There is a question every platform should be able to answer and most cannot: who has been shown my information?
Not who is allowed to see it. Most systems can answer that, and so could we. The harder question is who actually did, and when, and what exactly they saw. Earlier this year we found a gap between those two questions in our own platform, wrote it up as a formal problem, and started keeping a register of every surface that disclosed personal data without recording it.
This month the register reached zero. Twenty-one surfaces now write an audit record every time they show one person's data to another: which recipient, which categories of data, when, and how many records. Another forty-nine were reviewed one by one and carry a written reason, in the code itself, why no record is needed, usually because the only person being shown the data is its owner. A release check now refuses any new surface that does neither.
If you ever ask us who has seen your information, the answer is a query, not an investigation. That felt worth building before anyone asked.