Processes/compliance — filings, taxes, and staying compliantcompliance
Start SOC 2 Type I — compliance processStart SOC 2 Type I
Begin SOC 2 Type I compliance journey using Vanta, set up policies, and begin evidence collection.
Vanta API supports test monitoring and evidence collection. Policy creation and auditor engagement need human input.
Current agent ceiling
An agent can run 3 of 9 steps — 3 of them behind a human approval gate ⏸
⚡ Closable with today’s market (2 — via Browser Automation for Agents, Workflow Automation): Create Vanta account (computer-use candidate — a browser agent can drive this deterministic web flow); Employee security training (a workflow with webhooks/polling watches this so no human has to)
Irreducibly human (3): Review and customize policies (needs a human); Engage auditor (needs a human); Complete audit (needs a human)
No workaround yet (1): Connect integrations (manual form/portal — no API path)
How it runs
Route-coded block flow: emerald = agent, amber = manual form/portal, red = needs a human. ⏸ approval gate · ⏳ async wait.
01Create Vanta account
manual form⚡ agentic workaround: computer-use candidate — a browser agent can drive this deterministic web flow — Steel, top of Browser Automation for Agents → · assisted, not autonomous — a human supervises; verify the portal’s terms allow automation
02Connect integrations
manual form1 API call
- OAuth connections for AWS, GitHub, etc.
03Generate security policies
agent1 API call
- GET /v1/policy_templates
04Review and customize policies
human05Configure automated tests
agent1 API call
- PUT /v1/tests/{id}/configuration
runs in parallel · 2
06Remediate failing tests
agent07Employee security training
human⚡ agentic workaround: a workflow with webhooks/polling watches this so no human has to — n8n, top of Workflow Automation →
08Engage auditor
human09Complete audit
humanContext the agent needs first: company tech stack (from the founder) · gusto.employees · company data handling (from the founder)
The market options
Each role resolves against its arena’s live leaderboard — the default is the process’s canonical vendor, alternatives ranked by agent-readiness.
GitHubdefault71/100 agent-ready
GitLab54/100 agent-ready
Gitea34/100 agent-ready
Bitbucket19/100 agent-ready