{
  "summary": "Vendor risk can now be driven by what Allod SWG actually observes flowing to a system, not just manually-entered RoPA data. Each system gets an approved set of business-data tags (PII, FIN, IP, customer data, CRM) and an enforcement mode (silent audit, or notify the owner), compared automatically against tags SWG reports observing for that vendor; a mismatch opens a Risk Register entry the same way other automated compliance checks already do, and clears itself once the approved set is widened or the observed traffic stops. Separately, each business-data tag can now be mapped to one of your existing data classification levels from the Classification page - left unassigned by default, so nothing changes in how a system's sensitivity is classified until an admin explicitly makes that call. Owner Name and Owner Email fields across Systems and Risks, and the admin-group field in Settings > Auth, now offer autocomplete suggestions from your synced IdP directory."
}
