Agent Trust Forensics
Run every agent with a black-box recorder, so an incident is reconstructed from evidence rather than reconstructed from memory.
What it does
Capabilities
- A complete event trail per session: model and version, human user, tools, data, decisions, approvals, secrets and destinations
- An incident timeline to the second, including the actions policy refused
- Session replay of observable requests, tool calls, data access and results
- Blast radius across systems, records, credentials, downstream actions and affected customers
- A kill switch that revokes tokens, closes sessions, disconnects MCP and preserves evidence
What it leaves behind
Evidence produced
- A defensible timeline for a security review
- Preserved evidence that survives the containment that follows it
Specification
Where this is specified
4 blueprint pages carry the specification for this module.
Agent Activity Recorder & Replay
The activity recorder is the black box for agent behavior. It reconstructs sequence, context and authority so an incident responder or auditor can understand how a result occurred across multiple tools and agents.
FORENSICS →
Incident Response
Agent incidents can span identity, model, tool, data and business systems. Agent Trust Cloud should package the relevant context into a case workflow and automate containment actions while keeping irreversible decisions under explicit policy.
SOC VALUE →
Kill Switch, Quarantine & Containment
Customers need confidence that they can stop an agent immediately. The kill switch must be fast, scoped and resilient, with options ranging from one session to an entire agent class or tool integration.
PROMISE →
Forensics & Evidence Chain
For high-stakes investigations, evidence needs integrity, chronology and traceability. The platform should maintain a tamper-evident chain that shows what was observed, what policy was active, who approved actions and what downstream system returned.
TRUST →
13 modules and services make up the platform. See how they fit together.