‹

  • Assessment template settings โ€” assessment templates now have a Settings panel where you can set a default approver and one or more owners. On Risk Monitor templates, set the approver once and every assessment created from it โ€” however it's created โ€” gets the right person assigned automatically.
  • Assessment Requester role โ€” a new role lets you separate the people who create and work on assessments from the people who approve them. Requesters can do everything a Creator can โ€” create, edit, invite contributors, upload documents โ€” except approve an assessment, submit it for approval, or be assigned as an approver.
  • Assessment email templates now cover the full assessment workflow โ€” contributor invitations, assignment notices, reminders, and completion and approval notices can all be customized to match your own wording and branding.
  • Field Level Controls are now available for Access requests on SurveyMonkey, DocuSign, Slack, and Zendesk, so you can choose exactly which fields DataGrail collects from each.

๐Ÿ›  Changes Madeโ€‹

  • We reduced the size of the consent template generated for your Google Tag Manager container, freeing up publish headroom if you're running many privacy policies. Publish your container once to pick up the smaller template โ€” no configuration changes needed.
  • IP allowlisting in Settings > Security is easier to edit safely โ€” the sign-in allowlist and machine IP range catalog now save independently and guard against accidental lockouts, and you can now restrict a new Agent's API key to specific IP ranges at creation instead of only after the fact.
  • Data broker deletion CSV uploads that get rejected now show you the specific reason why โ€” like an incorrectly named file โ€” instead of a generic error, so you know exactly what to fix before re-uploading.
  • Request Manager Agent 1.3.1 โ€” routine maintenance and a security patch for a dependency vulnerability.

๐Ÿ› Bugs Squashedโ€‹

  • Resolved an issue where an Adobe consent container in embedded delivery could be left with an empty consent rule that no longer did anything.
  • Resolved an issue where @-mentioning a Creator, Requester, or Contributor in an assessment comment wouldn't surface them in the suggestion list.
  • Resolved an issue where an assessment answer could fail to save and force you to restart the assessment โ€” the answer is now preserved so you can retry without losing progress.
  • Resolved an issue where the Intake Form editor could crash when loading certain relationship questions.
  • Resolved an issue where bulk-editing contacts could silently drop a selection from the list.
  • Resolved an issue where an automated data broker deletion status update could get stuck retrying and never complete, due to an internal filename mismatch.
  • Resolved an issue where certain unclassified email-sourced privacy requests didn't receive their closure notification email.

Week of September 7โ€‹

๐Ÿš€ Features Addedโ€‹

  • Contacts in Settings > User Admin โ€” you can now manage everyone who owns a system in DataGrail but doesn't need a login from one searchable, sortable page, right alongside Users and Invitations. Each contact shows which systems they own and whether they were synced from your identity provider (Okta, OneLogin, and others) or added manually, and deleting a contact tells you up front how many system assignments will go with it.
  • Field Level Controls are now generally available for Access requests across 13 integrations, including Salesforce, Stripe, HubSpot, Shopify, and Klaviyo. If you have Super Admin or Connections Manager permissions, you can choose exactly which fields (or entire field categories) DataGrail retrieves for an Access request, directly within each connected integration, and review your changes before saving. No action is needed โ€” the defaults match what DataGrail includes today.
  • Box deletion โ€” Box can now process deletion requests automatically through its API, so you no longer have to find and remove files by hand. DataGrail locates the files, folders, and web links tied to the data subject and deletes them. Two new connection settings let you control whether items are purged from the trash immediately for permanent erasure or left to Box's retention window, and how non-empty folders are handled.
  • Show only my assignments on Risk Assessments โ€” contributors and reviewers on long risk assessments can now turn on "Show only my assignments" to filter the form down to just the sections and questions assigned to them. It's opt-in, off by default, and works for both internal and external contributors.
  • Explain automated workflows with Vera โ€” a new "Explain with Vera" button on the workflow view opens a Vera chat that walks through a workflow from top to bottom, covering every branch, condition, and path in plain language. You can keep the conversation going to dig into specific logic or ask how a workflow could be improved.
  • Upload documents to an assessment via API โ€” you can now attach a document to an existing risk assessment through the v2 API, so external systems like a procurement integration can add supporting files directly. The upload is attributed to the right person by email and appears in the assessment's attachments just like an in-app upload.

๐Ÿ›  Changes Madeโ€‹

  • Assessment progress and status now appear in two separate, sortable columns in the assessments table. A new Progress column shows each assessment's completion as a readable percentage for the first time and is included in the CSV export, while Status stays a clear text label.

๐Ÿ› Bugs Squashedโ€‹

  • Resolved an issue with how IAB TCF vendor data categories are synced from the Global Vendor List.
  • Resolved an issue where custom systems you added yourself were left out of your RoPA export.
  • Resolved an issue where the TSV viewer could hang your browser when opening large files.
  • Resolved an issue where compound condition rules couldn't be edited in assessment templates.
  • Resolved an issue where the Additional Info panel didn't load its saved title and description.
  • Resolved an issue where a multibrand group wasn't copied to the inventory item when connecting an integration.
  • Resolved an issue where deactivated users could still receive notification emails.

Week of August 31โ€‹

๐Ÿš€ Features Addedโ€‹

  • Custom system names โ€” you can now rename inventory items in the Live Data Map to match your own internal naming (for example, calling Salesforce "CRM"), which is especially helpful when you have more than one item for the same system. Anyone with edit permissions can set a custom display name from the three-dot menu on an inventory row or system profile. The original catalog name is preserved, and search matches both the custom and original names.
  • User job titles and a smarter contact picker โ€” each user can now have an optional job title (like "DPO" or "Legal Counsel") set in Settings > User Admin, and the system contact picker now shows each person's email and title alongside their name, with a badge indicating whether they're a DataGrail user or an external contact.
  • Risk source assessments โ€” risks flagged by an assessment now show the source assessment's ID and name (like "RA-0042 ยท Q3 Vendor Review") in a new Assessment column and in the risk detail panel, so you can trace any risk back to where it was identified.
  • Automatic High Risk (DPIA) detection โ€” RoPA forms now fill in their own High Risk (DPIA) answers by reading what's already known about an activity and its linked systems, checking the boxes for AI use, biometric data, genetic data, and targeting of children or vulnerable individuals. Every auto-filled answer is traceable to its source, unchecks itself if the source changes, and never overwrites an answer you entered. This is live for all customers, including a backfill of in-progress RoPAs.
  • Weekly assessment emails โ€” a new personalized weekly email lists only the assessments where you still have work to do โ€” sections or questions to complete, or an assessment awaiting your approval โ€” with a link straight to each one, and it's skipped in weeks when you're all caught up. It joins the account-wide admin summary email, and both are opt-in per person under Settings > Notifications.
  • Request Manager Agent 1.3.0 โ€” the Request Manager Agent can now send custom headers on OAuth2 client-credentials token requests and extract fields from API responses using JMESPath, giving you more flexibility when connecting custom APIs through the agent.

๐Ÿ›  Changes Madeโ€‹

  • Salesforce Order Management PKCE support โ€” the Salesforce Order Management OAuth flow now supports PKCE, so you can connect it even when your Salesforce org requires PKCE on its Connected App. The change is backward-compatible and needs no action for existing connections.
  • Ada integration on v2 APIs โ€” the Ada integration now uses Ada's Bulk End-User Deletion API for deletion requests, bringing more reliable deletion processing, clearer visibility into deletion progress, new deletion behavior configuration options, and a simpler setup with one less token to manage. No action is needed for existing connections.
  • Assessments API โ€” the v2 API now returns each assessment's identifier (like "RA-0042"), lets you assign and read an assessment's approver, and attributes API-created assessments to the correct creator and contributors by email.
  • Email templates for Risk Assessments โ€” email template settings are now available to Risk Assessments customers, so more teams can review and customize the emails DataGrail sends.

๐Ÿ› Bugs Squashedโ€‹

  • Resolved an issue where an assessment creator couldn't approve it once an approver had been assigned.
  • Resolved an issue where Adobe consent containers didn't appear in the picker across all projects.
  • Resolved an issue where archived URLs still counted against your consent URL limit.