AI agent audit trails
An AI agent audit trail is the record of who asked an agent to do something, what it relied on, what it proposed, who approved it, and what actually happened. To be worth anything to an auditor it has to be written in the same transaction as the change it describes, chained so that any alteration is detectable, and verifiable by someone other than the system that wrote it.
What to record
- Who asked, for which company, and the request itself.
- What the agent consulted — by reference, so the record does not become a copy of your data.
- Each action it proposed, and the decision on it: allowed, held for approval, or refused — with the reason.
- Approvals: who decided, when, and under which rule.
- The result the system of record returned — not the agent’s summary of it.
- Model usage: which model, how many tokens, what it cost.
- Why the run stopped: finished, budget reached, refused, cancelled.
Write it with the change, not after it
If the record is written after the change, a crash in between leaves an action with no record — exactly the gap an incident review falls into. Writing the event in the same database transaction as the change means both happen or neither does.
Make tampering detectable
- Chain the entries: each one commits to the one before it, so editing or removing an entry breaks every link after it.
- Keep one chain per company, so each tenant’s evidence stands on its own.
- Sign periodic anchors, so even a wholesale rewrite of the history is detectable against a signature made earlier.
- Let anyone verify: verification should report where the chain breaks, not just pass or fail.
What an audit trail does not prove
A verified chain proves the record was not altered. It does not prove the decision recorded was the right one — that is still a question for people, answered from the evidence the record keeps.
- Events are appended in the same database transaction as the change they record.
- Hash-chained per company with length-prefixed digests, and periodically anchored with an Ed25519 signature.
- Verification on demand in the console, listing any fault and where it is.
- Retention set per company; pruning is itself recorded on the chain.
Asked often.
Answered plainly.
Is writing to a log file enough?+
Not for evidence. A file can be edited without trace and can miss events when a process fails; an audit trail needs transactional writes and tamper evidence.
Can an administrator change the audit trail?+
An edit breaks the chain and verification reports exactly where. A signed anchor makes rewriting the whole history detectable as well.
Does the audit trail store our customers’ data?+
It records metadata and references. What content reaches it follows the company’s exposure policy.
Does a verified record prove the agent was right?+
No. It proves the record is intact. Whether the decision was correct is judged from the evidence the record preserves.