cx-data-flow-reviewlisted
Install: claude install-skill rulebase-co/rulebase-skills
# Where support data actually goes
Every support operation has a documented set of data flows and a real one, and they
diverge. The documented set was written at a point in time; the real one grows every time
someone connects an integration, trials a tool, or adds an AI feature that was already in
the product they use.
The gap matters because the documented set is what the privacy notice, the processing
records and the transfer assessments are based on. **A processor nobody registered is a
processor nobody assessed.**
## Build the real map from the systems, not from the register
Start from where the data is, not from what the register claims:
- **The helpdesk's own integrations list.** Every connected app is a potential recipient.
Check what each one can actually read — most integrations request broad scopes and use a
fraction of them.
- **Marketplace and plugin installs**, including ones installed for a trial and never
removed.
- **Outbound webhooks and API consumers.**
- **The AI features inside tools you already pay for.** Summarisation, sentiment, reply
suggestions, ticket classification. **These are the most commonly unregistered flows**,
because they arrive as a product update rather than as a procurement decision — often
enabled by default.
- **Analytics and BI**, and where those tools are hosted.
- **Transcription and voice** vendors.
- **Survey tools**, which see the conversation context alongside the response.
- **Vendor and BPO systems**, and their