Agent Trust Audit Ledger
Write every security-relevant event once, immutably, under a tenant, and keep it for as long as the customer must.
What it does
Capabilities
- An append-only record of agent, user, session, resource, action, policy, decision, tool, model, result and risk
- Customer-configurable retention from 30 days to seven years
- Tenant isolation on every record, so no agent can read across the boundary
- Event-driven telemetry that keeps the authorization path fast and synchronous while analytics runs behind it
What it leaves behind
Evidence produced
- The evidence every other module cites
- A retention position the auditor can check
The events written to the ledger
These are the names a customer sees in their own SIEM, so the console and the export speak the same vocabulary.
Specification
Where this is specified
2 blueprint pages carry the specification for this module.
Core Data Model & Event Schema
The data model is a strategic asset. If Agent Trust Cloud normalizes agent identity, delegation, tools, resources and actions across vendors, every downstream module—policy, risk, audit, FinOps and incident response—gets stronger. Avoid vendor-specific event models leaking into the core domain.
DATA MOAT →
Observability & Telemetry
Observability must capture what agents attempted, why controls responded, and what ultimately happened. The telemetry system should serve security operations without becoming an uncontrolled warehouse of sensitive prompts and business data.
OPERATING PRINCIPLE →
13 modules and services make up the platform. See how they fit together.