What the estate on this site actually wrote down
The ledger is the product's answer to "prove it" — to an auditor, to a regulator, to the person asking what the agent did before the money moved. Every line below is derived from a record the console already shows: the decisions taken on each agent, and the status and credentials of each identity. Nothing here was written by hand, so a ledger entry and the page it came from cannot disagree.
96 events, from 6 agents and 7 machine identities, using 14 of the 24 event types the ledger defines — the same names that leave for a customer's own SIEM over the connector framework. The other 10 are listed at the bottom rather than quietly left out — a demo estate this size does not exercise a whole product, and saying which parts it misses is worth more than a stream that appears to cover everything.
96 events
What the agents did
Ordered by the clock the estate recorded, across all 6 agents, so a reader sees what a single afternoon of governed activity looks like rather than one agent at a time. The rule underneath a line is the policy that decided it.
- 09:12:00agent.action.requestedHR Onboarding Assistant · read_policy_document on m365:handbookpeople.read.policy
- 09:12:00agent.action.allowedHR Onboarding Assistant · read_policy_document — allowpeople.read.policy
- 09:12:00agent.data.accessedHR Onboarding Assistant · m365:handbook via read_policy_documentpeople.read.policy
- 09:12:44agent.action.requestedHR Onboarding Assistant · read_compensation on hris:band-tabledata.class.employee-compensation
- 09:12:44agent.action.deniedHR Onboarding Assistant · read_compensation — denydata.class.employee-compensation
- 09:41:02agent.action.requestedCustomer Support Automation · read_contact on salesforce:bulkobserve-only · not yet enforced
- 09:41:02agent.action.allowedCustomer Support Automation · read_contact — allowobserve-only · not yet enforced
- 09:41:02agent.data.accessedCustomer Support Automation · salesforce:bulk via read_contactobserve-only · not yet enforced
- 09:41:40agent.action.requestedCustomer Support Automation · export_contacts on salesforce:bulkobserve-only · not yet enforced
- 09:41:40agent.action.allowedCustomer Support Automation · export_contacts — allowobserve-only · not yet enforced
- 09:41:40agent.data.accessedCustomer Support Automation · salesforce:bulk via export_contactsobserve-only · not yet enforced
- 10:01:14agent.incident.createdSales Outreach Agent · INC-2209 · Bulk export attempted twice, then contained
- 10:01:21agent.action.requestedSales Outreach Agent · read_contact on salesforce:248 recordsrevenue.read.contacts
- 10:01:21agent.action.allowedSales Outreach Agent · read_contact — allowrevenue.read.contacts
- 10:01:21agent.data.accessedSales Outreach Agent · salesforce:248 records via read_contactrevenue.read.contacts
- 10:01:28agent.action.requestedSales Outreach Agent · send_email on mcp:emailmcp.pending-approval
- 10:01:28agent.action.deniedSales Outreach Agent · send_email — restrictmcp.pending-approval
- 10:01:35agent.action.requestedSales Outreach Agent · export_contacts on salesforce:bulkdata.egress.bulk-export
- 10:01:35agent.action.deniedSales Outreach Agent · export_contacts — denydata.egress.bulk-export
- 10:01:36agent.action.requestedSales Outreach Agent · export_contacts on reporting-apidata.egress.bulk-export
- 10:01:36agent.action.deniedSales Outreach Agent · export_contacts — denydata.egress.bulk-export
- 10:01:37agent.action.requestedSales Outreach Agent · session on agentcontainment.quarantine
- 10:01:37agent.action.deniedSales Outreach Agent · session — denycontainment.quarantine
- 11:20:04agent.action.requestedAccounts Payable Agent · read_invoice on erp:inv-99214finance.read.invoices
- 11:20:04agent.action.allowedAccounts Payable Agent · read_invoice — allowfinance.read.invoices
- 11:20:04agent.data.accessedAccounts Payable Agent · erp:inv-99214 via read_invoicefinance.read.invoices
- 11:20:09agent.action.requestedAccounts Payable Agent · match_purchase_order on erp:po-4471finance.draft
- 11:20:09agent.action.allowedAccounts Payable Agent · match_purchase_order — allowfinance.draft
- 11:20:09agent.data.accessedAccounts Payable Agent · erp:po-4471 via match_purchase_orderfinance.draft
- 11:20:33agent.action.requestedAccounts Payable Agent · queue_payment_run on erp:run-2209finance.level-3.human-approval
- 11:20:33agent.action.allowedAccounts Payable Agent · queue_payment_run — approvefinance.level-3.human-approval
- 11:31:50agent.action.requestedAccounts Payable Agent · initiate_payout on erp:run-2209finance.level-4.prohibited
- 11:31:50agent.action.deniedAccounts Payable Agent · initiate_payout — denyfinance.level-4.prohibited
- 14:02:11agent.action.requestedSupplier Risk Agent · read_supplier on supplier:48120procurement.read.suppliers
- 14:02:11agent.action.allowedSupplier Risk Agent · read_supplier — allowprocurement.read.suppliers
- 14:02:11agent.data.accessedSupplier Risk Agent · supplier:48120 via read_supplierprocurement.read.suppliers
- 14:02:14agent.action.requestedSupplier Risk Agent · lookup_credit_rating on mcp:credit-datamcp.approved-tools
- 14:02:14agent.action.allowedSupplier Risk Agent · lookup_credit_rating — allowmcp.approved-tools
- 14:02:14agent.tool.calledSupplier Risk Agent · credit-data · lookup_credit_ratingmcp.approved-tools
- 14:02:14agent.data.accessedSupplier Risk Agent · mcp:credit-data via lookup_credit_ratingmcp.approved-tools
- 14:02:31agent.action.requestedSupplier Risk Agent · create_supplier_alert on supplier:48120procurement.write.alerts
- 14:02:31agent.action.allowedSupplier Risk Agent · create_supplier_alert — allowprocurement.write.alerts
- 14:07:52agent.action.requestedSupplier Risk Agent · change_bank_details on supplier:48120purpose.scope · level-4
- 14:07:52agent.action.deniedSupplier Risk Agent · change_bank_details — denypurpose.scope · level-4
- 14:08:03agent.action.requestedSupplier Risk Agent · export_report on mcp:credit-datamcp.drift.hold
- 14:08:03agent.action.deniedSupplier Risk Agent · export_report — restrictmcp.drift.hold
- 15:44:02agent.action.requestedCode Review Agent · read_repository on github:platformengineering.read.source
- 15:44:02agent.action.allowedCode Review Agent · read_repository — allowengineering.read.source
- 15:44:02agent.data.accessedCode Review Agent · github:platform via read_repositoryengineering.read.source
- 15:44:31agent.action.requestedCode Review Agent · comment_pull_request on github:pr-882engineering.write.comments
- 15:44:31agent.action.allowedCode Review Agent · comment_pull_request — allowengineering.write.comments
- 15:45:10agent.action.requestedCode Review Agent · run_shell on ci-runnertool.level-4.prohibited
- 15:45:10agent.action.deniedCode Review Agent · run_shell — denytool.level-4.prohibited
What the identities and their credentials did
An identity's history is mostly not a stream of actions — it is the state of a credential and who is answerable for it. These carry the estate's own recency rather than a clock time, because that is what an identity provider actually reports.
- 4 minutes agocredential.createdQeluntra Supplier Workload · managed-identity · Qeluntra Supplier API · read
- 4 minutes agocredential.usedQeluntra Supplier Workload · cred-mi-0412 last used
- Continuous — platform-managedcredential.rotatedQeluntra Supplier Workload · cred-mi-0412 · Qeluntra Supplier API · read
- 4 minutes agopermission.grantedQeluntra Supplier Workload · 6 on Qeluntra Supplier API via Direct role
- 4 minutes agopermission.grantedQeluntra Supplier Workload · 3 on PostgreSQL · procurement via Direct role
- 1 minute agocredential.createdProduction Billing Service · api-key · Billing API · full
- 1 minute agocredential.usedProduction Billing Service · cred-sp-1188 last used
- 1 minute agocredential.createdProduction Billing Service · client-secret · Microsoft Graph · application
- 2 hours agocredential.usedProduction Billing Service · cred-sp-1188b last used
- 392 days agocredential.rotatedProduction Billing Service · cred-sp-1188b · Microsoft Graph · application
- 1 minute agopermission.grantedProduction Billing Service · 34 on Billing API via Direct role
- 1 minute agopermission.grantedProduction Billing Service · 61 on Microsoft Graph via Group membership
- 1 minute agopermission.grantedProduction Billing Service · 37 on AWS · account 4471 via Cross-account trust
- 26 minutes agopermission.revokedGitHub Actions Deploy · Permissions withdrawn after a finding.
- 26 minutes agocredential.createdGitHub Actions Deploy · access-key · AWS · deployment role
- 26 minutes agocredential.usedGitHub Actions Deploy · cred-gh-2733 last used
- 214 days agocredential.rotatedGitHub Actions Deploy · cred-gh-2733 · AWS · deployment role
- 26 minutes agopermission.grantedGitHub Actions Deploy · 48 on AWS · ECS via Direct role
- 26 minutes agopermission.grantedGitHub Actions Deploy · 12 on AWS · S3 artefacts via Resource policy
- 26 minutes agopermission.grantedGitHub Actions Deploy · 9 on AWS · IAM via Group membership
- 9 minutes agocredential.createdSalesforce Integration Account · client-secret · Salesforce API · read, write, export
- 9 minutes agocredential.usedSalesforce Integration Account · cred-sf-3901 last used
- 168 days agocredential.rotatedSalesforce Integration Account · cred-sf-3901 · Salesforce API · read, write, export
- 9 minutes agopermission.grantedSalesforce Integration Account · 22 on Salesforce · Contacts via Direct role
- 9 minutes agopermission.grantedSalesforce Integration Account · 8 on Salesforce · Reports via Group membership
- 9 minutes agopermission.grantedSalesforce Integration Account · 4 on Salesforce · Bulk export via Resource policy
- 311 days agomachine_identity.owner_missingLegacy Warehouse ETL · No business owner of record. It keeps authenticating regardless.
- 311 days agomachine_identity.dormantLegacy Warehouse ETL · No authentication in the review window, and still able to.
- 311 days agocredential.createdLegacy Warehouse ETL · db-password · Snowflake · warehouse admin
- 311 days agocredential.usedLegacy Warehouse ETL · cred-etl-4010 last used
- 311 days agopermission.grantedLegacy Warehouse ETL · 71 on Snowflake · warehouse via Direct role
- 311 days agopermission.grantedLegacy Warehouse ETL · 18 on Snowflake · customer schema via Direct role
- 2 minutes agocredential.createdInvoice Parser Workload · spiffe-svid · spiffe://agenttrustcloud.com/prod/finance/invoice-parser
- 2 minutes agocredential.usedInvoice Parser Workload · cred-k8s-5266 last used
- Continuous — rotated hourlycredential.rotatedInvoice Parser Workload · cred-k8s-5266 · spiffe://agenttrustcloud.com/prod/finance/invoice-parser
- 2 minutes agopermission.grantedInvoice Parser Workload · 9 on ERP · invoices via Direct role
- 2 minutes agopermission.grantedInvoice Parser Workload · 4 on PostgreSQL · finance via Direct role
- 2 days agocredential.expiringOnboarding Document Reader · A credential lapses soon; something stops working when it does.
- 2 days agocredential.createdOnboarding Document Reader · certificate · Microsoft Graph · Files.Read.All
- 2 days agocredential.usedOnboarding Document Reader · cred-m365-6140 last used
- 353 days agocredential.rotatedOnboarding Document Reader · cred-m365-6140 · Microsoft Graph · Files.Read.All
- 2 days agopermission.grantedOnboarding Document Reader · 5 on Microsoft Graph · Files via Direct role
- 2 days agopermission.grantedOnboarding Document Reader · 6 on Microsoft Graph · Mail via Group membership
What this estate has not produced
These event types exist and nothing above emitted one. An agent version never changed here, no credential was revoked, and nothing was quarantined — so no line claims otherwise. A ledger that can only show findings cannot be used to establish that something did not happen, which is most of what an auditor came to ask.