Checklist

Audit-evidence checklist

What a reviewer actually asks for, and the artifact that satisfies each ask.

Why it exists

Teams prepare for audits by writing policy. Reviewers ask for evidence. The gap between those two is where examinations go badly.

What it contains

01

The reconstruction test — can you show what a specific agent did on a specific date and why it was permitted

02

Authority evidence — the grant, its scope, and the human who issued it

03

Policy evidence — which policy version evaluated the action, and its decision record

04

Change evidence — model and prompt versions in effect at the time of the action

05

Oversight evidence — what a human reviewer saw, and how long they had to see it

06

Retention mapping — how long each class of evidence must survive, per regime

07

Third-party evidence — contracts, audit rights, version notices and tested exit paths

08

Containment evidence — circuit-breaker triggers, kill-path exercise and incident ownership

No email required, and nothing is recorded when you download. Use it, adapt it, argue with it — attribution is welcome, not a condition.

Checklist · v1.0 · 22 July 2026

Evidence register

ControlQuestionEvidence that closes itCommon false positive
System boundaryCan you name the agent, owner, purpose, action classes, tools, models and production environments?Approved inventory record with version and review dateThe inventory lists a chatbot but not the actions or tools it can invoke
Human authorityWhich accountable human or body granted each action class?Grant record linked to agent and action classA product owner is named but no authority was recorded
Delegation chainCan authority be traced from principal through services to the executing agent?Machine-readable delegation chainThe service account is treated as the authority
ScopeAre resource, value, rate, data-classification and jurisdiction limits explicit?Bounded grant with enforceable constraintsLimits exist only in a prompt or policy document
ExpiryDoes authority expire or require periodic re-approval?Validity window and review eventAccess is granted once and remains indefinitely
Policy decisionWhich policy version evaluated the action before it took effect?Decision record with policy identifier and resultOnly the deployed application version is logged
EnforcementCould the policy layer refuse the exact action in flight?Allow/deny test and blocked-action evidenceMonitoring alerts after the system of record changes
Source of truthWere material commitments checked against an authoritative source?Lookup result, source version and comparison outcomeThe model was prompted to follow policy
Action recordWhat happened, to which resource, when and with what outcome?Immutable action event with correlation identifierA chat transcript is the only record
InputsCan the material inputs and retrieved evidence be reconstructed?Input references, retrieval results and hashesContext disappeared when the session ended
Model and promptWhich model, prompt, tool and configuration versions were effective?Pinned identifiers on the action recordA moving provider alias such as latest
Human oversightWhat did the approver see, decide and have time to assess?Presented context, decision, identity and timestampA workflow status says approved without the reviewed material
ValidationDid testing cover authority, tools, failure containment and customer impact?Independent validation plan, results and limitationsOnly model accuracy or red-team prompts were tested
Change triggerWhich changes force revalidation?Trigger matrix covering model, prompt, tool, data and policy changesProvider updates do not create an internal event
MonitoringAre thresholds tied to action risk and business impact?Metric definitions, thresholds, alerts and disposition recordsA generic quality dashboard with no action context
ContainmentCan a bad agent be stopped before more actions land?Tested circuit breaker and kill-path exerciseThe response is to deploy a code fix
Third partiesDo contracts provide visibility, audit rights, version notice and exit?Executed clauses and tested replacement or cease-use pathA vendor security page is treated as evidence
Incident responseWho owns an agent-caused event and how is evidence preserved?Runbook, severity model, contacts and exercise recordThe AI team assumes security will handle it
RetentionDoes each evidence class survive for the applicable regulatory period?Retention schedule mapped to systems and legal holdsDefault application-log retention is assumed sufficient
Reconstruction testCan an independent reviewer reproduce why one historical action was permitted?Completed sample with evidence links and reviewer sign-offThe team explains what should have happened

How to use it

  1. Select one material historical agent action.
  2. Link evidence; do not paste explanations into the evidence column.
  3. Mark missing, indirect or unreconstructible evidence as a gap.
  4. Have someone outside the delivery team perform the reconstruction test.
  5. Record the remediation owner, due date and retest result.

Built from public standards and general practice. The instruments cited in this artifact are checked against their primary sources on an ongoing basis. Instruments move — several cited here changed inside the last year — so verify against the source before you rely on one. If you find something stale, tell me and I will correct it.

Related: the other artifacts · the diagnostic.

Next step

Want this applied to your estate?

These artifacts are general by design — and they are the method behind the Agent Estate Review: two to three weeks establishing what is actually running, what each thing is permitted to do, and where you could not evidence it if you were asked next week. You have just read how it works.