An AI agent audit trail you can check.

Humming Arms preserves signed, linked agent action records. Check the evidence with capture boundaries in view.

What is an AI agent audit trail?

A

An AI agent audit trail is a sequence of recorded actions connecting an actor, an operation, a target, a decision and an observed outcome. It gives a reviewer something to inspect beyond the agent’s account of its own work.

RUN / 04207 / 11
upload.requestDENY
actor identity
agent/017
session
run/042
tool
upload.request
target
external destination
decision
deny
hash
h007…
prev
h006…
signature
sensor/03 · sig…

Observed outcome: not sent

Drag, tap or use the slider’s arrow keys to inspect an action.

Action 7: upload.request, deny, not sent.

In this example, a report upload is attempted and denied. The denied attempt still belongs in the record, although the upload is not sent. The stop acknowledgment relates to the covered tool path; it does not establish that every route has stopped.

Useful AI agent audit logs preserve the distinction between intent, decision and effect. Keep successful actions, denied attempts and unresolved results. See where Humming Arms records agent actions.

What to log for AI agents.

B

For a denied upload, preserve who tried it, the operation and destination, why it was denied and the observed result. Do not flatten an attempted action into a successful one.

Action / 007

1Identity
agent/017 · run/042 · sensor/03
2Action
upload.request
3Target
external destination
4Decision
deny · export restriction
5Outcome
not sent
6Time
14:03:16 · example clock
7Sequence
007 · prev h006… · hash h007…
Payload · redacted by default
Signature: sensor/03 · sig…
Signing key outside the agent sandbox.
Fields that survive an investigation
FieldWhy it matters
1IdentityAgent identity, session and observing sensor. Keep parent and child identities distinguishable so one run’s authority is not mistaken for another’s.
2ActionThe operation attempted: a tool invocation, file access, process execution or outbound request. Record the action boundary, not just a model’s description of it.
3TargetThe resource or destination involved. Apply redaction at capture without losing the context needed to identify the affected system.
4DecisionAllow or deny, the policy context and the reason. A denied attempt still belongs in the timeline even when the external action never happens.
5OutcomeWhat the sensor observes after the decision: success, failure or an unresolved result. A request being accepted does not prove the remote action completed.
6TimeCapture time and the clock context used to interpret it. Cross-host timestamps require care; a wall clock alone does not establish causal order.
7SequenceThe record’s position and previous hash. Sequence checks expose broken links; relate independent sensor streams explicitly when reconstructing a timeline.

Minimize evidence at capture and keep tenant access scoped. Payload capture and HTTPS decryption are opt-in per policy. Review signing keys, privacy and security boundaries.

Traces explain. Evidence can be checked.

C

A tool trace helps explain why an upload failed. An audit review asks which identity attempted it, which destination was involved, what policy decided and whether the exported record has changed. Keep both records; use each for the question it can answer.

The application trace

Editable here. Owned by the app.

upload.requestdecision: deny
Saved in the application

Spans, tool inputs and outputs connect execution steps for debugging. Check the tracing system’s own integrity and storage controls.

The sensor’s record

Signed outside the agent sandbox.

upload.requestdecision: deny
Matches the original signed fact

Recorded identities, targets and sensor signatures support attribution within the capture boundary. Trusted-key checks give the reviewer a separate test.

The recorded decision is deny in both witnesses.

Tamper-evident vs immutable logs

Tamper-evident agent logs make changes detectable under stated trust assumptions. Immutable storage restricts changes under its storage rules. Neither label, by itself, proves complete capture. Preserve the evidence and verification materials so another reviewer can check the recorded sequence independently of the tracing platform.

Follow the chain of custody.

D
Captured by sensorCAPTURED

The observing sensor records the attempted action at an instrumented boundary. Identify that boundary before interpreting the receipt.

SignedSIGNED

Sensor signatures bind records to signing keys kept outside the agent sandbox. A valid signature proves possession of a key, not complete or truthful capture.

CheckpointedCHECKPOINTED

A checkpoint commits to a recorded prefix at a known position. Compare it with an export to detect changes or an export ending before that position.

AnchoredANCHORED

Anchoring binds a checkpoint to an external reference. Check the reference’s authenticity and scope before using it to challenge a replacement history.

ExportedEXPORTED

Preserve the evidence with its trusted keys, checkpoints and anchor references. A console status alone is not an independent verification result.

Integrity is not completeness.

An intact record can still miss an action. A direct route outside sensor coverage leaves no receipt to check.

Coverage demonstration: the instrumented tool path reaches the recorder; a direct route has a gapTOOL → SENSOR → RECORDDIRECT ROUTE / NOT CAPTURED

Inventory capture paths, outages and sequence gaps. Cryptography cannot recover an action never observed.

Evaluate your stop boundaries →

How to verify agent action logs.

E

Verification report

CASE 042 / BUNDLE

  1. Chain linksPASS
  2. Sensor signaturesPASS
  3. Trusted checkpointsPASS
  4. External anchorsPASS
VERIFIED

Example checks complete. Verification materials present.

  1. Fix the scope

    Identify the run, sensors, sequence positions and capture boundaries under review. Keep a preserved export and work on a separate copy. List gaps and exclusions before interpreting a result.

  2. Recompute the chain

    A hash fingerprints a record’s bytes; each record includes the previous fingerprint. Recompute links in sequence and test an edited record and a removed middle record. A chain alone cannot prevent a rewrite of the whole sequence.

  3. Validate the signatures

    Check each sensor signature against independently trusted keys, including key changes. Trust the key’s relationship to the sensor separately. A valid signature does not turn an inaccurate observation into historical truth.

  4. Compare checkpoints

    Match the export to trusted checkpoints at known sequence positions. Test a truncated tail and a replacement history. A checkpoint cannot establish events beyond the position it covers.

  5. Check the anchors

    Verify the external references and state which checkpoints they witness. Keep those references with the bundle. A missing proof is a missing check, even if all the records you have appear internally consistent.

  6. Write the limits

    Record the checks, trusted inputs and failures so another reviewer can reproduce them. Inspect outages, redaction and uncovered routes separately. An integrity result never establishes that every relevant action reached the recorder.

Keep the evidence. Keep its proofs.

Export evidence with its verification materials. The open verifier checks hash links and signatures against trusted keys; compare checkpoint and anchor references for the sequence under review.

Team includes 30 days searchable and 1 year of archive retention from capture, including the searchable period. Enterprise supports custom retention; agree on Lab and Incident Response retention in the engagement scope. Verifiable export remains included after cancellation. Preserve materials before the retention window expires. Compare plan scope and retention.

AI agent incident response: work from the record.

Use this playbook with your own response procedure. Keep observed facts separate from hypotheses, and leave unresolved outcomes visible.

  1. Contain the action paths

    Identify the authority and routes involved. Apply the approved containment procedure to those paths. Connect stop requests to acknowledgments and observed effects; an unresolved stop remains unresolved evidence. Do not infer containment from a request alone.

  2. Preserve the case

    Export the action record and verification materials before retention expires. Preserve the original and document who collected it, when and from which scope. Restrict access to the people handling the incident; investigate on a copy.

  3. Establish the timeline

    Separate attempts, policy decisions and observed outcomes. Correlate agent, session and sensor identities. Use sequence within each stream; account for clock differences when relating hosts. Mark uncertain ordering rather than filling gaps with assumptions.

  4. Verify before interpreting

    Check links, signatures, checkpoints and anchors against trusted materials. Record failures and missing proofs explicitly. Keep application traces for debugging context, while using action evidence to inspect the recorded boundaries and their authority.

  5. Investigate the blind spots

    Inventory direct routes, capture outages, missing sequence positions and redaction rules. Compare with other available records. Distinguish an observed denial from a successful remote action, and a clean integrity result from a complete incident history.

  6. Close with a reproducible record

    Document findings, unresolved questions, containment effects and corrective actions. Have someone outside the operating team check the export. Preserve the access and retention decisions with the case, then test the affected capture and control paths again.

AI agent audit trail questions.

Are tamper-evident agent logs the same as immutable storage?

No. Tamper evidence makes changes detectable under stated trust assumptions. Immutable storage restricts changes under its storage rules. Humming Arms uses verifiable records so reviewers can check integrity; storage controls and retention remain separate questions.

Does a valid signature prove the action happened?

It establishes that the signed bytes match a signature from the corresponding key. You still need to trust the key’s relationship to the sensor, the sensor’s capture behavior and the meaning of its outcome fields. A signature does not turn an inaccurate observation into historical truth.

Can a valid chain still be incomplete?

Yes. An uninstrumented action may never enter the chain. An export can also omit the tail unless a trusted later checkpoint exposes the omission. Review coverage and checkpoint scope alongside the integrity checks.

Do audit trails require full prompt and payload capture?

No. Action evidence does not depend on chain of thought. Humming Arms minimizes data and applies redaction or tokenization at sensors; payload capture and HTTPS decryption are opt-in per policy. Agree on the fields needed for investigation before capturing sensitive content.

Can we verify agent action logs after cancelling?

Verifiable export remains included after cancellation. Preserve your evidence with its trusted keys, checkpoints and verification materials. The export can then be checked independently of hosted console access; it does not extend the plan’s retention period.

Bring the record you need to defend.

Walk through action fields, capture coverage, trusted keys and retention with Humming Arms. Define what an independent reviewer must be able to check.

CLOSED

A closed case keeps its evidence.