AIUC-1 evidence pack
AIUC-1 · version 2026-07-15 (Q3-2026) · log tenant_acme/prod · generated 2026-10-09T12:01:54.823Z
17 distinct events are cited as evidence across 51 controls. This product evidences the runtime controls — activity logging, tool-call restriction, human oversight, disclosure, change accountability — and states honestly that policy, third-party evaluation, and agent-side output controls are evidenced elsewhere.
A · Data & Privacy
Protect against data leakage, IP leakage, and training on user data without consent.
Create and share policies on how customer data is used for training, inference, retention, and customer rights.
A published data-use policy — held in your policy set, not the runtime record. (legal / contractual)
Define ownership, usage, consent, and deletion policies for AI outputs.
An output-rights policy — governance, not something an action log evidences. (legal / contractual)
Apply controls restricting agent data access by task, user role, agent role, and context.
Each agent acts under a unique identity carrying the human it acts for, and its tool grant is enforced deny-by-default at the action boundary. Data-classification scoping of the underlying stores is yours. #18, #23, #24, #48, #71, #98
| A003.1 | Data access scoping The tool-allowlist rule confines an agent to the tools its grant names; out-of-grant attempts are refused and chained. #18, #23, #24, #48, #71, #98 |
| A003.2 | Agent identity management Every action names one agent identity (5 on this log), and each per-action receipt cryptographically binds the action to it (AARM R6). #0, #4, #6, #15 |
| A003.3 | Per-agent permission scopes Grants are per agent and recorded on the receipt's identity.scope; silent inheritance is not possible because each action re-presents its own grant. |
Crosswalk: NIST AI RMF MAP 2.1 · OWASP Agentic ASI02/ASI06 · CSA AICM IAM-17/IAM-19
Prevent systems from exposing proprietary or confidential information.
Output-side IP filtering lives in the agent; the record proves what was done, not what a model said. (agent-side guardrail)
Block data leakage between customers.
Tenant isolation of the data stores is your infrastructure; Auditant's own logs are per-log isolated, which is evidence for B007, not this. (governance / policy)
Block personal data from appearing in outputs and logs.
The activity log itself carries no PII: default custody is metadata-and-hashes only, so A006.1's 'log redaction' is satisfied by construction — payloads never reach the chain. Output-side PII filtering is the agent's.
| A006.1 | PII detection and filtering (logs) Payloads are hashed, never stored on the chain; a GDPR erasure destroys the payload blob without breaking the log. There is no PII in the record to redact. |
Crosswalk: EU AI Act Art 12 · CSA AICM DSP-07
Prevent outputs infringing copyrights, trademarks, or third-party IP.
Output infringement filtering is inside the agent. (agent-side guardrail)
Detect and prevent secret exposure in inputs, outputs, logs, and storage.
A008.5 (secrets in logs) is met the same way A006 is: the chain stores hashes, not payloads, so no credential can land in the record. Detection in inputs/outputs (A008.1–.4) is the agent's.
| A008.5 | Secrets redaction in logs and stored artifacts Metadata-only custody: prompts and outputs are hashed before anything is chained, so a secret in a payload never reaches stored log artifacts. |
Crosswalk: Q3-2026 new control
B · Security
Protect against adversarial attacks and unauthorized tool calls.
Adversarial testing of resilience to prompt injection.
A red-team engagement (e.g. through your AIUC-1 auditor); not a runtime record. (third-party evaluation)
Monitor for adversarial inputs and prompt injection.
Input-side detection lives in the agent/gateway, upstream of the action. (agent-side guardrail)
Control disclosure of technical information.
A disclosure policy. (governance / policy)
Guard against probing/scraping of AI endpoints.
Rate-limiting/anomaly detection at your API edge; Auditant rate-limits money-spending calls but that is D003, not endpoint anti-scraping. (agent-side guardrail)
Automated moderation of inputs.
Input moderation is the agent's. (agent-side guardrail)
Prevent agents performing actions beyond intended scope and authorized privileges.
Actions are intercepted before execution and evaluated against policy; 181 were refused on this log, each naming the rule and version that refused it. The Q3-2026 sub-control B006.3 lists a pre-execution policy hook among its acceptable safeguards; /v1/decide is that hook. (Tool-definition integrity — detecting a tool whose definition changed after approval — is NOT something this product does.) #18, #23, #24, #48, #71, #98
| B006.1 | Agent service access restrictions Deny-by-default tool allowlist per agent; the MCP/tool grant is enforced at the action boundary. #18, #23, #24, #48, #71, #98 |
| B006.2 | Agent security monitoring and alerting Every agent action is logged; a quiet agent past 24h is a finding, and held actions ping the operator. 1 agents currently quiet. |
| B006.3 | Execution-level safeguards (pre-execution hook) The synchronous /v1/decide hook verifies each tool call at runtime before any side effect (AARM R1 pre-execution interception); each verdict is a per-action signed receipt. #18, #23, #24, #48, #71, #98 |
Crosswalk: OWASP LLM08:25 · CSA AICM AIS-11/IAM-19 · OWASP Agentic ASI02/ASI03
Maintain user access controls and admin privileges aligned with policy.
Access to the record is role-scoped: admin keys see the fleet, tenant keys resolve to exactly one log and can infer nothing about another, and operator surfaces (budgets, custom rules) are refused to a tenant key. Access to the underlying agent systems is yours.
Crosswalk: OWASP LLM06:25 · CSA AICM IAM-01..18
Encryption, access controls, and authorization in the deployment environment.
Your hosting environment; Auditant runs TLS and per-tenant keys but the model deployment env is yours. (governance / policy)
Output limitations and obfuscation.
Output volume/precision controls in the agent. (agent-side guardrail)
Secure defaults and vulnerability prevention in generated code.
A property of the coding agent's generation, not of the action log. (agent-side guardrail)
C · Safety
Prevent harmful AI outputs and brand risk through testing, monitoring and safeguards.
Establish a risk taxonomy for the system.
A document; your risk register. (governance / policy)
Internal testing across risk categories before deployment.
A pre-deployment test programme. (third-party evaluation)
Safeguards preventing harmful outputs.
Content filtering in the agent. (agent-side guardrail)
Safeguards preventing out-of-scope outputs.
Scope guardrails in the agent. (agent-side guardrail)
Safeguards for agent-specific high-risk outputs, including human review.
C005.2 (human review workflows) is evidenced: high-risk actions are held for a named human before they execute, and each grant or refusal is chained under the reviewer. The risk-detection logic itself (C005.1) is the agent's. #20, #50, #57, #73, #84, #100
| C005.2 | Human review workflows Actions above policy are held; 0 currently pending, released only by a named person. #20, #50, #57, #73, #84, #100 |
Crosswalk: EU AI Act Art 9 · OWASP LLM05:25
Prevent security vulnerabilities in outputs.
Output sanitisation in the agent. (agent-side guardrail)
Alerting that flags high-risk outputs for human review.
The human-sign-off rule flags and holds high-risk actions for review (C007.3 review workflow), with the queue and each decision on the chain. The detection criteria (C007.1/.2) are yours to define. #20, #50, #57, #73, #84, #100
Crosswalk: ISO 42001 A.9.3 · CSA AICM GRC-15
Monitor AI systems across risk categories.
Output-category monitoring; the chain monitors actions and spend, not output risk classes. (agent-side guardrail)
Mechanisms to pause, stop, or redirect system behavior.
C009.1's 'pause/stop' is the kill switch: a tenant-level halt that forbids over every rule, with each flip chained under the operator. The in-product feedback UI is the agent's surface.
| C009.1 | User intervention mechanisms (stop/pause) The halt flag stops every agent on the log immediately; arming and releasing it are chained events under a named human. |
Crosswalk: EU AI Act Art 14 · OWASP Agentic ASI01/ASI09
External evaluation of robustness to harmful outputs.
Quarterly red-team through your auditor. (third-party evaluation)
External evaluation of out-of-scope robustness.
Quarterly red-team. (third-party evaluation)
External evaluation of customer-defined high-risk outputs.
Quarterly red-team. (third-party evaluation)
D · Reliability
Prevent hallucinations and unreliable tool calls to business systems.
Safeguards preventing hallucinated outputs.
Groundedness controls in the agent. (agent-side guardrail)
External evaluation of hallucinated outputs.
Quarterly evaluation. (third-party evaluation)
Prevent tool calls executing unauthorized actions, accessing restricted information, or acting beyond scope.
Every one of D003's four technical sub-controls is a live capability of the record: tool authorization, rate limits, an execution log, and human-approval workflows. 181 unsafe calls refused, 0 held for a human. #18, #23, #24, #48, #71, #98
| D003.1 | Tool authorization & validation Deny-by-default tool allowlist enforced before execution; parameters travel as hashes on the receipt. #18, #23, #24, #48, #71, #98 |
| D003.2 | Rate limits & transaction caps Per-caller and global rate limits, plus the burn-rate and cost-velocity rules that stop a runaway loop before it spends. |
| D003.3 | Tool call log Every tool call is a chained event with server origin (adapter), tool name, parameter hash, and timestamp — 4827 events on this log. |
| D003.4 | Human-approval workflows Sensitive actions are held for a named human; 0 pending, each release or refusal chained under the reviewer. #20, #50, #57, #73, #84, #100 |
Crosswalk: MITRE ATLAS · OWASP Agentic Top 10 · NIST AI RMF
External evaluation of tool calls every 3 months.
Quarterly evaluation by an independent assessor — but the tool-call log this pack exports is exactly the evidence that assessment reads. (third-party evaluation)
E · Accountability
Assign accountability, enforce oversight, create emergency responses and vet suppliers.
Documented failure plan with owners, notification, remediation, and evidence collection.
The plan is a document (yours), but two of its required elements are runtime capabilities here: 'system freeze' is the kill switch, and 'evidence collection / preserve logs for legal review' is the tamper-evident chain and its offline export.
Crosswalk: EU AI Act Art 73 · ISO 42001 A.8.4
Response protocols for harmful outputs.
An incident-response document. (governance / policy)
Procedures for hallucinated outputs causing loss.
An incident-response document. (governance / policy)
Document which changes require review/approval, assign accountable leads, and record approvals.
E004.1 is evidenced: every policy and budget change is itself a chained event naming the author, and a rule version is the hash of its own bytes, so 'who changed the control, when, and what it said before' is answerable. E004.2 (code signing of AI components) is not — checkpoint signing is not artifact signing.
| E004.1 | Change approval policy and records Rule changes (created/updated/retired) and budget/halt changes are appended to the chain under the author's identity; the prior rule version is retained, never overwritten. |
| E004.2 | Code signing implementation Not evidenced by this product — code/model signing lives in your CI/CD. |
Crosswalk: MITRE ATLAS AML-M0013 · ISO 42001 A.3.2/A.6.2.2
Document storage practices against sensitivity and regulation.
A documentation control; see docs/sales/subprocessors.md and security-answers.md as starting material. (governance / policy)
Vet foundation/upstream model providers.
Vendor assessment records; the chain records WHICH providers were used (see E009), not your diligence on them. (governance / policy)
Regular internal process reviews with records.
An operational review cadence. (governance / policy)
Log third-party API connections, sessions, and data access, and alert on anomalies.
E009.1 is evidenced for the model providers your agents call: every model_call carries its provider and model id (or is flagged unpriced), so third-party model access is logged (1 provider(s) seen). Anomaly alerting (E009.2) on that access is the quiet-agent and burn-rate signals.
Crosswalk: EU AI Act Art 72 · NIST AI RMF MANAGE 4.1
Create and enforce an AI acceptable-use policy, with violation detection and logging.
The policy document (E010.1) is yours, but its enforcement is evidenced: policy rules detect and block disallowed actions (E010.2/.4), and every violation is a chained, reviewable record. #18, #23, #24, #48, #71, #98
Crosswalk: CSA AICM GRC
Document where AI data is processed.
A subprocessor/location record (docs/sales/subprocessors.md is a starting point); the chain names providers, not their processing regions. (governance / policy)
Map applicable AI laws and compliance strategy.
A regulatory mapping — though the compliance module maps five regimes to the record as a starting point. (governance / policy)
A proportionate QMS for AI operations.
A management-system control. (governance / policy)
Maintain logs of processes, actions, and agent outputs for investigation, auditing, and explanation, with retention, access control, and integrity protection.
This is the product. All four E015 sub-controls are live: agent activity is logged with provenance and tool parameters, stored append-only, and integrity-protected by a hash chain with signed, externally countersigned checkpoints. 4827 events, 184 checkpoints (180 countersigned, 175 in WORM storage). #0
| E015.1 | Logging implementation Inputs (hashed), outputs (hashed), tool calls, decisions, timestamps and actor — 4827 events captured across four planes. |
| E015.2 | AI agent logging implementation Agent provenance (agent id + version), tool-call parameters (as hashes), delegation chains (delegation/handoff events), and approval events (approver identity + timestamp + outcome) are all first-class on the schema. #20, #50, #57, #73, #84, #100 |
| E015.3 | Log storage Append-only store (UPDATE/DELETE refused by database trigger); retention is a property of the store, and payloads are erasable independently for GDPR without breaking the chain. |
| E015.4 | Log integrity protection Cryptographic hashing + append-only + WORM, all three: 184 hash-chain checkpoints signed (ECDSA P-256), 180 RFC 3161-countersigned, 175 written to S3 Object Lock. Any post-hoc edit is computable from the exported bundle offline. |
Crosswalk: ISO 42001 A.6.2.8 · EU AI Act Art 12 & 19 · NIST AI RMF MEASURE 2.4/2.8 · CSA AICM LOG-08/11/14/15
Inform users when they are interacting with AI rather than a human.
E016.2 (voice disclosure) and E016.4 (disclosing autonomous agent action) are evidenced: a disclosure event is recorded per voice call — provably present or provably missing — and every action records actor.mode (autonomous vs interactive). Text/media disclosure UI (E016.1/.3) is the agent's surface. 0 of 2 calls missing disclosure. #6, #12
| E016.2 | Voice-based AI disclosure A first-class disclosure event per call, timestamped; a missing disclosure is a chained policy violation (EU AI Act Art 50), not an omission. #6, #12 |
| E016.4 | Disclosing autonomous AI agent actions actor.mode distinguishes an autonomous action from a human-in-the-loop one on every event. |
Crosswalk: EU AI Act Art 50 · ISO 42001 A.8.2 · CSA AICM GRC-15
Model cards, datasheets, AI bill of materials.
A transparency repository. (governance / policy)
F · Society
Prevent AI from enabling societal harm through cyberattacks or national security risks.
Guardrails against AI-enabled cyber misuse.
Misuse guardrails in the model/agent. (agent-side guardrail)
Guardrails against catastrophic (CBRN) misuse.
Misuse guardrails in the model/agent. (agent-side guardrail)