Evidence and audit
A record an auditor can check without us
A log you control is not evidence. It is a claim about evidence.
The problem
The awkward question about any governance product is who checks the checker. If the only proof that a control ran is a line in a database the vendor also controls, then the vendor is the evidence — and that is exactly the position a regulator will not accept.
What one decision record holds
Reconstructing a decision a year later needs all of it. A verdict and a timestamp is a log line, not evidence.
agent + identityWho acted, and on whose behalf.
surfaceWhere the content entered or left.
provenanceWhere each argument came from, per argument.
rules_firedWhich rules matched, and what each decided.
degradedAny detector that ran out of budget on this call.
policy versionThe exact rule set in force at that moment.
effective_verdictWhat would have happened, when running in observe.
prev_hashThe link that makes a later deletion visible.
- 01
One record per decision, with what decided it
Not just the verdict: the agent, the identity behind it, the surface, where each argument came from, which rules fired, which detectors were degraded, and the policy version in force at that moment. Reconstructing a decision later needs all of it.
- 02
Chained, so a deletion is visible
Each record carries the hash of the one before it. Altering or removing an entry breaks the chain from that point on, which turns quiet tampering into a loud verification failure.
agentfox audit verify - 03
Export a package that travels
An evidence package is the records, the policy that produced them, and the versions of everything that took part, bundled for a date range and a scope.
agentfox evidence export - 04
Verified by a script that does not import us
The package ships with a standard-library-only verifier. An auditor runs it on their own machine against the bundle, and it recomputes the chain without any of our code in the room. That is the difference between evidence and a claim.
- 05
The governance layer is governed too
Operator actions — a policy switched to observe, an agent un-quarantined — go into their own chain. A control plane that recorded everything except changes to itself would be recording the wrong thing.
What the chain does not prove
A hash chain proves the record has not been altered since it was written. It does not prove the record was true when written, and anyone who can write to the database before a decision is recorded is inside the boundary. There is no external timestamping authority and no third party has audited any of this — /security says so at more length.
Try to break it before you trust it
No account, no install, and the same enforcement code as the product.
pip install agentfox agentfox init && agentfox demo
Offline: no API key, no downloaded weights, no network egress.