Skip to content

Platform

A complete record of AI activity

Search the record by person, system, policy or outcome. Every entry is sealed at the moment the decision is made and cannot be edited afterwards.

The record

Entries

240

Editable

0

after sealing

25 of them are refusals or holds. A trail of only successes cannot answer what an agent tried to do.

Why this is not a log

Sealed when the decision is made, and chained to what came before.

Permissions are a claim about who can edit a record. A chain is a property that makes an edit detectable even by someone who could make it — and that difference is the one an auditor actually cares about.

Sealed at decision time
Written as part of the decision, before the response returns. Not shipped to a collector that might be behind, so there is no window where the action has happened and the record does not say so.
Chained, not just protected
Each entry carries the digest of the one before it. Permissions are a claim about who can edit; a chain makes an edit detectable even by someone who could make it.
Names the version in force
Which version of which policy decided this. An entry from before a rule changed stays explainable afterwards, which is the whole point of writing it down.
Contains the refusals
Denials, holds and expiries are records too. A trail of only successes cannot answer the first question anyone asks after an incident, which is what the agent tried to do.

The record includes what was refused.

25 of the 240 entries in the sample estate are holds or denials. Teams are often surprised to want this, right up until the first time somebody asks what an agent attempted — at which point a trail of successes turns out to be the wrong artefact entirely.

A refusal is also the more informative entry. An authorized action tells you the system worked; a pattern of refusals tells you something is reaching for what it was never granted.

The evidence ledger

Every decision, with the record before it named.

Read the Chains-to column against the Digest column of the row beneath. Each entry names its predecessor, which is what turns a set of records into a sequence that cannot be quietly shortened.

Evidence ledger

240 entries · none editable
Recent sealed records from the sample estate: the record identifier, what it was for, its subject, what was decided, the policy version in force, the digest of the preceding record, and its own digest.
RecordWhat it was forSubjectDecidedPolicy versionChains toDigest
EV-7740adjust.stockSKU-36771Decision: Authorizedwrite.window v2f113ccde602b8aa688e42829
EV-7739read.contractMSA-53043Decision: Authorizedpii.export_block v11e3b7375dd66cc3307766ab4b
EV-7738adjust.stockSKU-57815Decision: Authorizedwrite.window v29957a40165f7b34da714573e
EV-7737update.recordACC-84125Decision: Authorizedwrite.window v2497d8d4dfda520db948841aa
EV-7736close.ticketTKT-82747Decision: Authorizedwrite.window v20e2386e829ed773e9be89f8f
EV-7735close.ticketTKT-7639Decision: Authorizedwrite.window v21c310ca203360b46589958bd

What a broken chain looks like.

Removing an entry does not leave a gap — it leaves a record whose stated predecessor does not exist, and every entry after it fails to verify. Editing one changes its digest, so the entry after it now points at something that no longer matches. Either way the break is located precisely, at the entry where it happened.

That precision is the useful part. A tamper-evident trail that only tells you something is wrong somewhere is barely better than none; one that names the entry gives an investigation a starting point.

Entries

240

24 hours, sample estate

Refusals recorded

25

holds and denials

Policies referenced

8

each by version

Editable after sealing

0

by anyone

IllustrativeThe OpsAI sample estate. Open any record as a trace.

Evidence

4 records
sealed on writeset per record type
Evidence records, newest first, each chained to the record before it
SeqRecordActionDecisionPolicyPreviousThis record
7737EV-7737update.recordDecision: Authorizedwrite.window v2497d8d4d20db948841aad218
7738EV-7738adjust.stockDecision: Authorizedwrite.window v29957a401b34da714573e047c
7739EV-7739read.contractDecision: Authorizedpii.export_block v11e3b7375dc3307766ab4bf592
7740EV-7740adjust.stockDecision: Authorizedwrite.window v2f113ccde8aa688e428297eec

Where to start

Ask what your current trail would say about last Tuesday.

Specifically: which rule was in force, who authorized it, and whether anything was refused. If assembling that takes more than a few minutes across more than one system, that is the gap this closes.