Weekday Addepar compliance digest from the audit trail
Every weekday at 7am, roll up 24 hours of Addepar activity, flag anything worth a compliance look, and email plus ping Slack.
Every weekday at 7am, produce a compliance security digest from the last 24 hours of Addepar audit trail activity, email it to the compliance team, and post a compact status line to the compliance Slack channel.
Trigger: cron, Monday through Friday at 7:00am in the firm's local timezone. On Monday, extend the lookback to cover the weekend so nothing falls through the gap.
Step 1. Pull the last 24 hours of audit events from Addepar using Get Audit Trail. Fetch every event in the window; do not sample. If the window spans a weekend or a missed run, extend it to cover the gap.
Step 2. Categorize each event into the buckets a compliance officer cares about:
- Failed login attempts and account lockouts (repeat failures for the same user, lockouts, MFA failures)
- Permission or role changes on client-facing users (advisors, client service, external users; scope grants, role escalations, portfolio access changes)
- Edits or deletions of transactions, snapshots, and valuations (especially bulk edits, backdated changes, or deletions on closed periods)
- Off-hours access (activity outside normal business hours in the firm's timezone, weekends, or from unusual geographies if location is present in the event)
- Unusual bulk exports or file downloads (large report generation, mass file downloads, exports of client-identifying data)
Step 3. Suppress benign noise so the digest stays useful. Routine advisor logins from known accounts during business hours, scheduled report runs, and system service accounts performing their normal daily jobs should be omitted from the categorized list (but still counted in totals). Only surface events that are exceptions or need follow-up.
Step 4. Flag anything that looks like a policy exception: repeated failed logins for a single user, permission grants to external or newly-created users, deletions of transactions in prior closed periods, off-hours edits to client data, or a single user pulling an unusually large volume of exports. Call these out at the top of the digest.
Step 5. Write the digest with an executive summary at the top (2 to 4 sentences: total events reviewed, count of exceptions by bucket, and the single most important thing the compliance team should look at first) followed by the categorized event list. Each event line should include the timestamp, the user, what happened, and why it was flagged. Keep it scannable.
Step 6. Send the digest via Gmail Send a Message to the compliance distribution list. Subject line should include the date and the exception count, for example: "Addepar compliance digest — 2026-07-17 — 3 items to review". If there are zero exceptions, say "all clear" in the subject.
Step 7. Post a single compact line to the compliance Slack channel via Slack Send a Message. Format: "Addepar compliance digest for <date>: all clear" when there are no exceptions, or "Addepar compliance digest for <date>: N items to review — see email" when there are. Do not paste the full digest into Slack; keep it a one-liner and link readers to the email.
Formatting rules: neutral, factual tone; no marketing language; no speculation about intent; if the audit trail is empty for the window, still send the email and the Slack line so the compliance team knows the check ran.
Additional information
What does this prompt do?
- Every weekday morning, pulls the last 24 hours of Addepar audit activity and groups it into buckets a compliance officer actually cares about.
- Flags failed logins and lockouts, permission or role changes on client-facing users, edits or deletions of transactions and valuations, off-hours access, and unusual bulk exports.
- Suppresses routine advisor logins and scheduled report runs so only real exceptions show up in the digest.
- Emails the categorized digest with an executive summary to your compliance team and posts a compact status line to your compliance Slack channel.
What do I need to use this?
- An Addepar login with permission to read the firm audit trail
- A Gmail account that can send from your compliance mailbox
- A Slack workspace with the compliance channel you want status pings in
How can I customize it?
- Change the schedule — a different time of morning, weekends included, or twice a day
- Add or drop the categories the digest watches (permission changes, off-hours access, bulk exports, transaction edits) and tune what counts as off-hours for your firm
- Update the email recipients and the Slack channel, and adjust the noise filters (which advisors or service accounts to suppress as routine)
Frequently asked questions
Does this replace our formal compliance monitoring program?
Will it flood the compliance team on quiet days?
How does it decide what is 'routine' versus worth flagging?
Can it look back further than 24 hours if we miss a day?
Do we need every reader on the compliance team to have an Addepar login?
Related templates
Give your compliance team eyes on Addepar without the manual review.
Turn the audit trail into a short daily brief with the exceptions already surfaced.