The application trace
Editable here. Owned by the app.
Spans, tool inputs and outputs connect execution steps for debugging. Check the tracing system’s own integrity and storage controls.
Humming Arms preserves signed, linked agent action records. Check the evidence with capture boundaries in view.
An AI agent audit trail is a sequence of recorded actions connecting an actor, an operation, a target, a decision and an observed outcome. It gives a reviewer something to inspect beyond the agent’s account of its own work.
Observed outcome: not sent
Action 7: upload.request, deny, not sent.
In this example, a report upload is attempted and denied. The denied attempt still belongs in the record, although the upload is not sent. The stop acknowledgment relates to the covered tool path; it does not establish that every route has stopped.
Useful AI agent audit logs preserve the distinction between intent, decision and effect. Keep successful actions, denied attempts and unresolved results. See where Humming Arms records agent actions.
For a denied upload, preserve who tried it, the operation and destination, why it was denied and the observed result. Do not flatten an attempted action into a successful one.
| Field | Why it matters |
|---|---|
| 1Identity | Agent identity, session and observing sensor. Keep parent and child identities distinguishable so one run’s authority is not mistaken for another’s. |
| 2Action | The operation attempted: a tool invocation, file access, process execution or outbound request. Record the action boundary, not just a model’s description of it. |
| 3Target | The resource or destination involved. Apply redaction at capture without losing the context needed to identify the affected system. |
| 4Decision | Allow or deny, the policy context and the reason. A denied attempt still belongs in the timeline even when the external action never happens. |
| 5Outcome | What the sensor observes after the decision: success, failure or an unresolved result. A request being accepted does not prove the remote action completed. |
| 6Time | Capture time and the clock context used to interpret it. Cross-host timestamps require care; a wall clock alone does not establish causal order. |
| 7Sequence | The record’s position and previous hash. Sequence checks expose broken links; relate independent sensor streams explicitly when reconstructing a timeline. |
Minimize evidence at capture and keep tenant access scoped. Payload capture and HTTPS decryption are opt-in per policy. Review signing keys, privacy and security boundaries.
A tool trace helps explain why an upload failed. An audit review asks which identity attempted it, which destination was involved, what policy decided and whether the exported record has changed. Keep both records; use each for the question it can answer.
Editable here. Owned by the app.
Spans, tool inputs and outputs connect execution steps for debugging. Check the tracing system’s own integrity and storage controls.
Signed outside the agent sandbox.
Recorded identities, targets and sensor signatures support attribution within the capture boundary. Trusted-key checks give the reviewer a separate test.
The recorded decision is deny in both witnesses.
Tamper-evident agent logs make changes detectable under stated trust assumptions. Immutable storage restricts changes under its storage rules. Neither label, by itself, proves complete capture. Preserve the evidence and verification materials so another reviewer can check the recorded sequence independently of the tracing platform.
The observing sensor records the attempted action at an instrumented boundary. Identify that boundary before interpreting the receipt.
Sensor signatures bind records to signing keys kept outside the agent sandbox. A valid signature proves possession of a key, not complete or truthful capture.
A checkpoint commits to a recorded prefix at a known position. Compare it with an export to detect changes or an export ending before that position.
Anchoring binds a checkpoint to an external reference. Check the reference’s authenticity and scope before using it to challenge a replacement history.
Preserve the evidence with its trusted keys, checkpoints and anchor references. A console status alone is not an independent verification result.
An intact record can still miss an action. A direct route outside sensor coverage leaves no receipt to check.
Inventory capture paths, outages and sequence gaps. Cryptography cannot recover an action never observed.
Evaluate your stop boundaries →CASE 042 / BUNDLE
Example checks complete. Verification materials present.
Identify the run, sensors, sequence positions and capture boundaries under review. Keep a preserved export and work on a separate copy. List gaps and exclusions before interpreting a result.
A hash fingerprints a record’s bytes; each record includes the previous fingerprint. Recompute links in sequence and test an edited record and a removed middle record. A chain alone cannot prevent a rewrite of the whole sequence.
Check each sensor signature against independently trusted keys, including key changes. Trust the key’s relationship to the sensor separately. A valid signature does not turn an inaccurate observation into historical truth.
Match the export to trusted checkpoints at known sequence positions. Test a truncated tail and a replacement history. A checkpoint cannot establish events beyond the position it covers.
Verify the external references and state which checkpoints they witness. Keep those references with the bundle. A missing proof is a missing check, even if all the records you have appear internally consistent.
Record the checks, trusted inputs and failures so another reviewer can reproduce them. Inspect outages, redaction and uncovered routes separately. An integrity result never establishes that every relevant action reached the recorder.
Export evidence with its verification materials. The open verifier checks hash links and signatures against trusted keys; compare checkpoint and anchor references for the sequence under review.
Team includes 30 days searchable and 1 year of archive retention from capture, including the searchable period. Enterprise supports custom retention; agree on Lab and Incident Response retention in the engagement scope. Verifiable export remains included after cancellation. Preserve materials before the retention window expires. Compare plan scope and retention.
Use this playbook with your own response procedure. Keep observed facts separate from hypotheses, and leave unresolved outcomes visible.
Identify the authority and routes involved. Apply the approved containment procedure to those paths. Connect stop requests to acknowledgments and observed effects; an unresolved stop remains unresolved evidence. Do not infer containment from a request alone.
Export the action record and verification materials before retention expires. Preserve the original and document who collected it, when and from which scope. Restrict access to the people handling the incident; investigate on a copy.
Separate attempts, policy decisions and observed outcomes. Correlate agent, session and sensor identities. Use sequence within each stream; account for clock differences when relating hosts. Mark uncertain ordering rather than filling gaps with assumptions.
Check links, signatures, checkpoints and anchors against trusted materials. Record failures and missing proofs explicitly. Keep application traces for debugging context, while using action evidence to inspect the recorded boundaries and their authority.
Inventory direct routes, capture outages, missing sequence positions and redaction rules. Compare with other available records. Distinguish an observed denial from a successful remote action, and a clean integrity result from a complete incident history.
Document findings, unresolved questions, containment effects and corrective actions. Have someone outside the operating team check the export. Preserve the access and retention decisions with the case, then test the affected capture and control paths again.
No. Tamper evidence makes changes detectable under stated trust assumptions. Immutable storage restricts changes under its storage rules. Humming Arms uses verifiable records so reviewers can check integrity; storage controls and retention remain separate questions.
It establishes that the signed bytes match a signature from the corresponding key. You still need to trust the key’s relationship to the sensor, the sensor’s capture behavior and the meaning of its outcome fields. A signature does not turn an inaccurate observation into historical truth.
Yes. An uninstrumented action may never enter the chain. An export can also omit the tail unless a trusted later checkpoint exposes the omission. Review coverage and checkpoint scope alongside the integrity checks.
No. Action evidence does not depend on chain of thought. Humming Arms minimizes data and applies redaction or tokenization at sensors; payload capture and HTTPS decryption are opt-in per policy. Agree on the fields needed for investigation before capturing sensitive content.
Verifiable export remains included after cancellation. Preserve your evidence with its trusted keys, checkpoints and verification materials. The export can then be checked independently of hosted console access; it does not extend the plan’s retention period.
Walk through action fields, capture coverage, trusted keys and retention with Humming Arms. Define what an independent reviewer must be able to check.
CLOSEDA closed case keeps its evidence.