Web app
Compliance
One control set mapped to several frameworks, with each control's status computed from your own telemetry rather than attested on a form, and the evidence to show for it.
In the web app Compliance
When to use this
- To see which controls the telemetry says are failing, and why.
- To have a qualified person review mappings framework by framework.
- To build an evidence package for an auditor, and to place a legal hold.
- To give leadership a one-page snapshot.
The header
The page loads GET /api/controls, /api/frameworks, /api/obligations, /api/risk/register, /api/evidence and /api/retention. Above the tabs: the Draft note, and a bar of control statuses (effective, degraded, failing, not implemented, not computed) with the effectiveness percentage. Not-implemented controls are left out of the ratio, not counted as failing. If the control catalog was never loaded, a Load control catalog button appears (POST /api/controls/sync); workspaces created by GitHub sign-in have it loaded already.
Controls tab
A worklist first: the failing and degraded controls, with what the telemetry found. Then the full catalogue (collapsed): each control's title and key, what it checks, status and the evidence or rationale. Grey means not assessed, which is different from failing. Recompute status from telemetry (POST /api/controls/compute) re-runs the assessment; controls that were never computed need real traffic, not a click.
agentfox report statusall frameworks — 43 controls
36 effective · 0 degraded · 4 failing · 2 not implemented
effectiveness 90%Frameworks tab, and reviewing mappings
Each framework with controls mapped, mappings, how many are reviewed, status (draft until all are reviewed) and Review mappings →. Under the table, each framework's declared gaps: what this product does not cover for it.
/app/compliance/frameworks/<key> (GET /api/frameworks/{key}) lists every control with the clauses it is mapped to and Mark reviewed. Marking one reviewed records you as the reviewer (POST /api/frameworks/review) and needs owner, admin or compliance. Only do it if you are the person accountable for the claim.
43 of 43 controls mapped, 0 of 70 mappings reviewed.
Declared gaps
Conformity assessment procedure (Art. 43), CE marking and notified-body interaction
Registration in the EU database (Art. 49)
Fundamental rights impact assessment content (Art. 27) — we provide inputs, not the filing
control reference(s) status
The complete execution path of every invocation is recorded Art. 12 — record-keeping and automatic logging draft Mark reviewedThe CLI equivalent attests by name, per control and optionally per clause, and report review-packet writes everything a reviewer needs for one framework into one file:
agentfox report review-packet --framework eu-ai-act --out eu-ai-act-review.md
agentfox report signoff NOM-AUD-01 --framework eu-ai-act --reviewer "Dana Reviewer"Obligations tab
Dated duties from regulations: effective date, framework, the obligation, live or upcoming, how many of your agents it applies to, and a build-by date. A row is a calendar entry, not a record that the duty was met. agentfox report obligations prints the same calendar.
Risk register tab
One row per agent: risk tier, EU AI Act class (or not assessed), residual risk, assessor, next review (or overdue). Assess / Reassess opens a form: EU AI Act class (or "Let the platform propose one"), residual risk (low, medium, high) and who signed it off. Record assessment posts POST /api/risk/assessments/{slug} and needs owner, admin or compliance. agentfox report risk prints the register.
Evidence & reports tab
- Verify audit chain integrity now (
POST /api/audit/verify) re-derives the hash chain over every audit entry and reports the result as a notice:
chain verified — 95 entries (seq 1–95), 1 checkpoint(s), intact- Build a package: agents (comma-separated slugs, blank for all), controls (blank for all), period from and to. Build evidence package posts
POST /api/evidence; building needs owner, admin, security, compliance or auditor. - The packages table: when built, by whom, scope, chain
verifiedorbroken, counts of what is inside (an empty package is tagged as such), and Download → (GET /api/evidence/{id}/download, a zip).
SUMMARY.md SUMMARY.html audit_entries.json audit_checkpoints.json traces.json
decisions.json policy_versions.json agents.json approvals.json eval_runs.json
findings.json control_status.json framework_mappings.json risk_assessments.json
chain_verification.json verify_chain.py README.txt manifest.jsonThe recipient verifies it without trusting AgentFox or calling its API:
python3 verify_chain.pynote: AGENTFOX_AUDIT_KEY not set - checkpoint signatures not verified
entries checked: 95 (seq 1..95)
CHAIN INTACTagentfox report evidence --agent payments-ops --since-days 30
agentfox report verifyevidence package
…/state/var/evidence/evd_01m469zq7njq66qhsx.zip
period 2026-09-05 → 2026-10-05
agents 1
traces 0
decisions 3
audit entries 27
audit payloads withheld 22
…
chain verification valid
Verify independently: unzip, then `python3 verify_chain.py`
chain: 99 entries, head seq 99, 1 checkpoints
CHAIN INTACT — 99 entries verified (seq 1..99)Building a package is logged to the audit chain after its contents are computed, so a package is always one entry behind a verification run straight after it. (The tab shows the older command name for building one; the current one is above.)
Retention & legal hold tab
Retention policies is read-only: each data class, how many days it is kept, and which fields are redacted. If there are none, nothing is purged on a schedule, and there is no way to add one from the web app. Place a legal hold takes agents (blank for all) and a required reason, and posts POST /api/legal-holds (owner, admin or compliance). Holds are listed with who placed them, scope, reason and whether they are active. There is no release button.
Board snapshot tab
/app/compliance?tab=board (GET /api/board): a printable one-page view, generated when you open it and not live. Tiles appear only for what wants attention: high-risk agents, unregistered agents, unassessed agents, open findings. Then agents under management, control effectiveness, agents by risk class, open findings by severity, control effectiveness per framework, and the regulatory clock (live and upcoming obligations with days remaining). It says how many agents are sample data, and ends with the draft caveat. Print / save as PDF opens the browser's print dialog.
agentfox report board╭─────────────────╮
│ AI risk posture │
╰─────────────────╯
agents under management 6 (1 shadow, 3 unowned)
high-risk agents 1 ['payments-ops']
…
open findings 24 {'critical': 9, 'high': 5, 'medium': 10}
controls with evidence 36 of 43 effective (40 assessed, 2 with no evidence yet)
live obligations 2
upcoming (24mo) 5
Control statuses are computed from telemetry over the stated window. Framework mappings are DRAFT
and have not been reviewed by compliance counsel — see the coverage and gap declarations per
framework.Common tasks
| You want to | Run |
|---|---|
| Control status | agentfox report status |
| Recompute control status | agentfox admin catalog compute |
| Frameworks and review status | agentfox report frameworks |
| Hand a reviewer one framework | agentfox report review-packet --framework eu-ai-act --out review.md |
| Build an evidence package | agentfox report evidence --since-days 30 |
| Verify the audit chain | agentfox report verify |
| Board snapshot in a terminal | agentfox report board |
| Risk register / obligations | agentfox report risk |
What can go wrong
- Every count reads zero. The catalog is not loaded; press Load control catalog, or run
agentfox admin catalog sync. - Controls stay "not computed" after Recompute. They need telemetry that does not exist yet.
- The chain shows
broken. An audit entry was altered or removed after it was written. The notice names the first broken sequence number. - The board snapshot's "Overview" link opens the public home page, not the app's Overview. Use the sidebar.
Limits
- Mappings are drafts until reviewed, and reviewed mappings are your reviewer's claim, not AgentFox's.
- No retention schedules from the web app; no legal-hold release button.