How to trigger a risk review from a Google Doc
TerraTrue's Google Drive integration does two things: it creates a risk review from a Google Doc, and it uses AI to answer the risk team's intake questions directly from that document — so product and engineering don't have to go in and answer every single question manually.
Here is what that path looks like, end to end.
How does a Google Doc trigger a risk review?
By applying a label. Nothing else.
The author opens the file menu, selects labels, applies the TerraTrue label, and marks the status as ready for review. TerraTrue detects the change to the document, recognizes that the label was added, and creates a review for that product.
That's the whole submission. No second tool, no form, no intake questions to answer first.
The document itself is unchanged — a product requirement doc written for the product and engineering team, describing objectives, use cases, and what the feature does. Nothing about it was written for the review process.
What happens to your existing intake workflow?
Nothing. It runs as configured — the AI answers it instead of a person.
Say a security intake workflow opens with three questions:
- Does the new feature introduce or modify authentication mechanisms?
- Does the new feature implement or modify cryptographic methods?
- Does the new feature introduce new user roles and access controls?
A yes to any of these creates a more elevated risk with the feature being added, and may warrant more review from the security team. That conditional logic doesn't change. What changes is who answers the questions, and when.
What does the reviewer see when the launch opens?
Two things are already done before anyone touches it.
An AI document overview. TerraTrue AI automatically creates a summary of the document, which makes it much faster and easier for a risk reviewer to get the big picture about what the document is about — without reading the full spec first.
An AI-enabled intake workflow. The workflow arrives with suggested answers already in place, drawn from the contents of the document.
How does TerraTrue AI answer intake questions from a spec?
It reads the document for the substance behind each question, not for matching words.
In the demo, the workflow's three questions get three different treatments. The AI determines the feature adds no new authentication mechanism and no new cryptography — two clean negatives — but does introduce a new user role, and flags it. That third answer is the one that changes the risk level, and it's the distinction a reviewer would have spent time confirming manually.
If the answers look right, one button applies all suggestions. Submitting them notifies the risk team that a new review is waiting, already scored.
The full sequence: someone applied a label to a document they had already written, and a triaged, contextualized, risk-scored review landed in the security team's queue. Nobody filled out a form, and nobody had to remember that a review was needed.
How do you set up the Google Drive integration?
Setup takes a few steps across Google Workspace and TerraTrue — creating the integration account, publishing the TerraTrue label, sharing the Drive, and choosing where integration-created launches are filed.
Full instructions are in the Google Drive integration guide in the TerraTrue Help Center.
Frequently asked questions
Does re-editing the document create a duplicate review?
No. TerraTrue creates one launch per document. Re-editing the Doc or setting its status to Ready again will not create a second launch.
What access does TerraTrue get to our Google Drive?
Only what you share with it. The integration connects through Google OAuth 2.0 as a dedicated account you create and control, so it can only reach the shared Drives and files shared with that account. Access can be revoked at any time from that account's Google security settings.
Does this only work for security reviews?
No. The security workflow above is an example. Any intake workflow configured in TerraTrue can be AI-enabled and answered from the connected document.
What if the document doesn't answer a question?
The AI suggests answers where the document supports them. Reviewers accept, edit, or complete the rest — the suggestions are a starting point, not a final submission.
Can the review link be found from inside the Google Doc?
Yes. Once the launch is created, TerraTrue writes the launch link back into the document's TerraTrue label, so anyone working in the Doc can jump straight to the review.
Why we built it: Why risk reviews should start in the doc, not the ticket →
Set it up: TerraTrue Google Drive integration →
