Diligent chat actions need identity-bound decision receipts
Diligent says its 3rdRisk virtual assistant lets users receive alerts, complete tasks, and interact with workflows from Microsoft Teams and Slack. That convenience needs a precise return path: the governed risk record must show who acted, under which role, on what evidence and version, with what decision meaning, and whether the source system accepted the action once.
Third Party Current editorial graphic. Source material: Diligent Third-Party Risk Management; analysis and presentation by Third Party Current.
A collaboration action is not yet the governed decision
A message, alert, button press, task completion, comment, acknowledgement, sign-off, approval, and risk acceptance have different meanings. The integration contract should name which actions are merely collaboration events and which can change an authoritative third-party record. For every permitted write, preserve the tenant, channel or workspace, user identity, authenticated session, connected Diligent identity, role, delegated authority, governed object, prior state, requested transition, timestamp, and originating interaction identifier.
The source system should decide whether the transition is valid. Teams or Slack can provide a convenient interaction surface, but neither a delivered notification nor a visible success message proves that 3rdRisk accepted the action. Return and retain a source-system transaction identifier, resulting state, server time, policy or workflow version, and any rejection or exception. If the collaboration platform is unavailable, stale, or disconnected, the risk record should remain authoritative rather than being reconstructed from chat history.
Bind the actor to current authority and content
A collaboration display name or email address is not sufficient authority evidence. The operating record should connect the external account to the governed directory identity, employment or contractor relationship, assigned role, business unit, separation-of-duties rules, delegation, start and end dates, authentication requirements, and access review. Guest accounts, shared channels, renamed users, forwarded alerts, mobile sessions, and former employees need explicit treatment. A person authorized to close a task may not be authorized to approve an assessment or accept residual risk.
The action must also bind to the exact content the actor saw. Retain the vendor and service scope, assessment or issue identifier, questionnaire and response version, evidence cutoff, findings, severity, proposed action, due date, exceptions, attachments or immutable references, and decision text. If evidence changes between notification and action, require a refreshed view or route the action for confirmation. A generic approve control should not inherit meaning from a message that can be edited, deleted, expanded, or separated from its attachments.
Delivery, completion, and decision need separate receipts
Keep the outbound and return paths explicit: event created, message queued, delivered, displayed, acknowledged, task opened, action attempted, source accepted, authoritative state changed, downstream subscribers notified, and any follow-up completed. Retries must be idempotent so a delayed response, double click, webhook replay, or mobile reconnect cannot create two approvals or close two actions. Conflicting attempts should remain visible with one controlled disposition rather than allowing the last arriving message to overwrite an earlier authorized decision.
Corrections and revocations need their own events. If the wrong person acts, a delegation expires, or the underlying issue changes, preserve the original action and record who reversed or superseded it, why, under what authority, and what dependent records were reconsidered. Retention should cover the evidence needed for the risk decision without copying unnecessary confidential assessment content into broad chat histories. Security, privacy, legal hold, e-discovery, and records owners should define which system retains each artifact and for how long.
Test ambiguity, replay, and authority loss
A representative evaluation should send the same workflow to two people with different roles, a guest user, a delegated approver, and a user whose authority is removed after the alert is delivered. Edit the evidence before one person responds, expire another task, retry one action after a timeout, replay a webhook, disconnect and reconnect the integration, and attempt the same action from both Teams and Slack. Reviewers should identify which interactions were informational, which were rejected, and which single transaction changed the authoritative state.
Then export the audit history and reproduce the actor, content version, decision meaning, source-system acceptance, correction path, and downstream effect without depending on an editable chat transcript. Diligent's page establishes the described 3rdRisk workflows, sign-offs, virtual assistant, Teams and Slack integration, alerts, tasks, and issue-management positioning. It does not establish a customer's identity mapping, role authority, message delivery, action integrity, configured workflow, risk decision, remediation, control effectiveness, or outcome.
What we will watch next
Third Party Current will watch for later primary-source evidence that changes the maintained company, capability, or standards record. The next useful evidence may include implementation documentation, release details, regulator findings, corrected methods, product packaging, customer-observable workflow, or a subsequent company statement. Until then, the dated source and its stated boundary remain attached to this analysis.