Guide · Grok Bot

How to use Grok Bot for vendor risk assessment. With live data from ClauseTrail.

Grok Bot runs routines and hands work between Bots. Connect it to ClauseTrail and every Bot can read your vendors' subprocessor changes, DPA terms and AI terms, from the vendors' own documents. Here is the setup, the routines to copy, and everything it can read.

Add your vendors to ClauseTrail, create an API key, and add ClauseTrail to Grok Bot as a custom MCP server. Then give a Bot the job in plain words, for example a Monday brief of vendor changes, and save it as a routine. The Bot answers from the vendors' own documents, with the sentence each answer comes from.

Every Monday at 9, check ClauseTrail for vendor changes we haven't reviewed and post a short brief to #privacy.

Vendor Watch · routine saved

First brief is posted. Northwind CRM added Anthropic, PBC as a subprocessor for email drafting, High, object by 14 October. Parcelly's DPA now keeps data 90 days after termination instead of 30. Helio Mail's AI terms still say it doesn't train on customer data.

Pulled from ClauseTrail: your vendors' changes, DPA terms, AI terms

Illustrative thread with fictional vendors.

Step by step

Set up Grok Bot as your vendor risk analyst.

  1. 1

    Add your vendors to ClauseTrail.

    Sign up and add the vendors that handle your customers' data, or import them from a CSV. ClauseTrail checks each one's subprocessor list, DPA, privacy policy, terms and AI terms every day and keeps every version, so Grok Bot can answer what changed and when.

  2. 2

    Create an API key.

    In ClauseTrail, open Settings → API & MCP and create a key, on Pro, Team, and Business. It is shown once, it can only read, and you can revoke it at any time.

  3. 3

    Add ClauseTrail to Grok Bot.

    In Grok Bot, add a custom MCP server with the URL and header below. Every Bot on your account can then call ClauseTrail's tools.

    Grok Bot custom MCP server

    URL https://clausetrail.com/mcp Header Authorization: Bearer YOUR_KEY
  4. 4

    Give a Bot the job.

    Create a Bot with a clear role, such as Vendor Watch, and ask for what you need in plain words. The Bot picks the right ClauseTrail tool and answers from tracked data.

    “You are Vendor Watch. Use ClauseTrail to tell me which of our vendors changed their subprocessors or DPA this week, and which change we should look at first.”

  5. 5

    Save it as a routine.

    Put the task on a schedule so it runs without you. Weekly suits most teams: objection windows are often 30 days, so nothing slips past one.

    “Every Monday at 9, check ClauseTrail for vendor changes we haven't reviewed and post the high-severity ones to #privacy, each with the date to object by.”

  6. 6

    Build it into your own tools (developers).

    Add ClauseTrail as a remote MCP tool in a request to xAI's API, so your own assistant or internal tool can answer vendor questions from the same data.

    xAI Responses API tool

    { "type": "mcp", "server_label": "clausetrail", "server_url": "https://clausetrail.com/mcp", "authorization": "Bearer YOUR_KEY" }

Routines to copy

Six vendor risk routines for Grok Bot.

Monday vendor brief

One short post that tells the team what their vendors changed and what to review.

“Every Monday, list the vendor changes in ClauseTrail we haven't reviewed, highest severity first, and post them to #privacy.”

Your vendors' changes

AI provider watch

Know when a vendor starts sending your data to a model provider.

“Every week, list the AI providers our vendors use in ClauseTrail and flag any vendor that added one since last week.”

Who uses a company Your vendors' changes

New vendor assessment

The first pass of a vendor review, from the vendor's own documents.

“We're evaluating Notion. From ClauseTrail, list its subprocessors outside the EU, its breach notice and subprocessor notice, and whether it trains AI on customer data, with quotes.”

Subprocessor lists DPA terms AI terms

Concentration check

See which companies sit behind many of your vendors at once.

“On the first of each month, list the subprocessors most of our vendors share in ClauseTrail and which of them are AI providers.”

Shared subprocessors Dependency graph

Audit trail

The record an auditor asks for, without a spreadsheet.

“List every vendor change since January 1 in ClauseTrail with our decision and who made it, as a table.”

Your vendors' changes

Renewal prep

Before a renewal, know what the vendor changed during the contract.

“Our Zendesk contract renews next month. From ClauseTrail, summarize what Zendesk changed in the last year and its current DPA terms.”

A vendor's history DPA terms

Available over MCP

Everything Grok Bot can read from ClauseTrail.

10 read-only tools on ClauseTrail's MCP server. Grok Bot chooses the right one from your question, so you never call them by name.

Your vendors' changes
clausetrail_list_workspace_changes
Every change published for the vendors you track, newest first, with where it stands for your team, the decision and who made it. Filter by status, vendor or date.
Ask: “What changed at our vendors this week that we haven't reviewed?”
Who uses a company
clausetrail_find_vendors_using
Which of your vendors name a given company as a subprocessor, or every AI provider your vendors use, with where each one processes data. On Team and Business.
Ask: “Which of our vendors send data to OpenAI?”
Shared subprocessors
clausetrail_list_dependencies
The companies your vendors rely on, most shared first. A company several of your vendors use is concentration risk. On Team and Business.
Ask: “Which subprocessors do most of our vendors depend on?”
Dependency graph
clausetrail_get_workspace_dependency_graph
Your vendors and the companies behind them as nodes and edges, with the purpose and locations each list gives. On Team and Business.
Ask: “Map our vendors to the AI providers behind them.”
A vendor's history
clausetrail_get_vendor_changes
The changes published for any vendor in the catalog: subprocessors added or removed, new locations, and changes to its DPA, policies, terms and AI terms, each with a severity and the date to object by.
Ask: “What has Notion changed in the last year?”
Subprocessor lists
clausetrail_get_subprocessors
A vendor's current subprocessor list as it publishes it: each name, purpose, location and data category, and the company behind the name.
Ask: “Which of Slack's subprocessors process data outside the EU?”
DPA terms
clausetrail_get_dpa_terms
What a vendor's DPA commits to: breach notice, notice before a new subprocessor, transfer mechanisms, deletion after the contract, liability and audit rights, each with the sentence behind it.
Ask: “How fast does HubSpot report a personal data breach?”
AI terms
clausetrail_get_ai_usage_terms
What a vendor's documents say about AI: whether it trains models on customer data, which model providers get it, the opt-out and how long AI data is kept, with quotes.
Ask: “Does Zendesk train AI models on our customer data?”
A vendor's dependencies
clausetrail_get_vendor_dependencies
The companies one vendor relies on, when each first and last appeared on its lists, and which are AI providers.
Ask: “Which AI providers does Intercom rely on?”
Vendor search
clausetrail_search_vendors
Search the catalog of vendors whose subprocessor lists, DPAs and policies ClauseTrail tracks, by name, domain or category.
Ask: “Which analytics vendors does ClauseTrail track?”

Safe to hand to Grok Bot

Read-only, workspace-scoped, revocable.

Grok Bot can read ClauseTrail data, never change it. Every tool is read-only and tells the client so. A key reads only your own workspace's vendors and decisions. Keys are stored hashed, shown once, and revoked instantly from Settings → API & MCP. The same data answers as JSON in the API reference.

Questions, answered.

Can Grok Bot do vendor risk assessment?
Yes. Connect Grok Bot to ClauseTrail over MCP and your Bots can read your vendors' subprocessor lists, DPA terms, AI terms and every change ClauseTrail publishes for them, each with the sentence it comes from. Save the tasks as routines and they run on a schedule.
How do I connect Grok Bot to ClauseTrail?
Create a key in ClauseTrail under Settings → API & MCP. In Grok Bot, add a custom MCP server with the URL https://clausetrail.com/mcp and the header Authorization: Bearer followed by your key. Then ask any Bot about your vendors.
What vendor data can Grok Bot read through ClauseTrail?
Ten read-only tools: your vendors' changes with your team's decisions, which vendors use a company, shared subprocessors and the dependency graph (on Team and Business), and for any vendor in the catalog its change history, subprocessor list, DPA terms, AI terms and dependencies, plus vendor search.
Can Grok Bot change my ClauseTrail data?
No. Every ClauseTrail MCP tool is read-only and tells the client so. A key reads only your workspace's vendors and decisions, and you can revoke it at any time.
Does ClauseTrail have an API?
Yes. The same data answers as JSON from the REST API at https://clausetrail.com/v1, and the MCP server is at https://clausetrail.com/mcp. Both take an API key from Settings → API & MCP, on Pro, Team, and Business.
Does ClauseTrail track xAI's own terms?
Not yet: xAI isn't in our catalog. Write to [email protected] if you need it tracked.
Is ClauseTrail affiliated with xAI?
No. Grok and Grok Bot are products of xAI. ClauseTrail is an independent vendor monitoring tool.

Grok Bot does the work. ClauseTrail brings the facts.

Add your vendors once. ClauseTrail checks their documents every day, and Grok Bot reads the result.

Grok and Grok Bot are products of xAI. ClauseTrail is not affiliated with or endorsed by xAI.