Skip to main content

September 2026

This page documents all customer-facing changes to the DataGrail application made in September 2026. Additional entries will be added every week on Friday.

Week of August 31โ€‹

๐Ÿš€ Features Addedโ€‹

  • Custom system names โ€” you can now rename inventory items in the Live Data Map to match your own internal naming (for example, calling Salesforce "CRM"), which is especially helpful when you have more than one item for the same system. Anyone with edit permissions can set a custom display name from the three-dot menu on an inventory row or system profile. The original catalog name is preserved, and search matches both the custom and original names.
  • User job titles and a smarter contact picker โ€” each user can now have an optional job title (like "DPO" or "Legal Counsel") set in Settings > User Admin, and the system contact picker now shows each person's email and title alongside their name, with a badge indicating whether they're a DataGrail user or an external contact.
  • Risk source assessments โ€” risks flagged by an assessment now show the source assessment's ID and name (like "RA-0042 ยท Q3 Vendor Review") in a new Assessment column and in the risk detail panel, so you can trace any risk back to where it was identified.
  • Automatic High Risk (DPIA) detection โ€” RoPA forms now fill in their own High Risk (DPIA) answers by reading what's already known about an activity and its linked systems, checking the boxes for AI use, biometric data, genetic data, and targeting of children or vulnerable individuals. Every auto-filled answer is traceable to its source, unchecks itself if the source changes, and never overwrites an answer you entered. This is live for all customers, including a backfill of in-progress RoPAs.
  • Weekly assessment emails โ€” a new personalized weekly email lists only the assessments where you still have work to do โ€” sections or questions to complete, or an assessment awaiting your approval โ€” with a link straight to each one, and it's skipped in weeks when you're all caught up. It joins the account-wide admin summary email, and both are opt-in per person under Settings > Notifications.
  • Request Manager Agent 1.3.0 โ€” the Request Manager Agent can now send custom headers on OAuth2 client-credentials token requests and extract fields from API responses using JMESPath, giving you more flexibility when connecting custom APIs through the agent.

๐Ÿ›  Changes Madeโ€‹

  • Salesforce Order Management PKCE support โ€” the Salesforce Order Management OAuth flow now supports PKCE, so you can connect it even when your Salesforce org requires PKCE on its Connected App. The change is backward-compatible and needs no action for existing connections.
  • Ada integration on v2 APIs โ€” the Ada integration now uses Ada's Bulk End-User Deletion API for deletion requests, bringing more reliable deletion processing, clearer visibility into deletion progress, new deletion behavior configuration options, and a simpler setup with one less token to manage. No action is needed for existing connections.
  • Assessments API โ€” the v2 API now returns each assessment's identifier (like "RA-0042"), lets you assign and read an assessment's approver, and attributes API-created assessments to the correct creator and contributors by email.
  • Email templates for Risk Assessments โ€” email template settings are now available to Risk Assessments customers, so more teams can review and customize the emails DataGrail sends.

๐Ÿ› Bugs Squashedโ€‹

  • Resolved an issue where an assessment creator couldn't approve it once an approver had been assigned.
  • Resolved an issue where Adobe consent containers didn't appear in the picker across all projects.
  • Resolved an issue where archived URLs still counted against your consent URL limit.