Foresight: checking a change against your promises¶
Before you swap a vendor, you can ask your AI to check the change against what you have already told your customers. Kanonik compares the promises you approved with the facts you approved about the vendors involved, and gives you a result for each promise before anything is signed or switched over.
You run it through your connected AI, which calls Kanonik's Foresight. The result is labelled "Foresight (preview)". Workspace admins, reviewers, authors and auditors can run it.
For example: you are moving your CRM from one vendor to another on a set date. Ask your AI to check the switch against what you have promised. You get one row per promise, the reason for each row, which of your sealed answer sets contain a promise that is not clear, and a suggested next step.
The check writes nothing. It does not change your compliance record, it does not send anything to a vendor, and it does not need an approval. As with every request Kanonik receives, the request itself is logged. You can run it as many times as you like, with different dates or a different plan.
The check covers two kinds of change: replacing a vendor and adding one. Every vendor in the change must already be sealed in your record, and you give a go-live date.
What the check reads¶
- Promises. Your saved answers that Kanonik can check, such as where customer data is stored, how long backups are kept, whether every sub-processor has a signed data processing agreement, how much notice you give before adding one, and whether customer data is used to train AI models. When you approved each one, Kanonik showed how it would be checked, and you approved that reading with it.
- Facts about vendors. Regions, backup retention, agreement status and similar facts your AI read from a vendor's own document. Each fact carries the document's fingerprint, the clause it came from, and who approved it. A second person approves each fact. In a workspace with only one person, that person approves it and the record says so.
- The change. The vendors you are retiring and adding, the go-live date, and, if you give one, the date you plan to send notice.
Your AI reads the vendor's document on your side. Kanonik never receives the file.
The four results¶
Every promise gets exactly one of four labels.
| Result | What it means |
|---|---|
| No conflict | The approved facts are consistent with the promise, for the vendors in this change. |
| Conflict | The promise cannot hold for this change: an approved fact contradicts it, or the dates you gave do not leave enough notice. If you give no notice date and the go-live date is already closer than the promised notice period, that is a conflict too. The row says which, and names the fact, its clause and who approved it when a fact is the reason. |
| Needs information | Kanonik cannot reach an answer yet. A fact the promise depends on may be missing or recorded as unknown, expired, out of date or not yet valid on the date checked, or recorded for a different data category, environment or plan; the approved facts may disagree with each other; a value may not match a known term; the way to check the promise may not be approved yet; or not every record could be read, in which case run the check again. The row names what is needed, so you know what to ask the vendor for or which fact to revisit. |
| Not applicable | The promise does not concern anything in this change. |
A "No conflict" row is stated for the vendors in the change only. It is not a statement about the rest of your vendors.
Dates are assumptions¶
The check is run for a date you give: the go-live date, and the date notice will go out. Those dates are shown in each result as assumptions, not facts. Change the go-live date and ask again: a notice period that is too short in November can be long enough in December, and the result moves with it.
Where a result rests on a reading¶
Some results rest on how a term should be read rather than on a published
fact. For example, a backup copy counts as storage for a promise that data is
stored only in the EU, because storing and holding a copy are both processing
under the GDPR (Article 4). When a promise's row rests on such a reading, the
result names it in the row's interpretation_rows_used, one entry for each
reading, and your AI is told to say that the result rests on it.
The result names the reading but does not print the source behind it. The readings are drawn from published sources: the W3C Data Privacy Vocabulary, Unicode CLDR for country and EU membership, the cloud providers' own region pages, the GDPR, and the European Data Protection Board's Guidelines 05/2021 on international transfers. The result also records the version and fingerprint of the vocabulary it used.
Naming the readings lets you see which one a result used, and agree or disagree with it before you rely on it.
What you get with the result¶
- Answer sets that contain the promise. Each sealed answer set that cites a promise whose result is Conflict or Needs information, with its date and whether it cites the version of the saved answer that was checked, an earlier version, or one that could not be found. Answer sets that have since been replaced are marked. A sealed answer set shows what you prepared and approved. It does not show what a customer was sent. The list is capped: when the result says the read was truncated or not every record could be read, more answer sets may exist, so run the check again or narrow the change.
- A suggested next step. "Changes required" when any promise is in conflict. Otherwise the step is further evidence, and the summary says what was checked, including "Nothing was checked: no approved promise applies" when that is so. Kanonik never says a change is compliant.
- A replay envelope and a result fingerprint. The envelope holds the exact inputs and the point in your record the check read. Send the replay envelope back and, when every record is read successfully, you get the same result fingerprint. A new check run later reads your record as it is then, so it can differ.
- What was not checked. Migration and retirement steps are not checked, and the result says so every time. Any other kind of change is not accepted: the check takes only a vendor replacement or addition.
More help¶
Browse every article in the Help center, where you can also ask the Kanonik assistant directly. For anything else, email [email protected] and a person who works on the product answers.