Vendor security posture watch between assessments

For: Third-party risk analyst or security lead responsible for supplier assurance

Pattern: WatchtowerNeeds a connectorDesigned for 10 to 300 agents

The pain today

Vendors are assessed once a year from a questionnaire. In between, their subprocessor lists, security pages and breach notices change, and nobody rereads them.

The ask

Watch the public security, trust, status and subprocessor pages of the vendors on my attached list, and compare them with what the vendors told us in the attached questionnaires. Tell me when a change contradicts an answer or our requirements, with both passages quoted.

Plain words, as you would say it to a colleague. Edit it to fit your case before you send it.

What you attach or connect

  • Vendor list with criticality
  • Completed security questionnaires and contract security clauses
  • Public trust, status and subprocessor pages
  • Our vendor security requirements

The unit of work

One worker task per one vendor page against that vendor's answers.

Why a swarm fits

Vendors are independent, and so are their pages. When one page changes, only the answers that depended on it need re-reading.

Not for

A deep assessment of one critical vendor: that needs their audit reports and a conversation.

The decision tree

5 typed decisions, each with an action for every answer

At fixed moments in a run, the engine puts one narrow question to a decision model. The decision model never writes text: it answers yes or no with a probability, picks from listed options, or gives a score, about a small slice of the material. The engine then does exactly what this tree says, which is what makes the run auditable. The thresholds are the template's design values, not measured results.

  1. Run control, between rounds

    Another round?A choice among options

    Between rounds

    Compared with the last capture, is this vendor page unchanged, changed, or unavailable?

    Sees only: The previous and current capture of one vendor page

    Why: Unchanged pages cost nothing further, and a failed fetch is never read as no change.

    • Fetched and unchangedthenStop
    • Fetched and changedthenContinue
    • Could not be fetchedthenMark unresolved
  2. Planner, while planning

    Scope checkYes or no, with a probability

    Before work starts on a unit

    Is the difference between the two captures a change of substance, such as a new subprocessor, a removed certification or new incident text, rather than layout or wording polish?

    Sees only: The changed passages from the two captures

    Why: Cosmetic edits are logged and dropped before any answer is re-read.

    • Yes: 0.55 or higherthenAccept
    • Unsure: 0.25 up to 0.55thenAccept
    • No: below 0.25thenSkip this unit
  3. Scope checkYes or no, with a probability

    Before work starts on a unit

    Does this questionnaire answer depend on what the changed passage states?

    Sees only: One questionnaire answer and the changed passage

    Why: Only the answers that depended on the page are redone.

    • Yes: 0.60 or higherthenAccept
    • Unsure: 0.25 up to 0.60thenAccept
    • No: below 0.25thenSkip this unit
  4. After workers, the judge checks

    Evidence checkA choice among options

    After a worker answers

    Does the new page text contradict the vendor's quoted questionnaire answer or contract clause?

    Sees only: The old text, the new text and the quoted answer or clause

    Why: An alert a risk analyst cannot verify in one glance will be ignored next time.

    • Contradicts itthenAccept
    • Consistent with itthenSkip this unit
    • Wording is ambiguousthenMark unresolved
    • Page no longer addresses the topicthenMark unresolved
  5. Accountable person, before anything is settled

    Person decidesYes or no, with a probability

    Before anything is reported as settled

    Does this change concern a vendor marked critical, or the location, subprocessors or breach status of data we send them?

    Sees only: One verified change and the vendor's criticality row

    Why: Whether to reassess, invoke the contract or do nothing is the risk owner's decision.

    Accountable: The risk owner decides whether a change triggers a reassessment, a contract step or nothing.

    • Yes: 0.35 or higherthenAsk a person
    • Unsure: 0.10 up to 0.35thenAsk a person
    • No: below 0.10thenAccept

The fleet: who does what

Model tiers by role, not brands: you choose the models. Strong reasoning models plan and reconcile, small fast models do the wide work, and the judge is a decision model from a different family, so it does not share the workers' blind spots.

  1. Planner

    A strong reasoning model links each questionnaire answer to the public pages that could confirm or contradict it.

    Decisions here:2. Scope check3. Scope check

  2. Workers

    Small fast workers from an open-weight family each re-read one changed page and extract what differs.

    Designed for 10 to 300 agents, one worker task per one vendor page against that vendor's answers. Each worker receives only its own unit.

  3. Judge, from a different model family

    A decision model from a different family checks the change truly contradicts the quoted answer or clause.

    Decisions here:4. Evidence check

  4. Reconciler

    A strong reasoning model orders changes by vendor criticality and keeps ambiguous wording as open questions.

    Decisions here:1. Another round?

  5. Accountable person

    The risk owner decides whether a change triggers a reassessment, a contract step or nothing.

    Decisions here:5. Person decides

Checked before anything is accepted

  • Each alert quotes the old text, the new text and the affected answer
  • Cosmetic page changes are logged but not alerted
  • Pages that could not be fetched are reported, not assumed unchanged

What comes back

  • Change alerts with before, after and the contradicted answer
  • Questions to send the vendor
  • Record of what was re-checked and why
  • Vendors with no public evidence to watch

What to measure

  • Alerts that led to a vendor question
  • Material changes learned elsewhere first
  • Analyst hours per vendor
  • Cost per re-check

Names of measures only. No result is claimed for this template.

Templates open in the workspace chat with the ask filled in. Nothing runs until you send it.

Get early accessSign in to use

A night of alerts triaged into incidents with evidence

For: Security operations lead or on-call analyst starting the morning shift

Overnight the queue fills with alerts, most of them duplicates or noise.

Pattern: Map, verify, reduceNeeds a connector6 decisionsDesigned for 30 to 1,000 agents

Root-cause hypotheses tested against log windows

For: Site reliability engineer or incident commander writing the review after an outage

After an outage the first plausible story wins.

Pattern: Cross-examinationNeeds scale6 decisionsDesigned for 20 to 500 agents

Threat model attacked before the design is built

For: Security architect or product security engineer reviewing a new system design

Threat models are written by the people who designed the system, so they list the threats the design already handles.

Pattern: Adversarial reviewNeeds live models5 decisionsDesigned for 6 to 60 agents