Skip to content
ModulesFoundational service

Agent Trust Audit Ledger

Write every security-relevant event once, immutably, under a tenant, and keep it for as long as the customer must.

What is the record, and can it be trusted?Phase 1 · Inventory and policy

What it does

Capabilities

  • An append-only record of agent, user, session, resource, action, policy, decision, tool, model, result and risk
  • Customer-configurable retention from 30 days to seven years
  • Tenant isolation on every record, so no agent can read across the boundary
  • Event-driven telemetry that keeps the authorization path fast and synchronous while analytics runs behind it

What it leaves behind

Evidence produced

  • The evidence every other module cites
  • A retention position the auditor can check

The events written to the ledger

These are the names a customer sees in their own SIEM, so the console and the export speak the same vocabulary.

agent.action.requestedagent.action.allowedagent.action.deniedagent.tool.calledagent.data.accessedagent.credential.issuedagent.behavior.anomalyagent.policy.violationagent.version.changedagent.incident.created

Specification

Where this is specified

2 blueprint pages carry the specification for this module.

13 modules and services make up the platform. See how they fit together.