Skip to content
ConsoleEvidence

What the estate on this site actually wrote down

The ledger is the product's answer to "prove it" — to an auditor, to a regulator, to the person asking what the agent did before the money moved. Every line below is derived from a record the console already shows: the decisions taken on each agent, and the status and credentials of each identity. Nothing here was written by hand, so a ledger entry and the page it came from cannot disagree.

96 events, from 6 agents and 7 machine identities, using 14 of the 24 event types the ledger defines — the same names that leave for a customer's own SIEM over the connector framework. The other 10 are listed at the bottom rather than quietly left out — a demo estate this size does not exercise a whole product, and saying which parts it misses is worth more than a stream that appears to cover everything.

96 events

What the agents did

Ordered by the clock the estate recorded, across all 6 agents, so a reader sees what a single afternoon of governed activity looks like rather than one agent at a time. The rule underneath a line is the policy that decided it.

  • 09:12:00agent.action.requestedHR Onboarding Assistant · read_policy_document on m365:handbookpeople.read.policy
  • 09:12:00agent.action.allowedHR Onboarding Assistant · read_policy_document — allowpeople.read.policy
  • 09:12:00agent.data.accessedHR Onboarding Assistant · m365:handbook via read_policy_documentpeople.read.policy
  • 09:12:44agent.action.requestedHR Onboarding Assistant · read_compensation on hris:band-tabledata.class.employee-compensation
  • 09:12:44agent.action.deniedHR Onboarding Assistant · read_compensation — denydata.class.employee-compensation
  • 09:41:02agent.action.requestedCustomer Support Automation · read_contact on salesforce:bulkobserve-only · not yet enforced
  • 09:41:02agent.action.allowedCustomer Support Automation · read_contact — allowobserve-only · not yet enforced
  • 09:41:02agent.data.accessedCustomer Support Automation · salesforce:bulk via read_contactobserve-only · not yet enforced
  • 09:41:40agent.action.requestedCustomer Support Automation · export_contacts on salesforce:bulkobserve-only · not yet enforced
  • 09:41:40agent.action.allowedCustomer Support Automation · export_contacts — allowobserve-only · not yet enforced
  • 09:41:40agent.data.accessedCustomer Support Automation · salesforce:bulk via export_contactsobserve-only · not yet enforced
  • 10:01:14agent.incident.createdSales Outreach Agent · INC-2209 · Bulk export attempted twice, then contained
  • 10:01:21agent.action.requestedSales Outreach Agent · read_contact on salesforce:248 recordsrevenue.read.contacts
  • 10:01:21agent.action.allowedSales Outreach Agent · read_contact — allowrevenue.read.contacts
  • 10:01:21agent.data.accessedSales Outreach Agent · salesforce:248 records via read_contactrevenue.read.contacts
  • 10:01:28agent.action.requestedSales Outreach Agent · send_email on mcp:emailmcp.pending-approval
  • 10:01:28agent.action.deniedSales Outreach Agent · send_email — restrictmcp.pending-approval
  • 10:01:35agent.action.requestedSales Outreach Agent · export_contacts on salesforce:bulkdata.egress.bulk-export
  • 10:01:35agent.action.deniedSales Outreach Agent · export_contacts — denydata.egress.bulk-export
  • 10:01:36agent.action.requestedSales Outreach Agent · export_contacts on reporting-apidata.egress.bulk-export
  • 10:01:36agent.action.deniedSales Outreach Agent · export_contacts — denydata.egress.bulk-export
  • 10:01:37agent.action.requestedSales Outreach Agent · session on agentcontainment.quarantine
  • 10:01:37agent.action.deniedSales Outreach Agent · session — denycontainment.quarantine
  • 11:20:04agent.action.requestedAccounts Payable Agent · read_invoice on erp:inv-99214finance.read.invoices
  • 11:20:04agent.action.allowedAccounts Payable Agent · read_invoice — allowfinance.read.invoices
  • 11:20:04agent.data.accessedAccounts Payable Agent · erp:inv-99214 via read_invoicefinance.read.invoices
  • 11:20:09agent.action.requestedAccounts Payable Agent · match_purchase_order on erp:po-4471finance.draft
  • 11:20:09agent.action.allowedAccounts Payable Agent · match_purchase_order — allowfinance.draft
  • 11:20:09agent.data.accessedAccounts Payable Agent · erp:po-4471 via match_purchase_orderfinance.draft
  • 11:20:33agent.action.requestedAccounts Payable Agent · queue_payment_run on erp:run-2209finance.level-3.human-approval
  • 11:20:33agent.action.allowedAccounts Payable Agent · queue_payment_run — approvefinance.level-3.human-approval
  • 11:31:50agent.action.requestedAccounts Payable Agent · initiate_payout on erp:run-2209finance.level-4.prohibited
  • 11:31:50agent.action.deniedAccounts Payable Agent · initiate_payout — denyfinance.level-4.prohibited
  • 14:02:11agent.action.requestedSupplier Risk Agent · read_supplier on supplier:48120procurement.read.suppliers
  • 14:02:11agent.action.allowedSupplier Risk Agent · read_supplier — allowprocurement.read.suppliers
  • 14:02:11agent.data.accessedSupplier Risk Agent · supplier:48120 via read_supplierprocurement.read.suppliers
  • 14:02:14agent.action.requestedSupplier Risk Agent · lookup_credit_rating on mcp:credit-datamcp.approved-tools
  • 14:02:14agent.action.allowedSupplier Risk Agent · lookup_credit_rating — allowmcp.approved-tools
  • 14:02:14agent.tool.calledSupplier Risk Agent · credit-data · lookup_credit_ratingmcp.approved-tools
  • 14:02:14agent.data.accessedSupplier Risk Agent · mcp:credit-data via lookup_credit_ratingmcp.approved-tools
  • 14:02:31agent.action.requestedSupplier Risk Agent · create_supplier_alert on supplier:48120procurement.write.alerts
  • 14:02:31agent.action.allowedSupplier Risk Agent · create_supplier_alert — allowprocurement.write.alerts
  • 14:07:52agent.action.requestedSupplier Risk Agent · change_bank_details on supplier:48120purpose.scope · level-4
  • 14:07:52agent.action.deniedSupplier Risk Agent · change_bank_details — denypurpose.scope · level-4
  • 14:08:03agent.action.requestedSupplier Risk Agent · export_report on mcp:credit-datamcp.drift.hold
  • 14:08:03agent.action.deniedSupplier Risk Agent · export_report — restrictmcp.drift.hold
  • 15:44:02agent.action.requestedCode Review Agent · read_repository on github:platformengineering.read.source
  • 15:44:02agent.action.allowedCode Review Agent · read_repository — allowengineering.read.source
  • 15:44:02agent.data.accessedCode Review Agent · github:platform via read_repositoryengineering.read.source
  • 15:44:31agent.action.requestedCode Review Agent · comment_pull_request on github:pr-882engineering.write.comments
  • 15:44:31agent.action.allowedCode Review Agent · comment_pull_request — allowengineering.write.comments
  • 15:45:10agent.action.requestedCode Review Agent · run_shell on ci-runnertool.level-4.prohibited
  • 15:45:10agent.action.deniedCode Review Agent · run_shell — denytool.level-4.prohibited

What the identities and their credentials did

An identity's history is mostly not a stream of actions — it is the state of a credential and who is answerable for it. These carry the estate's own recency rather than a clock time, because that is what an identity provider actually reports.

What this estate has not produced

These event types exist and nothing above emitted one. An agent version never changed here, no credential was revoked, and nothing was quarantined — so no line claims otherwise. A ledger that can only show findings cannot be used to establish that something did not happen, which is most of what an auditor came to ask.

agent.credential.issuedagent.behavior.anomalyagent.policy.violationagent.version.changedmachine_identity.discoveredmachine_identity.permission_changedmachine_identity.risk_changedcredential.revokedauthentication.anomalyidentity.quarantined