Use case · Continuous monitoring
Regulatory Change Analysis
Compliance teams must track three moving signals across 20+ regulators and ~30 peers: what just happened (peer enforcement), whether it applies to us, and what is coming (consultations, Dear CEO letters). The hard part, "is this us?", is unauditable when it lives in an analyst’s head instead of a traceable score.
From raw input to signed-off output.
$ promenaut run regulatory-change
What the workflow delivers
Peer watchlist (daily)
Ingest enforcement actions and industry events, extract respondent, breach type, period and fine, resolve peers to canonical entities, tag against a controlled breach taxonomy, and compute a deterministic significance score. A duplicate detector collapses the same event reported by multiple regulators.
Exposure brief (auto-triggered)
When significance passes 0.7, cross-reference your business lines and jurisdictions against the event, match your equivalent control class, and compute a deterministic exposure score of product-overlap × jurisdiction-overlap × control-sensitivity × recency. A composer writes the brief with peer and internal history and concrete investigation questions.
Publication monitor (daily)
Track consultations, policy statements and Dear CEO letters, tag jurisdiction and topic, and link each publication to the regulation it amends, feeding the exposure brief when an event ties to an open consultation.
Alert & review
Above an exposure threshold (default 0.6), fan out real-time alerts in-app, by email and to Slack/Teams. Humans validate the business footprint with an SME, tune the threshold and set the distribution list.
How it actually works.
- The number is deterministic and the narrative only explains it: a committee can trace "why 0.78?" to arithmetic factor contributions, and the score is reproducible, never dependent on how a model happened to answer.
- Every claim links to its source event, regulation or graph entry; every run is logged with its config version.
- The same event reported by, say, the FCA and the DOJ is deduplicated by respondent, breach period and fine amount before scoring.
- A hand-curated business-footprint matrix (business line × jurisdiction × product) drives per-desk relevance, so the right desk gets the right event.
- Deterministic code produces the score; lighter automated steps handle tagging; the most capable reasoning is reserved for the final brief.
What it produced.
What the workflow delivers
20+ regulators
Monitored continuously across ~30 peers
Instant
Understand which dependencies a regulatory event impacts
Auditable score
Relevance traced to arithmetic, not a hunch
Per-desk alerts
The right event reaches the right function in real time
Coverage seeded to ~30 peers, 20+ regulators and a controlled breach taxonomy, tuned once with a regulatory-affairs SME.
The parts that break naive tools.
The "is this us?" call must be auditable
A deterministic scorer produces the number so it is traceable to arithmetic; the narrative is written around it, not instead of it.
The same event, many regulators
Enforcement is often announced by multiple bodies; deduplication by respondent, breach period and fine amount prevents double-counting and duplicate alerts.
Mapping a peer’s failure onto your controls
Requires knowing your footprint and equivalent control class, handled by an SME-validated footprint matrix and a control matcher.
Timeliness versus a weekly digest
A weekly cadence would miss urgent events, so high-exposure items escalate synchronously and fan out immediately, decoupled from the digest.
See it on a workflow you own.
Bring a real process. We'll show what your first agentic workflow looks like on the platform.
Promenaut
