Monday vendor brief
One short post that tells the team what their vendors changed and what to review.
“Every Monday, list the vendor changes in ClauseTrail we haven't reviewed, highest severity first, and post them to #privacy.”
Guide · Grok Bot
Grok Bot runs routines and hands work between Bots. Connect it to ClauseTrail and every Bot can read your vendors' subprocessor changes, DPA terms and AI terms, from the vendors' own documents. Here is the setup, the routines to copy, and everything it can read.
Add your vendors to ClauseTrail, create an API key, and add ClauseTrail to Grok Bot as a custom MCP server. Then give a Bot the job in plain words, for example a Monday brief of vendor changes, and save it as a routine. The Bot answers from the vendors' own documents, with the sentence each answer comes from.
Every Monday at 9, check ClauseTrail for vendor changes we haven't reviewed and post a short brief to #privacy.
Vendor Watch · routine saved
First brief is posted. Northwind CRM added Anthropic, PBC as a subprocessor for email drafting, High, object by 14 October. Parcelly's DPA now keeps data 90 days after termination instead of 30. Helio Mail's AI terms still say it doesn't train on customer data.
Pulled from ClauseTrail: your vendors' changes, DPA terms, AI terms
Illustrative thread with fictional vendors.
Step by step
Sign up and add the vendors that handle your customers' data, or import them from a CSV. ClauseTrail checks each one's subprocessor list, DPA, privacy policy, terms and AI terms every day and keeps every version, so Grok Bot can answer what changed and when.
In ClauseTrail, open Settings → API & MCP and create a key, on Pro, Team, and Business. It is shown once, it can only read, and you can revoke it at any time.
In Grok Bot, add a custom MCP server with the URL and header below. Every Bot on your account can then call ClauseTrail's tools.
Grok Bot custom MCP server
URL https://clausetrail.com/mcp
Header Authorization: Bearer YOUR_KEY
Create a Bot with a clear role, such as Vendor Watch, and ask for what you need in plain words. The Bot picks the right ClauseTrail tool and answers from tracked data.
“You are Vendor Watch. Use ClauseTrail to tell me which of our vendors changed their subprocessors or DPA this week, and which change we should look at first.”
Put the task on a schedule so it runs without you. Weekly suits most teams: objection windows are often 30 days, so nothing slips past one.
“Every Monday at 9, check ClauseTrail for vendor changes we haven't reviewed and post the high-severity ones to #privacy, each with the date to object by.”
Add ClauseTrail as a remote MCP tool in a request to xAI's API, so your own assistant or internal tool can answer vendor questions from the same data.
xAI Responses API tool
{ "type": "mcp",
"server_label": "clausetrail",
"server_url": "https://clausetrail.com/mcp",
"authorization": "Bearer YOUR_KEY" }
Routines to copy
One short post that tells the team what their vendors changed and what to review.
“Every Monday, list the vendor changes in ClauseTrail we haven't reviewed, highest severity first, and post them to #privacy.”
Know when a vendor starts sending your data to a model provider.
“Every week, list the AI providers our vendors use in ClauseTrail and flag any vendor that added one since last week.”
The first pass of a vendor review, from the vendor's own documents.
“We're evaluating Notion. From ClauseTrail, list its subprocessors outside the EU, its breach notice and subprocessor notice, and whether it trains AI on customer data, with quotes.”
See which companies sit behind many of your vendors at once.
“On the first of each month, list the subprocessors most of our vendors share in ClauseTrail and which of them are AI providers.”
The record an auditor asks for, without a spreadsheet.
“List every vendor change since January 1 in ClauseTrail with our decision and who made it, as a table.”
Before a renewal, know what the vendor changed during the contract.
“Our Zendesk contract renews next month. From ClauseTrail, summarize what Zendesk changed in the last year and its current DPA terms.”
Available over MCP
10 read-only tools on ClauseTrail's MCP server. Grok Bot chooses the right one from your question, so you never call them by name.
Safe to hand to Grok Bot
Grok Bot can read ClauseTrail data, never change it. Every tool is read-only and tells the client so. A key reads only your own workspace's vendors and decisions. Keys are stored hashed, shown once, and revoked instantly from Settings → API & MCP. The same data answers as JSON in the API reference.
Add your vendors once. ClauseTrail checks their documents every day, and Grok Bot reads the result.
Grok and Grok Bot are products of xAI. ClauseTrail is not affiliated with or endorsed by xAI.