Layer 06/08
Audit & Compliance
An immutable, tamper-evident record of every action — by every agent and every human operator.
The problem
Regulated organisations cannot deploy what they cannot prove. When something goes wrong, or an auditor asks, teams need a complete, trustworthy account of what happened and who — or what — did it.
audit request
Who approved this transaction?
unknownWhat data did the agent access?
unknownCan this log be verified as unaltered?
unknownCan you export this as evidence?
unknown4 questions asked
0 answeredWhat it does
Capture every agent decision, tool call, data access, model call, and human approval as an immutable event.
Tamper-evident, cryptographically verifiable logs that cannot be silently altered.
Map activity to controls for SOC 2, ISO 27001, GDPR, HIPAA, DORA, the EU AI Act, and internal policy.
Export evidence and generate audit-ready reports on demand.
How it connects
This layer records the output of every other layer — creation, workflows, firewall decisions, access events, and HITL reviews — into one defensible timeline.