The vendor list is the DSAR
Most delayed DSARs are not delayed because someone cannot find a PDF. They are delayed because the processor list is fiction. Last year's RoPA does not include Tuesday's AI extension. Regulators will ask how you knew who held the subject's data. "We emailed the vendors we already had DPAs with" is not a discovery method. An OAuth export timestamped before first send is.
This template is the columns, the join rules, and the mistakes that make a list unusable in week two. It feeds the outreach in the DSAR playbook. Templates there are operator-reviewed, not lawyer-reviewed. Same rule here.
ScopeMantle DSAR automation snapshots Google Workspace and Okta grants when a case opens. You can build the CSV without us. You will hate doing it twice. $5 annual / $6 monthly, no seat min, custom 500+, trial.
The columns
| Column | Why it exists | Reject the row if |
|---|---|---|
| Display name | Humans | It is the only key. Rebrands will duplicate you |
| OAuth client ID | Stable identity | Missing. Display-name-only rows fail traceability |
| Scopes | Inferred data categories | Blank. You cannot tier the send |
| Grant owner | Escalation path | You never mapped a department |
| Created / last used | Stale vs active | You treat last-used as proof of "no data" |
| Scope Sanity / score | Send order | You sort by vendor brand instead |
| DPA on file | Parallel remediation | You stall the subject clock waiting for paper |
| Privacy contact | Where the letter goes | You used support@ with no ticket ID |
| Attestation status | Who said this tool is allowed | A Slack emoji counts as yes |
Deduplicate on client ID. Filter to mail, Drive, calendar, profile, and directory scopes for the first send. Keep the rest in an appendix so you can defend the cut. Tag missing DPA as privacy work, not as a reason to miss Article 15.
Map scopes to categories (starting point only)
gmail.readonly: email content and metadata. Tier 1.- Drive /
drive.file: documents the user opened through the vendor. Tier 1 if the subject could be in those files. - Calendar: meeting titles and attendees. Still personal data.
- Profile / email: identity. Confirm. Do not assume empty.
- admin.directory: org records. Tier 1, blast radius is not one mailbox.
Inference is not vendor confirmation. The Article 15 letter still asks. AI tools with broad Google scopes go in the parallel-send pile. Do not wait to be "sure." Sure is what the reply is for.
Build the list (procedure)
- Export Google third-party app access and Okta OAuth clients the morning the request is valid (after identity verification).
- Join on client ID. Drop display-name-only duplicates.
- Join grant owner to HRIS for department and employment status. Departed owners with live grants are both a DSAR problem and a CC9.2 problem. Fix with the deprovisioning model.
- Fill privacy contact from the DPA, the vendor trust page, or a procurement note. If none exists, the row is still sendable to the published privacy email plus a ticket.
- Filename:
dsar-{caseId}-inventory-YYYYMMDD.csv. Hash it. Store it on the case. That is how you prove the list was contemporaneous, not retrofitted. - Open the case in your tool (or ScopeMantle) with that snapshot attached. Do not keep editing the snapshot. New grants after send go in a supplement.
RoPA reconciliation
Once a quarter, diff the OAuth inventory against RoPA. Net-new grants become RoPA update tickets. That is how the two artifacts stop lying about each other. Mature privacy programs already want this. OAuth just gives them a join key.
Do not replace RoPA with an OAuth export. OAuth misses processors that never used Google or Okta. Warehouse connectors with only a service key are the obvious hole. Call that limitation in the case file. ScopeMantle will not invent those rows.
Worked examples
HubSpot via Google. Client ID from inventory, mail and contacts scopes, marketing owner, DPA on file. Article 15 goes to the HubSpot privacy contact with the ID in the letter. See playbook templates.
Unknown extension, gmail.readonly, intern owner who left. Tier 1. Send access. Revoke the grant. Note the leftover as an offboarding miss.
Analytics tool with profile only, 3 users. Tier 3. Confirm. Do not blast Article 20.
What to tell an auditor or a DPA
"Discovery is the hashed IdP export attached to the case, dated before first vendor email. Here are send logs. Here is the RoPA diff from last quarter." Say the templates are operator-reviewed. Say Entra inventory is Beta if Microsoft is in scope. Do not claim HIPAA. Do not claim a DPDPA certification.
Failure modes
- One spreadsheet for the year, copied into every case.
- No client ID.
- Starting the clock before identity verification, or after you "felt ready."
- Forgetting sandbox and agency grants.
- Letting an MSP send without client counsel (white-label note).
What to do this week
- Build the column header row. Freeze it. Do not let people delete client ID.
- Rebuild one closed DSAR from a fresh export. Count missed processors. That number funds the project.
- Read the OneTrust alternative if someone wants another policy library instead of a list.
- India clocks: DPDPA checklist.
- Trial the platform if you want the snapshot on case open.
CSV validation rules you can give an intern
- Reject rows without client ID.
- Reject rows without at least one scope string.
- Warn if owner email is not in HRIS and not in the contractor register.
- Warn if privacy contact is empty. Fill before send, not after.
- Do not delete appendix rows (non-personal-data scopes). Hide them.
- Never overwrite the hashed snapshot. Clone to a working sheet.
Version the working sheet if you must. The snapshot stays sacred. Auditors and regulators care about the sacred one.
When the subject names a tool you do not have
Add it to the case as a lead, not as a proof of inventory failure. Search Admin and Okta for the name and for cousins (acquirer names). Search Salesforce Connected Apps if CRM is in play. If it is a warehouse connector with only a key, you are outside OAuth. Say so. Do not pretend the IdP export is omniscient.
If the subject names a tool that is on the inventory and you did not email them, that is an inventory-quality miss. Fix the tiering rule. Do not blame the intern.
MSP and multi-entity notes
Per-entity snapshots. Do not mix a subsidiary's grants into the parent case unless counsel says the controller relationship works that way. White-label operators: read the gate. India clocks: DPDPA. $5 / $6, no seat min, Entra Beta, HIPAA not attested.
Field guide: the intern week
Day 1: freeze headers. Day 2: one export, one hash. Day 3: fill privacy contacts for Tier 1 only. Day 4: rebuild one old case. Day 5: present the miss count. Do not let them send mail. Do not let them delete appendix rows. Do not let them overwrite the snapshot. If they finish early, they write the validation rules into the wiki in their own words so you can see what they misunderstood.
Operator-reviewed templates. Counsel send. Entra Beta. HIPAA not attested. $5 / $6, no seat min. Playbook.
Mistakes I keep seeing after the first workshop
People export once and call it culture. People revoke by display name after a rebrand. People promise Entra completeness. People put OAuth rows in the user-access matrix. People send DSAR mail without a case ID. People treat a CASB invoice as grant inventory. People change a score threshold the night before audit. People staff an MSSP sprint with someone who cannot read a scope string. Each of those has a fix already on this page. The failure is skipping the fix because the demo looked polished.
Write the one thing you will not skip this week. Put it on a calendar. If you want the inventory to stay current, the 30-day trial is the productized version of the export. Five dollars per employee per month billed annually, or six dollars monthly. No seat minimum. Custom terms at 500+ employees. Microsoft Entra stays labelled Beta. HIPAA is not attested. Templates stay operator-reviewed. No fabricated customer counts on the customers page.
If you are evaluating us next to a GRC tool, keep both jobs honest. If you are evaluating us next to a consent-intercept tool, stack prevention and inventory. If you are an MSP, register the deal before the demo and keep the counsel gate in the SOW. If you are writing a board slide, use last quarter as the only benchmark we will stand behind. That is enough program for a quarter. The next quarter is whether the leftover-grant count actually moved.
A note for the privacy analyst building the first sheet
Freeze headers. Require client ID. Hash the snapshot. Clone a working copy. Fill Tier 1 privacy contacts before anyone talks about Article 20. Rebuild one old case and bring the miss count to the stand-up. Do not send mail. Do not delete the appendix. Do not treat last-used as proof of no data. Counsel still owns the letter. We still do not review it as lawyers.
What you can do without buying anything
Export the IdP list. Deduplicate on client ID. Revoke three rows you cannot explain. Write the CC9.2 versus CC6.7 sentence for your auditor. Add OAuth grants equals zero to offboarding. Put an extension allow-list in one OU. Schedule a Friday tabletop with a fictional client ID. Hash a file and put it in GRC. Those steps do not require ScopeMantle. They do require a calendar and a human who will not skip them.
When those steps start to rot (and they will, usually by week six), the productized version is daily Google and Okta sync, scores, attestation expiry, bulk revoke, and DSAR snapshot on the same inventory. Price is public. Beta labels stay on the page. We will not invent a case study to make the last paragraph feel finished. Start the trial if the calendar is already losing.
Name the four column owners even if they are the same person. A RACI of one is still a RACI. The hashed snapshot stays sacred. Working sheets get cloned. That discipline is the difference between a template and a theater CSV.
Related reading stays on the internal paths already linked above: platform, integrations, demo, and the companion resources or blog posts for this topic. Use those links when you brief a colleague so they get the same product truth: public $5 / $6 pricing, no seat minimum, custom at 500+, Entra labelled Beta, DSAR templates operator-reviewed, no HIPAA attestation, no invented logos. That is the briefing. Everything else is the procedure you can run this week.
Start the trial from /demo when the manual export starts to rot. That is usually week six, not week one.